BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Jan 2017 | Perrone Rosaria e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriestePerrone Rosaria and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste were fined by the Garante 20,000 EUR. The sanction concerned unauthorized access by medical staff to personal health data, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk. | IT | Garante | GDPR | €35,000 | ↗ |
| 17 Jul 2024 | IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2014 | Comune di SparaniseComune di Sparanise was fined for unlawfully publishing personal data, including IBAN and bank account details, on its institutional website without a legal basis. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Jul 2023 | Prodav s.r.l.Prodav s.r.l. was fined by the Garante 1,000 EUR for operating a surveillance camera without the required informational signage and safeguards. The case concerned non-compliance with data protection rules and the duty to inform individuals under surveillance. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Apr 2018 | Emanuele CollaEmanuele Colla was fined by the Garante for activating seven phone cards without the consent of the person whose data was used. The case concerns a breach of data protection rules and the unauthorized use of personal data. | IT | Garante | GDPR | €16,000 | ↗ |
| 18 Apr 2018 | Futur3 s.r.l.Futur3 s.r.l. was fined EUR 50,000 by the Garante for requiring users to give mandatory consents for marketing and profiling purposes that were not directly related to the requested Wi‑Fi service. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 08 Jun 2023 | AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 May 2011 | Jnternet srlJnternet srl was fined by the Italian data protection authority, Garante, in the amount of EUR 10,000. The case concerned the failure to respond to requests for information about compliance with data protection obligations in connection with promotional emails sent without proper consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Dec 2012 | Regione Emilia RomagnaRegione Emilia Romagna was fined EUR 14,000 by the Garante for unlawfully disseminating personal data through the Regional Student Registry without a legal basis. The authority also found unauthorized retention of sensitive student data. | IT | Garante | GDPR | €14,000 | ↗ |
| 04 Apr 2013 | Stifter Josef KGStifter Josef KG was fined 2,400 EUR by the Garante. The company failed to provide the required data protection notice to customers when collecting personal data during online orders. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Mar 2015 | Antonianum s.r.l.Antonianum s.r.l. was fined EUR 8,000 by the Garante. The authority found that consent flags for data processing were pre-set on the company’s websites, which did not meet user consent requirements. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Jul 2018 | Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Oct 2013 | TeleTu s.p.a.TeleTu s.p.a. was fined 60,000 EUR by the Italian Garante. The sanction concerned unsolicited promotional phone calls made without the required consent of the data subject. | IT | Garante | GDPR | €60,000 | ↗ |
| 27 Jan 2021 | Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Jul 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 22 May 2014 | Tenacta Group s.p.a.Tenacta Group s.p.a. was fined €10,000 by the Garante for making an unsolicited promotional phone call. The conduct breached the complainant’s right to object, as recorded in the public opt-out list. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Oct 2012 | Casa di cura Eretenia S.p.a.The Garante fined Casa di cura Eretenia S.p.a. €30,000 for failing to provide proper data protection notices in its video surveillance system. The authority found a breach of privacy rules and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Sept 2013 | Iniziative Commerciali S.r.l.Iniziative Commerciali S.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This breached the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 02 Mar 2023 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality. | IT | Garante | GDPR | €50,000 | ↗ |