BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Feb 2016 | A.S.L. Roma 2A.S.L. Roma 2 was fined EUR 4,000 by the Garante for failing to respond to requests for information concerning the processing of personal data relating to a minor's civil disability. The authority found this to be a breach of Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di UdineOrdine delle Professioni Infermieristiche di Udine was fined 8,000 EUR by the Garante for breaches of data protection rules. The authority found improper disclosure of data to third parties and a failure to provide proper information to data subjects. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Jun 2023 | Ew Business Machines S.p.A.Ew Business Machines S.p.A. was fined 20,000 EUR by the Garante. The authority found that the company used a surveillance system without proper notice, collected employee fingerprints, and tracked employee locations through mobile apps without adequate transparency. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 May 2022 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures. | IT | Garante | GDPR | €7,000 | ↗ |
| 02 Jul 2015 | Lu JiruiLu Jirui was fined EUR 2,400 by the Garante for processing personal data through a video surveillance system without providing the required information to data subjects. The breach concerned Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Jul 2013 | Naturmedia s.r.l.Naturmedia s.r.l. was fined EUR 2,400 by the Italian Garante. The case concerned the collection of personal data without providing the required information notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 19 Jul 2018 | Idroservice Italia s.r.l.Idroservice Italia s.r.l. was fined by the Garante for failing to respond to a request for information. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2011 | Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Jun 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights. | IT | Garante | GDPR | €40,660 | ↗ |
| 04 Jul 2024 | Provvedimento del 4 luglio 2024 [10068075]The Garante imposed a EUR 400 fine on an individual for improperly installing a surveillance system. The cameras captured public street areas, which breached privacy rules. | IT | Garante | GDPR | €400 | ↗ |
| 30 Jan 2025 | Guru Nanak s.r.l.s.Guru Nanak s.r.l.s. was fined by the Garante EUR 1,000 for the non-compliant installation of a video surveillance system. The cameras captured areas beyond the company’s premises, creating a privacy and data protection breach. | IT | Garante | GDPR | €1,000 | ↗ |
| 26 Jul 2018 | Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 04 Jun 2015 | Comune di Vico EquenseThe Municipality of Comune di Vico Equense was fined 20,000 EUR by the Garante. The authority found that the security program document was not updated and data processing officers were not appointed, which allowed unauthorized access to sensitive data. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Jul 2016 | Ordine degli Ingegneri della Provincia di CasertaOrdine degli Ingegneri della Provincia di Caserta was fined by the Garante for failing to respond to requests for information about the processing of employees’ sensitive personal data. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Mar 2025 | Azienda sanitaria territoriale di MacerataAzienda sanitaria territoriale di Macerata was fined 5,000 EUR by the Garante for failing to comply with data access requests and for breaches of data protection rules. The case concerned the processing of health data and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 May 2022 | Università Agraria di NettunoUniversità Agraria di Nettuno was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found unlawful handling of personal data, including failures in lawfulness, fairness, transparency, and data minimization, involving information publicly accessible online since 2019. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jun 2013 | Mafeco S.r.l.Mafeco S.r.l. was fined by the Garante in the amount of EUR 6,000 for failing to provide the required privacy notice when collecting personal data through website forms. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Mar 2015 | Comune di BasicòComune di Basicò was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of data protection rules and the confidentiality of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Feb 2016 | Decatel s.r.l.Decatel s.r.l. was fined €10,000 by the Italian Garante. The case concerned the processing and retention of telephone traffic data without the required safeguards, including biometric recognition and strong authentication. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jan 2015 | Comune di SidernoComune di Siderno was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The conduct breached privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |