BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Nov 2016 | Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed. | IT | Garante | GDPR | €1,200 | ↗ |
| 26 Jul 2012 | Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Feb 2025 | Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2025 | Comune di PompeiThe Garante fined Comune di Pompei EUR 5,000 for failing to provide the Authority with the contact details of its Data Protection Officer. The breach concerned the notification duty under Article 37 GDPR. | IT | Garante | GDPR | €5,000 | ↗ |
| 07 Feb 2013 | Società delle terme s.p.a.Società delle terme s.p.a. was fined by the Garante 18,400 EUR for providing inadequate information when collecting personal data and for obtaining invalid consent. The authority found violations of Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €18,400 | ↗ |
| 27 Mar 2014 | Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Sept 2007 | Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate individuals responsible for data processing, in breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations. | IT | Garante | GDPR | €24,000 | ↗ |
| 20 Oct 2011 | Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Jan 2015 | Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €80,000 | ↗ |
| 12 Mar 2015 | Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking. | IT | Garante | GDPR | €3,000 | ↗ |
| 07 Nov 2018 | Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Dec 2021 | FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Oct 2016 | Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Feb 2018 | Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €22,400 | ↗ |
| 20 Oct 2022 | I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk. | IT | Garante | GDPR | €7,000 | ↗ |
| 14 Sept 2023 | GFB One s.r.l.GFB One s.r.l. was fined EUR 90,000 by the Italian Garante. The case concerned its failure to respond to requests for information relating to the unauthorized activation of SIM cards and the misuse of personal identification documents. | IT | Garante | GDPR | €90,000 | ↗ |