BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Feb 2022 | Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Nov 2015 | Ente Parco dei NebrodiEnte Parco dei Nebrodi was fined EUR 8,000 by the Garante for processing employees’ biometric data without prior notification. The authority found a breach of Article 37 of the Codice Privacy. | IT | Garante | GDPR | €8,000 | ↗ |
| 19 Feb 2015 | Tecno Line S.r.l.Tecno Line S.r.l. was fined EUR 8,000 by the Italian data protection authority, Garante. The case concerned the activation of SIM cards in individuals’ names without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 06 Sept 2012 | BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules. | IT | Garante | GDPR | €75,000 | ↗ |
| 07 Mar 2024 | BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Mar 2025 | Comune di PolinoComune di Polino was fined by the Garante for breaches of transparency and information obligations in data processing under GDPR Articles 6, 12, 13, and 14. The case concerned insufficient information provided to data subjects about how their personal data was processed. | IT | Garante | GDPR | €2,500 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di GoriziaThe Garante imposed a fine of EUR 5,000 on the Ordine delle Professioni Infermieristiche di Gorizia for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 27 Apr 2023 | Ministero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di LecceMinistero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce was fined 15,000 EUR by the Garante for publishing personal data on its website. The case concerns a breach of data protection rules through unauthorized disclosure of information. | IT | Garante | GDPR | €15,000 | ↗ |
| 25 Jan 2018 | Avis Budget Italia s.p.a.Avis Budget Italia s.p.a. was fined EUR 60,000 by the Garante for improper installation and notification of geolocation devices on its vehicle fleet. The authority found that the company did not comply with data protection requirements. | IT | Garante | GDPR | €60,000 | ↗ |
| 12 Jun 2014 | Mediolanum Hotel s.r.l.Mediolanum Hotel s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required notice under Article 13 of the Italian Data Protection Code. The breach concerned the absence of the mandatory privacy information for job applicants. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Mar 2016 | Caaf Consulenti del lavoro srlCaaf Consulenti del lavoro srl was fined EUR 4,800 by the Garante. The authority found that the company failed to provide the required privacy notice for data collected through its website contact form and video surveillance system, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 18 Jul 2023 | Compara Facile S.r.l.Compara Facile S.r.l. was fined EUR 40,000 by the Garante for making unsolicited marketing calls to a number listed in the Public Register of Oppositions without prior informed consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €40,000 | ↗ |
| 08 Mar 2018 | INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users. | IT | Garante | GDPR | €26,000 | ↗ |
| 12 May 2022 | Minimarket di Alam SaifulThe Garante fined Minimarket di Alam Saiful 1,000 EUR for operating a video surveillance system without the required notice to individuals being recorded. The case concerned a breach of data protection information obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 06 Nov 2014 | Dragica LjubojevicDragica Ljubojevic was fined by the Garante in the amount of 2,400 EUR for failing to provide data subjects with the required information about the processing of personal data. The case concerned a video surveillance system at a private club. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Apr 2023 | Sorgenia S.p.a.Sorgenia S.p.a. was fined EUR 676,956 by the Italian data protection authority, Garante. The case concerned failure to respect data deletion and objection rights in connection with unlawful telemarketing practices in the energy sector. | IT | Garante | GDPR | €676,000 | ↗ |
| 08 Jun 2023 | Mirva s.r.l.Mirva s.r.l. was fined by the Garante 5,000 EUR for installing a video surveillance system without proper informational signage. The system also captured areas not pertaining to the company, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Apr 2021 | Fondazione Policlinico Tor Vergata di RomaFondazione Policlinico Tor Vergata di Roma was fined by the Garante 15,000 EUR for breaches of data processing principles. The case concerned compliance with lawfulness, fairness, transparency, and security measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 16 Jan 2026 | Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Jul 2024 | Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles. | IT | Garante | GDPR | €10,000 | ↗ |