BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Apr 2014 | Armando ChessaArmando Chessa was fined by the Garante for failing to provide adequate information about the use of a video surveillance system. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Dec 2017 | Telenando di Sannino Caterina e C s.a.s.Telenando di Sannino Caterina e C s.a.s. was fined by the Garante EUR 30,000 for registering phone cards to unaware third parties without their consent. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Feb 2021 | Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data. | IT | Garante | GDPR | €45,000 | ↗ |
| 20 Mar 2014 | Liguria Radiologia s.r.lLiguria Radiologia s.r.l was fined by the Garante EUR 16,000 for breaching data protection rules. The company improperly communicated patient data to third parties without adequate consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 09 Jul 2020 | Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2018 | SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Jun 2015 | San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data. | IT | Garante | GDPR | €24,000 | ↗ |
| 19 Feb 2015 | HHHH was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 20 Feb 2014 | Magazzini Gabrielli s.p.a.Magazzini Gabrielli s.p.a. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Oct 2024 | Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed. | IT | Garante | GDPR | €6,500 | ↗ |
| 29 Jan 2026 | Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 19 Oct 2017 | A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Nov 2008 | Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Jul 2018 | CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €12,400 | ↗ |
| 12 Feb 2026 | Comune di AversaThe Garante fined Comune di Aversa 3,000 EUR for failing to communicate the contact details of the Data Protection Officer. The case concerns Article 37 GDPR and the obligation to make DPO contact information available. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Mar 2011 | Nuova Demolizione Sas di Saviotti GaetanoNuova Demolizione Sas was fined by the Garante 6,000 EUR for sending unsolicited promotional faxes without proper consent. The conduct breached data protection and direct marketing rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Jun 2023 | Futuro Molise S.r.l.Futuro Molise S.r.l. was fined EUR 2,000 by the Garante for publishing an article that contained personal data without demonstrating a public interest basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 May 2017 | Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 11 Jan 2024 | Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities. | IT | Garante | GDPR | €50,000 | ↗ |
| 22 Nov 2012 | Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |