BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 May 2024 | Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required. | IT | Garante | GDPR | €4,500 | ↗ |
| 21 Jul 2022 | Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures. | IT | Garante | GDPR | €3,000 | ↗ |
| 28 May 2020 | Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €6,000 | ↗ |
| 17 Nov 2010 | Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2011 | Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 May 2026 | Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 17 May 2023 | Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2025 | Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Jul 2024 | Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data. | IT | Garante | GDPR | €22,000 | ↗ |
| 30 Jan 2025 | Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jun 2018 | Azienda Unità Sanitaria Locale di PiacenzaAzienda Unità Sanitaria Locale di Piacenza was fined by the Garante EUR 36,000 for creating electronic health records without informing patients or obtaining their consent. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €36,000 | ↗ |
| 06 Feb 2020 | Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Dec 2020 | Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 15 Dec 2022 | Azienda Universitaria Friuli CentraleAzienda Universitaria Friuli Centrale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found failures to provide instructions for data deletion and to stop unauthorized processing by Insiel spa. | IT | Garante | GDPR | €55,000 | ↗ |
| 15 Dec 2022 | Azienda Universitaria Friuli OccidentaleAzienda Universitaria Friuli Occidentale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found that the organization failed to provide required information about data deletion, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €55,000 | ↗ |
| 18 Jun 2015 | Azienda USL5 di PisaAzienda USL5 di Pisa was fined EUR 6,000 for unlawful processing of personal data through a video surveillance system. The authority found that the required information notice was not provided to individuals, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 May 2021 | Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 Jan 2021 | Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €50,000 | ↗ |