BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Oct 2016 | Condominio via Michelangelo da CaravaggioThe condominium was fined €4,800 by the Garante. The authority found that the surveillance system notices did not identify the data controller, which breached data protection rules. | IT | Garante | GDPR | €4,800 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Nov 2024 | FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures. | IT | Garante | GDPR | €6,000 | ↗ |
| 10 Jun 2011 | Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code. | IT | Garante | GDPR | €34,000 | ↗ |
| 05 Sept 2013 | Perini GianfrancoPerini Gianfranco was fined EUR 2,400 by the Garante. The authority found that individuals were given inadequate data protection information, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Feb 2022 | Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jul 2023 | Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices. | IT | Garante | GDPR | €100,000 | ↗ |
| 03 Apr 2014 | Travelplan Italia s.r.l.Travelplan Italia s.r.l. was fined EUR 16,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company failed to provide the required information notice and did not obtain consent, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,000 | ↗ |
| 28 May 2026 | Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status. | IT | Garante | GDPR | €700 | ↗ |
| 12 Mar 2026 | Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Apr 2023 | Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data. | IT | Garante | GDPR | €239,000 | ↗ |
| 27 Oct 2016 | Porto di Imperia s.p.a.Porto di Imperia s.p.a. was fined by the Italian Garante in the amount of €2,400. The authority found a data protection breach linked to the use of a video surveillance system because individuals entering the port were not provided with simplified information. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Dec 2021 | Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data. | IT | Garante | GDPR | €7,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 26 Mar 2020 | Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | M.S.M. Immobiliare s.r.l.M.S.M. Immobiliare s.r.l. was fined €1,000 by the Garante for a video surveillance system that captured areas beyond its property. The authority also found that proper informational signage was missing, in breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 11 Apr 2013 | Errebian S.p.aErrebian S.p.a was fined EUR 6,000 by the Italian Garante. The case concerned the failure to provide the required data protection notice on website forms, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 17 Jan 2008 | Proemotion s.r.l.Proemotion s.r.l. was fined EUR 3,000 by the Italian data protection authority, Garante. The case concerned promotional activities for travel, vacations, weddings, and meetings, where personal data were collected through website forms without adequate prior information. | IT | Garante | GDPR | €3,000 | ↗ |
| 12 Feb 2026 | Comune di CoccaglioComune di Coccaglio was fined EUR 6,000 for using surveillance footage for disciplinary purposes without informing employees. The authority also found that no data protection impact assessment had been carried out, in breach of data protection rules. | IT | Garante | GDPR | €6,000 | ↗ |