BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Jan 2022 | Villa Masi Residenza per anzianiVilla Masi Residenza per anziani was fined EUR 1,000 by the Garante for a video surveillance system that did not comply with GDPR Article 13. The authority found that the required information notices for monitored individuals were not properly provided. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Mar 2026 | ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €50,000 | ↗ |
| 12 Sept 2024 | Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request. | IT | Garante | GDPR | €15,000 | ↗ |
| 07 Mar 2024 | Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Feb 2021 | Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 May 2019 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 4,000 for violations linked to data processing through public service apps. The authority found that adequate data protection and security measures were not ensured. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Feb 2018 | Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Mar 2017 | MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Oct 2022 | Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2016 | Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Mar 2015 | Comune di SortinoComune di Sortino was fined for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the improper disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Jan 2016 | Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2016 | Planet Book Service di Mario Manna & C. s.a.s.Planet Book Service di Mario Manna & C. s.a.s. was fined by the Garante for failing to respond to an information request. The conduct breached Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Jul 2006 | Vascotto RobertoThe sole proprietorship Vascotto Roberto was fined EUR 1,549 by the Garante for breaching data protection rules. The authority found that data subjects were not provided with the information required by law. | IT | Garante | GDPR | €1,549 | ↗ |
| 18 May 2017 | Terrecablate reti e servizi s.r.l.Terrecablate reti e servizi s.r.l. was fined by the Garante €10,000 for inadequate security measures. The violation concerned weak password authentication on servers storing telephone traffic data. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2024 | Grafiche E.The Garante imposed a fine of EUR 12,000 on Grafiche E. for violations of data protection rules. The case concerned non-compliance with regulatory requirements for the processing of personal data. | IT | Garante | GDPR | €12,000 | ↗ |
| 10 Nov 2022 | Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 May 2015 | Pelamatti GiacomoPelamatti Giacomo was fined by the Garante EUR 10,000 for activating phone cards in the names of individuals without their knowledge. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2024 | Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR. | IT | Garante | GDPR | €10,000 | ↗ |