BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Feb 2026 | Ministero delle Imprese e del Made in ItalyMinistero delle Imprese e del Made in Italy was fined by the Garante €15,000 for unlawfully publishing personal data in a ranking list. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 04 Apr 2013 | Kinesi s.r.l.Kinesi s.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through a website form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 25 Sept 2025 | Officine Serena s.r.l.Green.mec. s.r.l. did not respond to a data subject’s request for training certificates and communications related to the termination of employment. The Garante imposed a fine of 1,000 EUR on Officine Serena s.r.l., the incorporating company. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Apr 2013 | Cappellina FedericoCappellina Federico was fined by the Garante in the amount of 2,400 EUR for failing to provide the required privacy notice in a private club's video surveillance system. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Jan 2008 | La Dolce Vita s.r.l.La Dolce Vita s.r.l. was fined by the Garante for failing to respond to a request for access to personal data. The authority treated this as a breach of the Italian data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Sept 2014 | Alabarda Gestioni s.r.l.Alabarda Gestioni s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required information notice. This breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Jan 2008 | Deas Desideri e associati s.r.l.Deas Desideri e associati s.r.l. was fined €10,000 by the Garante for failing to notify the processing of sensitive personal data within the required timeframe. The authority found a breach of Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Nov 2016 | Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined for making an unauthorized advertising phone call. The company also failed to respond to information requests from the Garante. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Feb 2014 | Bar Falterona di Jin LiuminBar Falterona di Jin Liumin was fined by the Garante in the amount of EUR 2,400 for failing to provide adequate information about the use of a video surveillance system. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 20 Apr 2017 | Linea Com s.r.l.Linea Com s.r.l. was fined by the Garante EUR 40,000 for retaining customers' telephone and telematic traffic data beyond the legal retention periods. The authority found that the storage periods exceeded the limits set by data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 02 Feb 2017 | Yume s.r.l.Yume s.r.l. was fined by the Garante in the amount of 1,590,000 EUR for improper processing of personal data during money transfer operations. The authority found that techniques were used to obscure the true identity of the initiators of financial transactions. | IT | Garante | GDPR | €1,590,000 | ↗ |
| 23 Oct 2025 | Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Jun 2018 | EMMECI LOGISTICA S.r.l.EMMECI LOGISTICA S.r.l. was fined by the Garante 8,000 EUR for violations related to the processing of personal data. The case concerned the use of a geolocation system without the required compliance measures. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Jan 2024 | Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Nov 2024 | Mario IonàMario Ionà was fined EUR 2,000 by the Garante for sending unsolicited emails and SMS promoting a tutoring service. The website lezioniprivate.eu did not provide information about the data controller, which added an information-duty breach. | IT | Garante | GDPR | €2,000 | ↗ |
| 19 Jan 2017 | Perrone Rosaria e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriestePerrone Rosaria and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste were fined by the Garante 20,000 EUR. The sanction concerned unauthorized access by medical staff to personal health data, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk. | IT | Garante | GDPR | €35,000 | ↗ |
| 17 Jul 2024 | IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2014 | Comune di SparaniseComune di Sparanise was fined for unlawfully publishing personal data, including IBAN and bank account details, on its institutional website without a legal basis. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Jul 2023 | Prodav s.r.l.Prodav s.r.l. was fined by the Garante 1,000 EUR for operating a surveillance camera without the required informational signage and safeguards. The case concerned non-compliance with data protection rules and the duty to inform individuals under surveillance. | IT | Garante | GDPR | €1,000 | ↗ |