BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Jun 2023 | La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details. | IT | Garante | GDPR | €300,000 | ↗ |
| 21 Nov 2018 | Legea s.p.a.Legea s.p.a. was fined for processing personal data through forms on its website without providing the required information notice to data subjects. The case concerned a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 May 2024 | Luigi De BenedictisThe Garante fined Luigi De Benedictis EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 07 Oct 2010 | Easynetwork s.r.l.Easynetwork s.r.l. was fined EUR 6,000 by the Italian data protection authority, Garante. The sanction concerned the sending of promotional communications by fax without providing data subjects with the required information. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 07 Apr 2022 | Made in Italy s.r.l.s.Made in Italy s.r.l.s. was fined EUR 20,000 by the Garante for carrying out promotional contacts without obtaining consent. The authority also found that the company failed to respond to data subject rights requests, which is a breach of data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Mar 2026 | Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 05 Dec 2013 | Comune di San Felice CirceoThe Garante fined Comune di San Felice Circeo EUR 6,000 for failing to provide the information required under Art. 13 and for not updating the security program document under Art. 33. The authority also found non-compliance with a prior order. | IT | Garante | GDPR | €6,000 | ↗ |
| 30 Jul 2015 | Pastore srlPastore srl was fined by the Garante in the amount of 2,400 EUR for publishing an inadequate privacy notice on its website. The notice lacked several required elements under the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2015 | Supermercato Centro Storico srlSupermercato Centro Storico srl was fined €12,400 by the Garante for inadequate data protection measures linked to its video surveillance system. The authority found that the required informational signage was missing, in breach of data protection rules. | IT | Garante | GDPR | €12,400 | ↗ |
| 10 Feb 2022 | Istituto Nazionale di StatisticaIstituto Nazionale di Statistica was fined €6,000 by the Garante for breaches of data protection rules. The case concerned inadequate security measures and data processing practices that did not meet compliance requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 May 2021 | Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches. | IT | Garante | GDPR | €120,000 | ↗ |
| 10 Mar 2011 | Riabitalia s.r.l.Riabitalia s.r.l. was fined EUR 6,000 by the Garante for sending an unsolicited promotional fax without prior explicit consent. The authority also found that the required privacy notice was not provided, constituting a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 06 Jun 2024 | Cappello Giovanni & figli s.r.l.Cappello Giovanni & figli s.r.l. was fined by Garante for unlawful processing of employee personal data using Infinity DMS software and X.-Face 380 hardware. The authority found that the company's practices breached GDPR principles. | IT | Garante | GDPR | €120,000 | ↗ |
| 01 Jun 2023 | Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Mar 2025 | IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s.IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s. was fined by the Garante EUR 10,000 for making unsolicited marketing calls without proper consent. The authority found a breach of GDPR rules on data processing and consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2023 | Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing. | IT | Garante | GDPR | €15,000 | ↗ |
| 19 Jan 2017 | D’Agostino Domenico FedeleD’Agostino Domenico Fedele was fined EUR 9,600 by the Garante for failing to provide individuals with the required data protection information. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,600 | ↗ |
| 13 Jan 2011 | Ashley s.r.l.Ashley s.r.l. was fined 6,000 EUR by the Garante for failing to provide adequate information to data subjects about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Apr 2021 | Comune di PutifigariComune di Putifigari was fined EUR 3,000 by the Garante for publishing special-category personal data online. The disclosed information could reveal individuals' health status, which breached GDPR requirements on data protection and privacy. | IT | Garante | GDPR | €3,000 | ↗ |
| 22 Apr 2010 | Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined by the Garante €10,400 for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained, constituting a data protection breach. | IT | Garante | GDPR | €10,400 | ↗ |