BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jan 2026 | Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA). | IT | Garante | GDPR | €50,000 | ↗ |
| 26 Sept 2024 | Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status. | IT | Garante | GDPR | €17,000 | ↗ |
| 26 Nov 2020 | Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Apr 2021 | Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Apr 2015 | Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Jul 2015 | Roberto NaccaratoRoberto Naccarato was fined by the Garante for processing the personal data of 12 individuals without providing proper information or obtaining consent. The authority found this to be a breach of Italian data protection law. | IT | Garante | GDPR | €76,800 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details. | IT | Garante | GDPR | €100,000 | ↗ |
| 11 Jan 2024 | Comune di SiracusaThe Garante fined Comune di Siracusa €5,000 for breaches of data protection obligations under Article 37 GDPR. The case concerned failures related to the appointment and management of the data protection officer requirement. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 Jul 2006 | La Locanda dei f.lli Rosafio Gianfranco, Adriano e Mauro s.n.c.The company was fined for sending unsolicited promotional emails without providing recipients with the required information on data processing. The authority found a breach of the information obligation under data protection law. | IT | Garante | GDPR | €1,549 | ↗ |
| 24 Apr 2024 | C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Jul 2020 | Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 11 Apr 2013 | I.S.P. Italia srlI.S.P. Italia srl was fined by the Garante for sending unsolicited promotional faxes without the required information notice and without obtaining recipients’ consent. The authority found that the conduct breached rules on prior consent and information duties. | IT | Garante | GDPR | €32,000 | ↗ |
| 17 Jul 2024 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing. | IT | Garante | GDPR | €50,000 | ↗ |
| 24 Apr 2024 | Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Dec 2024 | Wind Tre S.p.A.Wind Tre S.p.A. was fined €347,520 by the Garante for violations related to processing personal data for promotional purposes and for inadequate technical and organizational measures. The case concerned telemarketing activities and the protection of the data involved. | IT | Garante | GDPR | €347,000 | ↗ |
| 10 Jul 2025 | Poste Vita S.p.a.Poste Vita S.p.a. was fined EUR 80,000 by the Garante for unlawfully disclosing personal data relating to life insurance policies to an unauthorized third party. The data were then used in judicial proceedings. | IT | Garante | GDPR | €80,000 | ↗ |
| 01 Jun 2023 | Comune di NapoliComune di Napoli was fined for improperly communicating performance evaluation results of former employees. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 02 Feb 2012 | Casa di cura Villa Giustina s.r.l.Casa di cura Villa Giustina s.r.l. was fined 40,000 EUR by the Garante. The authority found that the company failed to submit the required notification for personal data processing activities under the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Dec 2014 | Ferreri Costruzioni s.r.l.Ferreri Costruzioni s.r.l. was fined EUR 2,400 by the Garante for failing to provide data subjects with the required information about data processing through web forms on its website. The conduct breached Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 30 Nov 2023 | Techno Security s.r.l.Techno Security s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to respond to a data subject request and for inadequate security measures in its installed security system. The authority found that these failures breached data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |