BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Sept 2015 | Jackpot srlJackpot srl was fined for failing to respond to a request for information within the required timeframe. This constituted a breach of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Oct 2013 | ICA Foods S.p.a.ICA Foods S.p.a. was fined by the Garante for installing a video surveillance system without providing employees with adequate information. The conduct breached privacy rules and the information obligations applicable to monitored persons. | IT | Garante | GDPR | €2,400 | ↗ |
| 09 May 2018 | Telefonika s.r.l.sTelefonika s.r.l.s was fined by the Italian data protection authority, Garante, in the amount of EUR 42,000. The sanction concerned numerous unsolicited promotional phone calls made without proper consent. | IT | Garante | GDPR | €42,000 | ↗ |
| 22 Dec 2016 | Comune di VergatoComune di Vergato was fined by the Garante for retaining surveillance footage beyond the permitted period. The case concerned non-compliance with data protection rules on storage limitation and video retention. | IT | Garante | GDPR | €12,000 | ↗ |
| 02 Apr 2015 | Comune di AccianoComune di Acciano was fined 4,000 EUR by the Garante for unlawfully processing personal data by keeping a council resolution online beyond the legally permitted period. The case concerned non-compliance with data protection rules on retention and publication limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Mar 2026 | INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Oct 2017 | Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 23 Nov 2017 | AMAT PALERMO S.P.A.AMAT PALERMO S.P.A. was fined by the Garante 20,000 EUR for failing to properly notify the use of a geolocation system to track vehicles. The authority found a breach of the Italian data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Jan 2018 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement. | IT | Garante | GDPR | €60,000 | ↗ |
| 28 Jun 2018 | ANSORGE LOGISTICA ITALIA S.r.l.ANSORGE LOGISTICA ITALIA S.r.l. was fined EUR 8,000 by the Garante. The case concerned employee geolocation carried out without proper compliance with data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 17 Mar 2016 | Gruppo Scuole s.r.l. – Istituto Giuseppe Mazzini di AvezzanoGruppo Scuole s.r.l. was fined by the Garante for collecting personal data through its website without providing the required privacy notice and without obtaining consent. The authority found violations of Articles 13 and 23 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object. | IT | Garante per la protezione dei dati personali | GDPR | €80,000 | ↗ |
| 18 Apr 2018 | Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Jun 2011 | Fastrent Money srlFastrent Money srl was fined by the Garante EUR 6,000 for sending unsolicited commercial faxes. The authority also found that the required data protection information under Article 13 of the Italian Data Protection Code was not provided. | IT | Garante | GDPR | €6,000 | ↗ |
| 24 Oct 2013 | Stadek sncStadek snc was fined EUR 4,000 by the Garante for non-compliant video surveillance signage. The case concerns a breach of data protection requirements related to informing individuals about surveillance. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Mar 2015 | Azienda Ospedaliera Bolognini di SeriateAzienda Ospedaliera Bolognini di Seriate was fined by the Garante for sending medical reports to an incorrect address without the patient's consent. The case involved a breach of data protection rules and the confidentiality of medical information. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Feb 2013 | Terme Forlenza di Forlenza Ferruccio & C. s.n.c.Terme Forlenza was fined EUR 4,800 by the Italian Garante. The case concerned the failure to provide the required privacy notice when collecting personal data through the hotel booking form on its website. | IT | Garante | GDPR | €4,800 | ↗ |
| 28 Feb 2019 | Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Jul 2022 | Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Dec 2017 | Rotondi AndreaAndrea Rotondi was fined for the improper handling of banking documents that were found by a private citizen. Banca Nazionale del Lavoro was held jointly liable for the violation. | IT | Garante | GDPR | €4,000 | ↗ |