BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Sept 2014 | Happy Fit s.r.l.Happy Fit s.r.l. was fined by the Garante in the amount of EUR 16,400 for making an unsolicited promotional phone call. The company did not provide the required information or obtain consent, breaching data protection rules. | IT | Garante | GDPR | €16,400 | ↗ |
| 04 Jun 2025 | Comune di ReccoThe Garante fined Comune di Recco EUR 5,000 for inadequate data protection measures linked to video surveillance used to monitor waste disposal. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 19 Dec 2024 | Comune di LevantoThe Garante fined Comune di Levanto 4,000 EUR for data protection breaches linked to video surveillance systems. The authority found violations of the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Mar 2008 | W.I. mind consulting s.r.l.W.I. mind consulting s.r.l. was fined by the Garante 6,000 EUR for sending unsolicited advertising by fax. The authority found that prior and adequate information required under Article 13 of the Italian Data Protection Code was not provided. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Jan 2025 | Comune di PaternòThe Garante fined Comune di Paternò EUR 6,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €6,000 | ↗ |
| 21 Jan 2010 | Centro Chirurgico s.r.l.Centro Chirurgico s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 6,000. The case concerned the collection of personal data through a website contact form without providing the required information notice to data subjects, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Feb 2015 | Comune di Castelvetrano SelinunteComune di Castelvetrano Selinunte was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The case involved a breach of data protection rules and the confidentiality of sensitive information. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Dec 2012 | Wire s.r.l.Wire s.r.l. was fined by the Garante in the amount of EUR 32,000 for making pre-recorded electoral propaganda calls without prior, specific, and informed consent from the recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 19 Dec 2024 | Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles. | IT | Garante | GDPR | €70,000 | ↗ |
| 06 Jul 2006 | I.C. Recruiting di Aldo Corradi & C. s.n.c.The company was fined EUR 258 by the Garante for failing to provide adequate information to data subjects in job advertisements. This constituted a breach of Article 13 of the Italian Codice Privacy. | IT | Garante | GDPR | €258 | ↗ |
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Mar 2015 | Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Feb 2024 | Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Mar 2021 | Unione dei Comuni Valli del Reno, Lavino e SamoggiaUnione dei Comuni Valli del Reno, Lavino e Samoggia was fined by the Garante EUR 13,000 for improperly publishing personal data on the web. The authority found a breach of GDPR principles on lawfulness and data processing. | IT | Garante | GDPR | €13,000 | ↗ |
| 20 Nov 2014 | Centro Nautico Tirreno s.r.l.Centro Nautico Tirreno s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice when collecting personal data through a web form. The authority found that individuals were not properly informed before their data was collected. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Jun 2014 | CO.RE.MA. di Gian Luigi Morando & C. s.a.s.CO.RE.MA. was fined by the Garante EUR 12,000 for using an integrated video surveillance system that allowed viewing images from workplaces. Required safeguards were not implemented, including logical separation of recordings from different data controllers. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Mar 2015 | Lo.Ma. S.r.l.Lo.Ma. S.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned the activation of SIM cards without the knowledge of the individuals concerned, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Apr 2021 | Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2015 | Okcom S.p.a.Okcom S.p.a. was fined EUR 40,000 by the Italian Garante. The authority found non-compliance with strong authentication requirements and a failure to notify the Garante about compliance with data protection measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Dec 2023 | Mushtaq RubinaThe Garante fined Mushtaq Rubina 2,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward recorded individuals. | IT | Garante | GDPR | €2,000 | ↗ |