BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Nov 2017 | Ricciotti CorradoRicciotti Corrado was fined by the Garante 4,000 EUR for violations related to personal data protection. The case involved improper handling of banking documentation. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Dec 2016 | Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad. | IT | Garante | GDPR | €72,000 | ↗ |
| 25 Sept 2025 | Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Jul 2014 | Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 23 Jan 2020 | Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5. | IT | Garante | GDPR | €80,000 | ↗ |
| 17 Mar 2016 | Belzirossi s.r.l.Belzirossi s.r.l. was fined by the Italian Garante in the amount of EUR 2,400. The case concerned the use of a video surveillance system without providing data subjects with the required information under data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Jan 2022 | Musicraiser S.r.l.Musicraiser S.r.l. was fined 1,000 EUR by the Garante for continuing to send newsletters to a user despite multiple requests to be removed. The case concerns a breach of data protection rules on respecting opt-out and cancellation requests for marketing communications. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Jul 2025 | Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Nov 2008 | Castaldo intermediazione immobiliare di Antonia Romeo e Roberto Castaldo s.n.c.The company was fined by the Garante 6,000 EUR for failing to provide adequate information to data subjects about the processing of personal data collected through its website. The case concerned a breach of the information duties under the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Nov 2008 | Silvia BriggiSilvia Briggi, a financial consultant, was fined EUR 3,000 by the Garante. The authority found that clients were not provided with the required data protection information under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 Mar 2018 | SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Jun 2014 | Ecaterina GypjasEcaterina Gypjas was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system in her hotel. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Mar 2010 | Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €24,000 | ↗ |
| 25 Mar 2021 | TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data. | IT | Garante | GDPR | €7,000 | ↗ |
| 17 Apr 2026 | Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 24 Nov 2022 | Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 19 Jan 2011 | Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 23 Oct 2025 | Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization. | IT | Garante | GDPR | €15,000 | ↗ |
| 28 Sept 2023 | Giuseppe AnzaloneThe Garante imposed a EUR 5,000 fine on Giuseppe Anzalone for breaches of personal data processing rules. The case concerned patient data and involved failures to comply with lawfulness, fairness, transparency, data minimization, integrity, and confidentiality principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 May 2023 | Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |