BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Feb 2017 | Euro Comunication System s.r.l.Euro Comunication System s.r.l. was fined EUR 1,260,000 by the Garante. The authority found that funds were transferred without obtaining consent for data processing and that transactions were split to avoid detection, breaching AML rules. | IT | Garante | GDPR | €1,260,000 | ↗ |
| 17 Sept 2020 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing. | IT | Garante | GDPR | €80,000 | ↗ |
| 02 Apr 2015 | Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Nov 2020 | Ministero dell’InternoThe Ministry of the Interior was fined by the Garante for the unauthorized dissemination of video and images related to a police incident. The authority found a breach of GDPR rules governing the processing of personal data. | IT | Garante | GDPR | €60,000 | ↗ |
| 18 Apr 2018 | Comune di San GeminiComune di San Gemini was fined EUR 10,000 by the Garante for unlawfully transmitting personal data of residents born in 1994–1996 to a school. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Dec 2017 | Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization. | IT | Garante | GDPR | €120,000 | ↗ |
| 05 Mar 2015 | Comune di AcateComune di Acate was fined by the Garante for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the confidentiality of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Oct 2021 | OTTO s.r.l.OTTO s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 2,000 EUR. The case concerned a video surveillance system operated without the required privacy notice, which constitutes a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Oct 2025 | Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Jan 2016 | Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2017 | Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jan 2023 | Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 25 Oct 2012 | Enterprise Group S.r.l.Enterprise Group S.r.l. was fined EUR 70,000 by the Garante. The case concerned unsolicited promotional communications sent by fax without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |
| 11 Sept 2025 | J&D di ZAMBRANO AGUIRRE Ruth JohannaThe Garante imposed a fine of 8,000 EUR on J&D di ZAMBRANO AGUIRRE Ruth Johanna for violations related to the use of a video surveillance system. The authority found that the system was not fully compliant with GDPR requirements. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Oct 2015 | Dolce Salato & C. s.r.l.Dolce Salato & C. s.r.l. was fined by the Garante 2,400 EUR for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 May 2021 | Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Feb 2012 | Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 22 Feb 2024 | S.A.T.E. (Servizi Ambiente Territorio Energia)The Garante fined S.A.T.E. 6,000 EUR for breaches of data protection principles, including lawfulness, integrity, and confidentiality. The authority found that inadequate security measures led to unauthorized access to data. | IT | Garante | GDPR | €6,000 | ↗ |
| 04 Oct 2011 | NGI s.p.a.NGI s.p.a. was fined by the Garante 50,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers, did not prepare the required security program document, and improperly retained traffic data. | IT | Garante | GDPR | €50,000 | ↗ |