BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Jul 2023 | AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €40,000 | ↗ |
| 04 Oct 2011 | Mancosu Editore s.r.l.Mancosu Editore s.r.l. was fined by the Garante 10,400 EUR for sending promotional emails without providing the required information to data subjects and without obtaining explicit consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,400 | ↗ |
| 28 Jul 2016 | Rigamonti s.r.l.Rigamonti s.r.l. was fined 4,000 EUR by the Garante for sending promotional SMS messages without obtaining the recipient’s prior specific consent. The conduct breached data protection rules governing direct marketing. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jul 2021 | Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale città di MilanoAzienda sanitaria locale città di Milano was fined by the Garante EUR 20,000 for improperly processing personal data concerning health and sexual life without adequate safeguards. The authority found that the processing breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Sept 2024 | Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 14 Oct 2021 | Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Dec 2022 | Azienda Universitaria Friuli OccidentaleAzienda Universitaria Friuli Occidentale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found that the organization failed to provide required information about data deletion, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €55,000 | ↗ |
| 29 Oct 2020 | Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration. | IT | Garante | GDPR | €8,000 | ↗ |
| 17 Jan 2013 | Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Feb 2016 | Banco dell'oro Operatori professionali in oro srlBanco dell'oro Operatori professionali in oro srl was fined by the Garante EUR 2,400 for operating a video surveillance system without the required data protection notice. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Sept 2008 | Scip ItaliaScip Italia was fined EUR 3,000 by the Garante for sending unsolicited commercial material by mail. The authority found that the company did not provide the data subject with adequate information required under the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 19 Jul 2018 | Go Internet S.p.AGo Internet S.p.A was fined by the Garante in the amount of 40,000 EUR for processing and retaining telephone and internet traffic data beyond the permitted period. The authority found this conduct contrary to the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 28 Apr 2022 | Comune di TarantoComune di Taranto was fined by the Garante in the amount of EUR 20,000 for violations related to the installation of surveillance cameras without proper data protection measures. The authority found a lack of transparency and a failure to provide the required information to data subjects. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Jun 2008 | Loga s.r.l.Loga s.r.l. was fined by the Garante for operating a video surveillance system without providing the required information to individuals. The case concerned a breach of privacy law information obligations. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Nov 2024 | Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jul 2006 | Work Safety Training Italia s.r.l.Work Safety Training Italia s.r.l. was fined by the Garante for sending unsolicited promotional emails. The authority found that the company failed to provide adequate information about data processing, breaching the information duty under data protection rules. | IT | Garante | GDPR | €1,549 | ↗ |