BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Oct 2012 | Abbanoa s.p.a.Abbanoa s.p.a. was fined EUR 28,000 by the Garante for failing to provide the required privacy notice in its video surveillance systems. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €28,000 | ↗ |
| 13 Feb 2025 | Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Jul 2015 | Chirco MicheleChirco Michele was fined for processing personal data through a video surveillance system without providing the required information notice to the data subjects. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 Apr 2022 | Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 May 2018 | Telecom Italia S.p.A.Telecom Italia S.p.A. was fined by the Garante €800,000 for the unauthorized activation of numerous residential phone lines in a citizen's name. The case involved processing and disclosing personal data without a legal basis, as well as failing to notify data breaches. | IT | Garante | GDPR | €800,000 | ↗ |
| 06 Oct 2022 | Associazione Rescue Drones Network ODVAssociazione Rescue Drones Network ODV was fined by the Garante in the amount of 3,000 EUR for failing to comply with data access requests. The authority treated this as a breach of GDPR Article 5. | IT | Garante | GDPR | €3,000 | ↗ |
| 10 Jan 2013 | Consodata S.p.A.Consodata S.p.A. was fined by the Garante 400,000 EUR for violations linked to unsolicited telemarketing. The authority also found that the company failed to provide individuals with proper data protection information. | IT | Garante | GDPR | €400,000 | ↗ |
| 11 Apr 2024 | Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack. | IT | Garante | GDPR | €25,000 | ↗ |
| 06 Apr 2017 | Siportal s.r.l.Siportal s.r.l. was fined by the Garante for retaining telephone and internet traffic data longer than permitted by law. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 21 Dec 2023 | Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 May 2018 | Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2022 | Società Lombarda Sport s.r.l.Società Lombarda Sport s.r.l. was fined by the Garante 4,000 EUR for processing personal data without an adequate legal basis. The authority also found failures to ensure data integrity and confidentiality in connection with the issuance of medical certificates for non-competitive sports activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Mar 2022 | Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy. | IT | Garante | GDPR | €2,120,000 | ↗ |
| 07 Apr 2022 | Comune di OrteComune di Orte was fined for improper handling of personal data collected through video surveillance. The authority found a lack of transparency and insufficient data protection measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Feb 2026 | Comune di Mazara del ValloComune di Mazara del Vallo was fined EUR 4,000 by the Garante for breaches of data protection principles. The authority found that the municipality failed to provide adequate information to data subjects and did not carry out a data protection impact assessment for its video surveillance system. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Feb 2026 | Conservatorio “XX” di XXThe Garante fined Conservatorio “XX” di XX EUR 5,000 for processing personal data relating to criminal convictions without a valid legal basis. The authority found breaches of the GDPR and the national privacy code. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Jun 2015 | Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing. | IT | Garante | GDPR | €32,000 | ↗ |
| 23 Jul 2015 | Bike Service s.n.c.Bike Service s.n.c. was fined by the Garante 2,400 EUR for failing to inform data subjects about the processing of personal data through a video surveillance system. The breach concerned the absence of required notices for individuals subject to the monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Jan 2026 | Provvedimento del 16 gennaio 2026 [10213836]The Garante imposed a fine of EUR 500 on an anonymized data controller for a minor breach of data protection rules in the health sector. The authority also ordered publication of the decision on its website. | IT | Garante | GDPR | €500 | ↗ |