BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 Nov 2015 | Massimo GeraciMassimo Geraci was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system. The authority found a breach of data protection requirements. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Dec 2014 | R. Nautica s.r.l.R. Nautica s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice to individuals whose personal data was collected through a web form. The conduct breached Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Apr 2013 | Discotape di Filippin Angelo & C. sncDiscotape di Filippin Angelo & C. snc was fined EUR 12,000 by the Garante. The case concerned registering numerous phone cards to an individual without their knowledge and failing to provide the required information notice. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Jan 2017 | Comune di Roma CapitaleComune di Roma Capitale was fined EUR 10,000 by the Garante for unlawfully publishing personal data of disabled individuals on its website. The case concerned a breach of data protection rules and required removal of the disclosed information. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Oct 2014 | Xiao Bin JiangXiao Bin Jiang was fined EUR 2,400 by the Garante. The violation concerned the failure to provide data subjects with the required information about the processing of personal data through a video surveillance system at a commercial establishment. | IT | Garante | GDPR | €2,400 | ↗ |
| 20 Jun 2024 | Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Feb 2013 | Stefano Giovanni MaulluStefano Giovanni Maullu was fined by the Garante in the amount of 16,000 EUR for sending unsolicited political SMS messages. The authority also found that the required data protection information was not provided. | IT | Garante | GDPR | €16,000 | ↗ |
| 14 Jan 2021 | Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5. | IT | Garante | GDPR | €2,000 | ↗ |
| 02 Feb 2017 | Euro Comunication System s.r.l.Euro Comunication System s.r.l. was fined EUR 1,260,000 by the Garante. The authority found that funds were transferred without obtaining consent for data processing and that transactions were split to avoid detection, breaching AML rules. | IT | Garante | GDPR | €1,260,000 | ↗ |
| 17 Sept 2020 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing. | IT | Garante | GDPR | €80,000 | ↗ |
| 02 Apr 2015 | Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Nov 2020 | Ministero dell’InternoThe Ministry of the Interior was fined by the Garante for the unauthorized dissemination of video and images related to a police incident. The authority found a breach of GDPR rules governing the processing of personal data. | IT | Garante | GDPR | €60,000 | ↗ |
| 18 Apr 2018 | Comune di San GeminiComune di San Gemini was fined EUR 10,000 by the Garante for unlawfully transmitting personal data of residents born in 1994–1996 to a school. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Dec 2017 | Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization. | IT | Garante | GDPR | €120,000 | ↗ |
| 05 Mar 2015 | Comune di AcateComune di Acate was fined by the Garante for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the confidentiality of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Oct 2021 | OTTO s.r.l.OTTO s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 2,000 EUR. The case concerned a video surveillance system operated without the required privacy notice, which constitutes a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Oct 2025 | Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Jan 2016 | Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2017 | Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |