BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Jan 2010 | Centro Chirurgico s.r.l.Centro Chirurgico s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 6,000. The case concerned the collection of personal data through a website contact form without providing the required information notice to data subjects, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Feb 2015 | Comune di Castelvetrano SelinunteComune di Castelvetrano Selinunte was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The case involved a breach of data protection rules and the confidentiality of sensitive information. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Dec 2012 | Wire s.r.l.Wire s.r.l. was fined by the Garante in the amount of EUR 32,000 for making pre-recorded electoral propaganda calls without prior, specific, and informed consent from the recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 19 Dec 2024 | Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles. | IT | Garante | GDPR | €70,000 | ↗ |
| 06 Jul 2006 | I.C. Recruiting di Aldo Corradi & C. s.n.c.The company was fined EUR 258 by the Garante for failing to provide adequate information to data subjects in job advertisements. This constituted a breach of Article 13 of the Italian Codice Privacy. | IT | Garante | GDPR | €258 | ↗ |
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Mar 2015 | Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Feb 2024 | Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Mar 2021 | Unione dei Comuni Valli del Reno, Lavino e SamoggiaUnione dei Comuni Valli del Reno, Lavino e Samoggia was fined by the Garante EUR 13,000 for improperly publishing personal data on the web. The authority found a breach of GDPR principles on lawfulness and data processing. | IT | Garante | GDPR | €13,000 | ↗ |
| 20 Nov 2014 | Centro Nautico Tirreno s.r.l.Centro Nautico Tirreno s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice when collecting personal data through a web form. The authority found that individuals were not properly informed before their data was collected. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Jun 2014 | CO.RE.MA. di Gian Luigi Morando & C. s.a.s.CO.RE.MA. was fined by the Garante EUR 12,000 for using an integrated video surveillance system that allowed viewing images from workplaces. Required safeguards were not implemented, including logical separation of recordings from different data controllers. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Mar 2015 | Lo.Ma. S.r.l.Lo.Ma. S.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned the activation of SIM cards without the knowledge of the individuals concerned, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Apr 2021 | Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2015 | Okcom S.p.a.Okcom S.p.a. was fined EUR 40,000 by the Italian Garante. The authority found non-compliance with strong authentication requirements and a failure to notify the Garante about compliance with data protection measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Dec 2023 | Mushtaq RubinaThe Garante fined Mushtaq Rubina 2,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward recorded individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Feb 2016 | A.S.L. Roma 2A.S.L. Roma 2 was fined EUR 4,000 by the Garante for failing to respond to requests for information concerning the processing of personal data relating to a minor's civil disability. The authority found this to be a breach of Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di UdineOrdine delle Professioni Infermieristiche di Udine was fined 8,000 EUR by the Garante for breaches of data protection rules. The authority found improper disclosure of data to third parties and a failure to provide proper information to data subjects. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Jun 2023 | Ew Business Machines S.p.A.Ew Business Machines S.p.A. was fined 20,000 EUR by the Garante. The authority found that the company used a surveillance system without proper notice, collected employee fingerprints, and tracked employee locations through mobile apps without adequate transparency. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 May 2022 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures. | IT | Garante | GDPR | €7,000 | ↗ |
| 02 Jul 2015 | Lu JiruiLu Jirui was fined EUR 2,400 by the Garante for processing personal data through a video surveillance system without providing the required information to data subjects. The breach concerned Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |