BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Mar 2026 | Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles. | IT | Garante | GDPR | €563,000 | ↗ |
| 21 Mar 2024 | Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Jan 2021 | Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Sept 2006 | Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Apr 2026 | Comune di Campo CalabroThe Garante fined Comune di Campo Calabro EUR 6,000 for publishing personal data online. The case concerned a breach of data protection rules and the unlawful disclosure of information. | IT | Garante | GDPR | €6,000 | ↗ |
| 24 Apr 2013 | Free Time s.r.l.Free Time s.r.l. was fined EUR 54,000 by the Italian Garante. The case concerned the registration of numerous phone cards to unaware third parties without providing the required information on data processing. | IT | Garante | GDPR | €54,000 | ↗ |
| 09 May 2018 | Mercuri SalvatoreMercuri Salvatore was fined by the Garante EUR 60,000 for making unsolicited promotional calls to individuals whose phone numbers were listed in the opposition register. This conduct infringed their right to object to such communications. | IT | Garante | GDPR | €60,000 | ↗ |
| 14 Feb 2013 | Impresa individuale Mail TrainingThe company was fined for making an unsolicited promotional phone call without providing the required information or obtaining consent. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 24 Oct 2013 | Comune di Torre CajetaniComune di Torre Cajetani was fined by the Garante for unlawfully publishing an individual's health data on a public notice board. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Sept 2025 | ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Oct 2023 | Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Feb 2026 | Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended. | IT | Garante | GDPR | €3,000 | ↗ |
| 28 Jul 2022 | Ordinanza ingiunzione - 28 luglio 2022 [9813385]The Garante imposed a fine of EUR 1,000 on the website administrator for failing to remove or de-index a page containing a Corriere della Sera article about a judicial case involving the complainant's father. The authority found a violation of the right to be forgotten. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Jan 2015 | Abruzzo Vigilanza s.r.l.Abruzzo Vigilanza s.r.l. was fined €8,000 by the Garante for using a vehicle tracking system without the required notification. The case concerns non-compliance with data protection notification obligations. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Sept 2006 | Asl n. 8 di Asolo (TV)Asl n. 8 di Asolo was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The notification was required under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Oct 2025 | Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Jul 2022 | Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data. | IT | Garante | GDPR | €45,000 | ↗ |
| 28 Oct 2021 | Anfiteatro Flavio s.r.l.Anfiteatro Flavio s.r.l. was fined EUR 2,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Apr 2015 | Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |