BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Sept 2013 | Ri.Dat. di Boldetti RenatoRi.Dat. di Boldetti Renato was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional emails without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Aug 2023 | GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Mar 2023 | H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach. | IT | Garante | GDPR | €50,000 | ↗ |
| 12 Sept 2024 | Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15. | IT | Garante | GDPR | €5,000 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 19 Dec 2024 | Altroconsumo Edizioni S.r.l.Altroconsumo Edizioni S.r.l. was fined by the Garante EUR 60,000 for sending unsolicited marketing emails despite unsubscribe requests. The authority also found deficiencies in obtaining valid consent and in the handling of personal data by third-party affiliates involved in the campaign. | IT | Garante | GDPR | €60,000 | ↗ |
| 18 Apr 2013 | Digital Design di Patron AndreaDigital Design di Patron Andrea was fined 2,400 EUR by the Garante. The authority found that the website's contact form lacked the required data protection information, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Mar 2015 | Artsana s.p.a.Artsana s.p.a. was fined by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Jan 2016 | Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Sept 2011 | Aga s.r.l.Aga s.r.l. was fined EUR 8,000 by the Garante for processing online customers' personal data without ensuring freely given and specific consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 21 Jan 2016 | Federico FabiFederico Fabi was fined by the Garante for failing to provide the required information to data subjects when collecting personal data through forms on the company’s website. The case concerns a breach of transparency and notice obligations under data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 09 May 2024 | Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 02 Mar 2017 | Trilogy s.r.l.Trilogy s.r.l. and Fastweb s.p.a. were fined for making unsolicited promotional calls to a phone number listed in the public opt-out register. The conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Nov 2024 | Comune di Borgo Val di TaroComune di Borgo Val di Taro was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 08 Sept 2016 | Pan YinpinPan Yinpin was fined 2,400 EUR by the Garante. The authority found that data subjects were not informed about the processing of personal data through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Feb 2024 | Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER)The Garante fined Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER) EUR 6,000. The authority found that the organization failed to appoint a Data Protection Officer in a timely manner, despite the GDPR requirement being in force for about three years. | IT | Garante | GDPR | €6,000 | ↗ |
| 30 Jul 2015 | Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jun 2025 | impresa individuale Pasquale GuadagnoThe company was fined for installing a surveillance camera without proper signage. The camera also captured areas beyond its commercial premises, which breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 11 Dec 2008 | Comune di PontenureComune di Pontenure was fined EUR 3,000 by the Garante for failing to provide the required data protection notice when sending a questionnaire about waste management tariffs. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 07 Dec 2023 | Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card. | IT | Garante | GDPR | €1,000 | ↗ |