BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Nov 2022 | Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Jul 2010 | Comune di VentimigliaComune di Ventimiglia was fined by the Garante for processing employees’ biometric data without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Mar 2017 | Roma TPL s.c.a.r.l.Roma TPL s.c.a.r.l. was fined EUR 8,000 by the Garante for processing personal data through AVM systems on buses without full compliance with data protection rules. The case concerned improper use of monitoring and data-processing systems affecting passengers. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Jan 2024 | Euro Servizi per i Notai S.r.l.Euro Servizi per i Notai S.r.l. was fined 5,000 EUR by the Garante for processing personal data without a valid legal basis and without adequate transparency. The violations concerned reporting services provided to banks through the PIGNA portal. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Jun 2023 | More News società cooperativa a r.l.The Garante fined More News società cooperativa a r.l. 5,000 EUR for publishing a minor’s personal data without proper anonymization. The disclosure allowed acquaintances to identify the child and caused embarrassment. | IT | Garante | GDPR | €5,000 | ↗ |
| 02 Mar 2017 | MM Group s.r.l.MM Group s.r.l. was fined EUR 16,000 by the Italian Garante. The case concerned promotional calls made without providing the required data protection information and without obtaining consent, in breach of Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €16,000 | ↗ |
| 28 Nov 2013 | Ma.CI.E. s.a.s di Favaro Stefano & C.Ma.CI.E. s.a.s was fined EUR 2,400 by the Garante for failing to provide the simplified information required under data protection rules. The breach concerned the use of a video surveillance system at the company’s premises. | IT | Garante | GDPR | €2,400 | ↗ |
| — | Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action. | IT | Garante per la protezione dei dati personali | GDPR | €79,100,000 | ↗ |
| 04 Dec 2025 | Istituto Comprensivo Centro di Casalecchio di RenoThe Garante fined Istituto Comprensivo Centro di Casalecchio di Reno EUR 2,000 for publishing personal data online without a proper legal basis. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 28 Sept 2023 | Ministero dell'Ambiente e della Sicurezza EnergeticaThe Ministry of Environment and Energy Security was fined EUR 5,000 by the Garante for the online publication of personal data relating to numerous workers. The disclosure also included health-related data for some individuals. | IT | Garante | GDPR | €5,000 | ↗ |
| 13 Mar 2025 | Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Apr 2023 | SWG S.p.A.SWG S.p.A. was fined EUR 15,000 by the Garante for blocking an employee’s access to email and phone before the agreed termination date. This prevented access to personal data, including sensitive data. | IT | Garante | GDPR | €15,000 | ↗ |
| 02 Jul 2020 | Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 Jul 2006 | Filippi Giovanni & C. s.n.c.Filippi Giovanni & C. s.n.c. was fined 1,549 EUR by the Garante. The authority found that personal data were processed to send commercial messages without proper disclosure required under data protection law. | IT | Garante | GDPR | €1,549 | ↗ |
| 28 May 2015 | El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data. | IT | Garante | GDPR | €174,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jan 2015 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined EUR 4,000 by the Garante. The authority found that personal data had been unlawfully published on its website for longer than the legally permitted fifteen days. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Apr 2016 | Romana Supernegozi s.r.l.Romana Supernegozi s.r.l. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The case concerned breaches of data protection information duties. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Mar 2017 | Welcome s.a.s. di Somma MicheleWelcome s.a.s. di Somma Michele was fined EUR 16,000 by the Garante for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained. | IT | Garante | GDPR | €16,000 | ↗ |
| 04 Dec 2014 | Hotel Stamira s.r.l.Hotel Stamira s.r.l. was fined by the Garante for processing personal data related to job applications without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |