BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Oct 2013 | Antonio CastielloAntonio Castiello was fined for failing to provide the required privacy notice in relation to a video surveillance system at his gaming establishment. The authority found that the omission breached the information duties owed to individuals captured by the cameras. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Apr 2013 | Diners Club Italia s.r.l.Diners Club Italia s.r.l. was fined €40,000 by the Garante for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not update the security program document. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Jun 2016 | Autoverde 07 s.r.l.Autoverde 07 s.r.l. was fined by the Garante in the amount of 2,400 EUR for processing customers’ personal data through its website without providing adequate information. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Dec 2025 | Comune di TuscaniaThe Garante fined Comune di Tuscania 12,000 EUR for failing to provide timely and complete responses to information requests. It also found breaches of lawfulness, fairness, and transparency, as well as inadequate data protection impact assessments for video surveillance. | IT | Garante | GDPR | €12,000 | ↗ |
| 22 Feb 2018 | Bar La Piazzetta s.a.s.Bar La Piazzetta s.a.s. was fined EUR 46,000 by the Italian Garante. The authority found that surveillance footage was kept longer than permitted, access was not password-protected, and the required privacy notices were not provided. | IT | Garante | GDPR | €46,000 | ↗ |
| 11 Oct 2012 | Professional Pneus sccrlProfessional Pneus sccrl was fined EUR 10,400 by the Garante. The authority found that personal data were processed without giving users the option to refuse consent for marketing purposes, breaching transparency requirements. | IT | Garante | GDPR | €10,400 | ↗ |
| 30 Mar 2017 | Grand Hotel Des Bains s.r.l.Grand Hotel Des Bains s.r.l. was fined by the Garante 12,000 EUR for retaining surveillance footage longer than permitted under the video surveillance guidelines. The case concerns a breach of data retention rules for CCTV recordings. | IT | Garante | GDPR | €12,000 | ↗ |
| 20 Mar 2008 | PromofaxPromofax was fined by the Italian authority Garante in the amount of EUR 3,000. The case concerned sending advertising material by fax without providing recipients with prior and adequate information, in breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 28 Mar 2019 | Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Oct 2014 | Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization. | IT | Garante | GDPR | €130,000 | ↗ |
| 05 Jul 2018 | Gianolini Servizi e Trasporti s.r.l.Gianolini Servizi e Trasporti s.r.l. was fined €8,000 by the Garante for failing to notify the authority about its use of a vehicle localization system with GPS devices. The conduct was found to breach notification obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Sept 2014 | History s.a.s.History s.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide the required information notice under Article 13 of the Italian Privacy Code when operating a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 Apr 2022 | Ekss s.r.l.Ekss s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jun 2016 | Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 13 Jun 2013 | BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €64,000 | ↗ |
| 20 Jul 2017 | Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact. | IT | Garante | GDPR | €64,000 | ↗ |
| 18 May 2016 | Istituto Robert Kennedy s.r.l.Istituto Robert Kennedy s.r.l. was fined EUR 2,400 by the Italian Garante for providing clients with inadequate information about data processing. The authority found a breach of the information duties under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Jul 2021 | Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €30,000 | ↗ |
| 03 Sept 2020 | Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |