BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Oct 2025 | Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Sept 2025 | RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 06 Oct 2022 | Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online. | IT | Garante | GDPR | €15,000 | ↗ |
| 19 Sept 2013 | Impresa Individuale Oriana Grandi EventiThe company was fined for collecting personal data through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Mar 2013 | Paolo RanieriPaolo Ranieri was fined 6,400 EUR by the Italian data protection authority, Garante. The sanction concerned sending an electoral email without the required information and without obtaining consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 30 Jan 2025 | Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Apr 2014 | Armando ChessaArmando Chessa was fined by the Garante for failing to provide adequate information about the use of a video surveillance system. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Dec 2017 | Telenando di Sannino Caterina e C s.a.s.Telenando di Sannino Caterina e C s.a.s. was fined by the Garante EUR 30,000 for registering phone cards to unaware third parties without their consent. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Feb 2021 | Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data. | IT | Garante | GDPR | €45,000 | ↗ |
| 20 Mar 2014 | Liguria Radiologia s.r.lLiguria Radiologia s.r.l was fined by the Garante EUR 16,000 for breaching data protection rules. The company improperly communicated patient data to third parties without adequate consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 09 Jul 2020 | Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2018 | SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Jun 2015 | San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data. | IT | Garante | GDPR | €24,000 | ↗ |
| 19 Feb 2015 | HHHH was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 20 Feb 2014 | Magazzini Gabrielli s.p.a.Magazzini Gabrielli s.p.a. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Oct 2024 | Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed. | IT | Garante | GDPR | €6,500 | ↗ |
| 29 Jan 2026 | Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 19 Oct 2017 | A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Nov 2008 | Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Jul 2018 | CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €12,400 | ↗ |