BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Feb 2026 | Comune di AversaThe Garante fined Comune di Aversa 3,000 EUR for failing to communicate the contact details of the Data Protection Officer. The case concerns Article 37 GDPR and the obligation to make DPO contact information available. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Mar 2011 | Nuova Demolizione Sas di Saviotti GaetanoNuova Demolizione Sas was fined by the Garante 6,000 EUR for sending unsolicited promotional faxes without proper consent. The conduct breached data protection and direct marketing rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Jun 2023 | Futuro Molise S.r.l.Futuro Molise S.r.l. was fined EUR 2,000 by the Garante for publishing an article that contained personal data without demonstrating a public interest basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 May 2017 | Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 11 Jan 2024 | Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities. | IT | Garante | GDPR | €50,000 | ↗ |
| 22 Nov 2012 | Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 06 Feb 2020 | R.T.I. - Reti Televisive Italiane s.p.a.R.T.I. - Reti Televisive Italiane s.p.a. was fined EUR 20,000 by the Garante for broadcasting a segment on “Le Iene”. The segment made the complainant identifiable through her voice and personal information, breaching data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Apr 2026 | Pak StorePak Store was fined EUR 2,000 by the Garante for using a CCTV camera without the required signage and without the necessary authorization from the Labour Inspectorate. The authority found a breach of the information obligations under GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 05 Apr 2018 | Comune di Magliano SabinaThe Municipality of Magliano Sabina was fined 10,000 EUR by the Garante for unlawfully disclosing personal data to a private educational institution without a valid legal basis. The authority found that this conduct breached the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225084]The Garante fined a retail business for failing to provide adequate informational signage for its video surveillance system. The authority found a breach of data protection rules because individuals on the premises were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Sept 2011 | XY s.r.l.XY s.r.l. was fined by the Garante in the amount of EUR 10,400 for sending an unsolicited promotional fax. The conduct breached data protection and marketing communication rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 07 Apr 2022 | Rebirth s.r.l.Rebirth s.r.l. was fined by the Garante EUR 15,000 for operating a video surveillance system at “Caffè Antica Roma” in a manner that did not comply with data protection rules. The conduct breached the GDPR and provisions of the Italian Privacy Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Jul 2020 | Istituto Comprensivo Statale Crucoli TorrettaIstituto Comprensivo Statale Crucoli Torretta was fined EUR 2,000 by the Garante for unlawfully publishing a list of students on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 May 2016 | Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The case concerned a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Mar 2026 | Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Feb 2025 | Comune di SciaccaThe Garante fined Comune di Sciacca EUR 2,500 for violations related to the processing of personal data. The case concerned the communication of data to third parties without a proper legal basis. | IT | Garante | GDPR | €2,500 | ↗ |
| 06 Apr 2017 | Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Apr 2011 | Iniziative immobiliari s.p.a.Iniziative immobiliari s.p.a. was fined 20,000 EUR by the Garante. The authority found that the company collected personal data through a website form without providing adequate information and failed to appoint data processing personnel or implement minimum security measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Mar 2018 | Lombardia Informatica S.p.A.Lombardia Informatica S.p.A. was fined EUR 40,000 by the Garante for allowing unauthorized access to personal data through its portal. The case concerned a breach of data protection rules and indicated insufficient access controls. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Mar 2021 | Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |