BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jun 2023 | Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jul 2023 | Provvedimento del 18 luglio 2023 [9935503]A complaint was filed with the Garante concerning a surveillance system installed by an individual that may have captured footage of a public street. The authority found a GDPR breach and imposed a fine of EUR 400. | IT | Garante | GDPR | €400 | ↗ |
| 18 Dec 2025 | Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Jul 2024 | Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Apr 2026 | Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9973749]An attorney was fined for unlawfully processing personal data by sending sensitive judicial documents via certified email. The authority found that the method of transmission breached data protection rules. | IT | Garante | GDPR | €500 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Jan 2026 | Provvedimento del 16 gennaio 2026 [10213836]The Garante imposed a fine of EUR 500 on an anonymized data controller for a minor breach of data protection rules in the health sector. The authority also ordered publication of the decision on its website. | IT | Garante | GDPR | €500 | ↗ |
| 14 Nov 2024 | Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Sept 2024 | Provvedimento del 12 settembre 2024 [10065894]The Garante imposed a EUR 400 fine for the improper installation of surveillance cameras oriented toward private residences. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €400 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10226120]The Garante imposed a fine of EUR 1,500 for unlawful processing of personal data through a video surveillance system at a commercial establishment. The cameras captured public streets and private residences, and the data subjects were not properly notified. | IT | Garante | GDPR | €1,500 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225084]The Garante fined a retail business for failing to provide adequate informational signage for its video surveillance system. The authority found a breach of data protection rules because individuals on the premises were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Dec 2024 | Provvedimento del 12 dicembre 2024 [10095836]A doctor was fined EUR 20,000 for breaching core data protection principles. The authority cited failures relating to lawfulness, fairness, transparency, purpose limitation, data minimization, and integrity and confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Apr 2025 | Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector. | IT | Garante | GDPR | €18,000 | ↗ |
| 24 Nov 2016 | Provincia di VercelliProvincia di Vercelli was fined EUR 10,000 by the Garante for unlawfully publishing personal data on its institutional website. The disclosed information included photocopies of identity cards and bank account numbers, without an appropriate legal basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Apr 2015 | Provincia di TriesteProvincia di Trieste was fined for publishing personal data on its institutional website without a legal basis. This breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Jan 2024 | Provincia di SassariThe Garante imposed a fine of 2,000 EUR on Provincia di Sassari for breaches of data protection obligations under Article 37 GDPR. The case concerned failure to comply with requirements related to the designation of a data protection officer. | IT | Garante | GDPR | €2,000 | ↗ |
| 25 Jan 2018 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement. | IT | Garante | GDPR | €60,000 | ↗ |
| 22 Jan 2015 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined EUR 4,000 by the Garante. The authority found that personal data had been unlawfully published on its website for longer than the legally permitted fifteen days. | IT | Garante | GDPR | €4,000 | ↗ |