BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Sept 2007 | Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 May 2022 | Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach. | IT | Garante | GDPR | €16,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Mar 2025 | ImmosanremoImmosanremo was fined EUR 3,000 by the Garante for sending unsolicited marketing messages via WhatsApp without valid consent. The authority found that the conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €3,000 | ↗ |
| 26 Mar 2026 | Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Jun 2015 | SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Feb 2013 | Face2Face s.r.l.Face2Face s.r.l. was fined EUR 40,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide the required privacy notice and did not obtain specific consent from data subjects before processing their data. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Feb 2026 | Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28. | IT | Garante | GDPR | €3,000 | ↗ |
| 08 Nov 2012 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Mar 2026 | Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles. | IT | Garante | GDPR | €800 | ↗ |
| 23 Oct 2025 | Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Dec 2011 | dott. Mancini Endriodott. Mancini Endrio was fined EUR 8,000 by the Garante for violating data protection rules. The case concerned inadequate compliance with data security requirements under Article 162, paragraph 2-bis, of the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Nov 2012 | Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes. | IT | Garante | GDPR | €10,400 | ↗ |
| 25 Feb 2016 | Sol Levante s.r.l.Sol Levante s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 11 days. This exceeded the 7-day limit set out in the authority’s video surveillance guidelines. | IT | Garante | GDPR | €12,000 | ↗ |
| 28 May 2026 | AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles. | IT | Garante | GDPR | €55,000 | ↗ |
| 29 Jan 2026 | Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA). | IT | Garante | GDPR | €50,000 | ↗ |
| 26 Sept 2024 | Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status. | IT | Garante | GDPR | €17,000 | ↗ |
| 26 Nov 2020 | Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Apr 2021 | Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data. | IT | Garante | GDPR | €30,000 | ↗ |