BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Jan 2023 | Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 25 Oct 2012 | Enterprise Group S.r.l.Enterprise Group S.r.l. was fined EUR 70,000 by the Garante. The case concerned unsolicited promotional communications sent by fax without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |
| 11 Sept 2025 | J&D di ZAMBRANO AGUIRRE Ruth JohannaThe Garante imposed a fine of 8,000 EUR on J&D di ZAMBRANO AGUIRRE Ruth Johanna for violations related to the use of a video surveillance system. The authority found that the system was not fully compliant with GDPR requirements. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Oct 2015 | Dolce Salato & C. s.r.l.Dolce Salato & C. s.r.l. was fined by the Garante 2,400 EUR for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 May 2021 | Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Feb 2012 | Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 22 Feb 2024 | S.A.T.E. (Servizi Ambiente Territorio Energia)The Garante fined S.A.T.E. 6,000 EUR for breaches of data protection principles, including lawfulness, integrity, and confidentiality. The authority found that inadequate security measures led to unauthorized access to data. | IT | Garante | GDPR | €6,000 | ↗ |
| 04 Oct 2011 | NGI s.p.a.NGI s.p.a. was fined by the Garante 50,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers, did not prepare the required security program document, and improperly retained traffic data. | IT | Garante | GDPR | €50,000 | ↗ |
| 02 Mar 2011 | Sestrieres S.p.A.Sestrieres S.p.A. was fined by the Italian Garante for failing to provide adequate information to individuals about the processing of their personal data when using ski lift turnstiles. The authority found a breach of data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 12 Feb 2026 | Depurazione Acqua S.r.l.Depurazione Acqua S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The case concerns GDPR breaches related to data processing and consent. | IT | Garante | GDPR | €15,000 | ↗ |
| 13 Sept 2007 | Asl San Severo (Foggia 1)Asl San Severo (Foggia 1) was fined by the Garante for processing personal data, including genetic and biometric data, without proper compliance with data protection rules. The case indicates insufficient legal basis and safeguards for the handling of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Sept 2013 | European Group Sae, Italian Business GuaranteeEuropean Group Sae was fined EUR 12,800 by the Garante. The authority found that the company sent unsolicited promotional faxes without proper information or consent, in breach of privacy rules. | IT | Garante | GDPR | €12,800 | ↗ |
| 12 Nov 2014 | Yueming LiYueming Li was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned a failure to provide data subjects with the required information about the processing of personal data through a video surveillance system at Sala VLT Video Lottery 999 in Milan. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Sept 2006 | Asl 21 di Casale MonferratoThe Garante fined Asl 21 di Casale Monferrato 10,000 EUR for processing genetic and health data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2013 | Pologest s.r.l.Pologest s.r.l. was fined by the Garante €6,400 for sending unsolicited promotional communications by fax. The conduct breached data protection rules governing marketing communications. | IT | Garante | GDPR | €6,400 | ↗ |
| 22 Feb 2024 | Blue Work s.r.l.Blue Work s.r.l. was fined EUR 6,000 by the Garante for unlawful processing of biometric data using facial recognition for employee attendance tracking. The authority found that the same purpose could have been achieved through less intrusive means. | IT | Garante | GDPR | €6,000 | ↗ |
| 14 Mar 2013 | Casa di cura Parco dei Tigli S.a.s. di Alessandro Borgherini & Co.The Garante fined Casa di cura Parco dei Tigli S.a.s. 2,400 EUR for providing inadequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Dec 2010 | Altea Servizi s.r.l.Altea Servizi s.r.l. was fined by the Garante in the amount of 12,000 EUR. The authority found two violations for failing to provide timely information to data subjects as required by Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Mar 2015 | Comune di Santa NinfaComune di Santa Ninfa was fined EUR 4,000 by the Garante for unlawfully publishing personal data on its institutional website. The data remained available for longer than the legally permitted 15 days, constituting a data protection breach. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Mar 2017 | Obiettivo Ferrari s.r.l.Obiettivo Ferrari s.r.l. was fined by the Garante €16,000 for making an unsolicited promotional call. The company did not provide the required data protection information or obtain consent from the recipient. | IT | Garante | GDPR | €16,000 | ↗ |