BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Jan 2022 | Musicraiser S.r.l.Musicraiser S.r.l. was fined 1,000 EUR by the Garante for continuing to send newsletters to a user despite multiple requests to be removed. The case concerns a breach of data protection rules on respecting opt-out and cancellation requests for marketing communications. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Jul 2025 | Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Nov 2008 | Castaldo intermediazione immobiliare di Antonia Romeo e Roberto Castaldo s.n.c.The company was fined by the Garante 6,000 EUR for failing to provide adequate information to data subjects about the processing of personal data collected through its website. The case concerned a breach of the information duties under the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Nov 2008 | Silvia BriggiSilvia Briggi, a financial consultant, was fined EUR 3,000 by the Garante. The authority found that clients were not provided with the required data protection information under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 Mar 2018 | SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Jun 2014 | Ecaterina GypjasEcaterina Gypjas was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system in her hotel. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Mar 2010 | Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €24,000 | ↗ |
| 25 Mar 2021 | TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data. | IT | Garante | GDPR | €7,000 | ↗ |
| 17 Apr 2026 | Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 24 Nov 2022 | Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 19 Jan 2011 | Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 23 Oct 2025 | Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization. | IT | Garante | GDPR | €15,000 | ↗ |
| 28 Sept 2023 | Giuseppe AnzaloneThe Garante imposed a EUR 5,000 fine on Giuseppe Anzalone for breaches of personal data processing rules. The case concerned patient data and involved failures to comply with lawfulness, fairness, transparency, data minimization, integrity, and confidentiality principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 May 2023 | Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Oct 2025 | Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Sept 2025 | RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 06 Oct 2022 | Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online. | IT | Garante | GDPR | €15,000 | ↗ |
| 19 Sept 2013 | Impresa Individuale Oriana Grandi EventiThe company was fined for collecting personal data through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Mar 2013 | Paolo RanieriPaolo Ranieri was fined 6,400 EUR by the Italian data protection authority, Garante. The sanction concerned sending an electoral email without the required information and without obtaining consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 30 Jan 2025 | Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks. | IT | Garante | GDPR | €10,000 | ↗ |