BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Dec 2012 | Azienda sanitaria regionale MoliseThe Regional Health Company of Molise was fined for failing to designate data processing officers for each employee. The authority also found that minimum security measures for electronic processing were not implemented, including weak password policies and insufficient protection against unauthorized external access. | IT | Garante | GDPR | €15,000 | ↗ |
| 15 Feb 2018 | Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Nov 2022 | Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Dec 2022 | Altroconsumo Edizioni S.r.lAltroconsumo Edizioni S.r.l was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a proper legal basis. The authority also found that the company failed to provide adequate information and to obtain free and specific consent from data subjects. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Mar 2021 | Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance. | IT | Garante | GDPR | €4,501,000 | ↗ |
| 26 Jan 2011 | Doss s.a.s. di Mazza Mario & C.Doss s.a.s. was fined by the Garante EUR 6,000 for processing personal data without proper consent. The company purchased and used personal data lists for promotional mailings without an adequate legal basis. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Mar 2011 | Radio Casa s.r.l.Radio Casa s.r.l. was fined 8,000 EUR by the Garante for activating an automatic preselection service without the user's consent. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 08 May 2014 | Galleria Voci s.r.l.Galleria Voci s.r.l. was fined EUR 2,400 by the Garante for failing to provide simplified information about the use of a video surveillance system. The authority found this to be a breach of privacy and data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Jan 2010 | I.S.A. - Istituto Scolastico Ambrosiano s.n.c.I.S.A. - Istituto Scolastico Ambrosiano s.n.c. was fined EUR 6,000 by the Garante. The case concerned the collection of personal data through its website without providing users with adequate information required under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Nov 2012 | Eco Education s.r.l.Eco Education s.r.l. was fined by the Garante 10,400 EUR for sending promotional faxes without prior, specific, and informed consent from recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 16 Sept 2021 | Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Dec 2010 | Eraclea Minoa Village s.r.l.Eraclea Minoa Village s.r.l. was fined 6,000 EUR by the Garante for collecting personal data through its website without providing the required privacy notice. The case concerned a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Mar 2026 | Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 15 Dec 2022 | Verizon Connect Italy S.p.A.Verizon Connect Italy S.p.A. was fined EUR 30,000 by the Garante for violations linked to the unauthorized installation of a geolocation device in a vehicle. The authority found that the processing of personal data breached GDPR requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Oct 2015 | San Vincenzo di Fernando Rota s.r.l.San Vincenzo di Fernando Rota s.r.l. was fined by the Garante for processing employees’ biometric data without notifying the authority and without requesting prior verification. The conduct breached privacy rules and the requirements applicable to sensitive data processing. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jun 2020 | Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Nov 2010 | Fitness Solution società sportiva dilettantistica s.r.l.Fitness Solution was fined EUR 10,000 by the Garante. The authority found that biometric personal data were processed without proper consent and retained longer than necessary. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data. | IT | Garante | GDPR | €70,000 | ↗ |
| 29 Apr 2021 | Azienda Ospedaliero Universitaria PisanaAzienda Ospedaliero Universitaria Pisana was fined by the Garante EUR 4,000 for breaches of the principles of lawfulness, fairness, transparency, integrity, and confidentiality in data processing. The case concerned improper handling of personal data under GDPR requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Oct 2013 | Continental Terme srlContinental Terme srl was fined EUR 12,400 by the Garante for providing inadequate privacy notices and obtaining a single consent for multiple data processing activities. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €12,400 | ↗ |