BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Mar 2019 | Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Oct 2014 | Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization. | IT | Garante | GDPR | €130,000 | ↗ |
| 05 Jul 2018 | Gianolini Servizi e Trasporti s.r.l.Gianolini Servizi e Trasporti s.r.l. was fined €8,000 by the Garante for failing to notify the authority about its use of a vehicle localization system with GPS devices. The conduct was found to breach notification obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Sept 2014 | History s.a.s.History s.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide the required information notice under Article 13 of the Italian Privacy Code when operating a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 Apr 2022 | Ekss s.r.l.Ekss s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jun 2016 | Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 13 Jun 2013 | BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €64,000 | ↗ |
| 20 Jul 2017 | Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact. | IT | Garante | GDPR | €64,000 | ↗ |
| 18 May 2016 | Istituto Robert Kennedy s.r.l.Istituto Robert Kennedy s.r.l. was fined EUR 2,400 by the Italian Garante for providing clients with inadequate information about data processing. The authority found a breach of the information duties under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Jul 2021 | Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €30,000 | ↗ |
| 03 Sept 2020 | Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Oct 2016 | Condominio via Michelangelo da CaravaggioThe condominium was fined €4,800 by the Garante. The authority found that the surveillance system notices did not identify the data controller, which breached data protection rules. | IT | Garante | GDPR | €4,800 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Nov 2024 | FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures. | IT | Garante | GDPR | €6,000 | ↗ |
| 10 Jun 2011 | Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code. | IT | Garante | GDPR | €34,000 | ↗ |
| 05 Sept 2013 | Perini GianfrancoPerini Gianfranco was fined EUR 2,400 by the Garante. The authority found that individuals were given inadequate data protection information, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Feb 2022 | Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jul 2023 | Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices. | IT | Garante | GDPR | €100,000 | ↗ |