BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Mar 2018 | Comune di San Mango PiemonteComune di San Mango Piemonte was fined for unlawfully using a biometric system based on fingerprint processing to record employee attendance. The authority found that this processing breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Mar 2018 | Priolo Servizi S.c.p.A.Priolo Servizi S.c.p.A. was fined EUR 52,000 for the unlawful processing of biometric data of about 6,700 workers. The authority found that the company failed to properly notify the Garante and provided inadequate information to the data subjects. | IT | Garante | GDPR | €52,000 | ↗ |
| 08 Mar 2018 | INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users. | IT | Garante | GDPR | €26,000 | ↗ |
| 08 Mar 2018 | Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search. | IT | Garante | GDPR | €160,000 | ↗ |
| 08 Mar 2018 | Carriere Italia s.r.l.Carriere Italia s.r.l. was fined for processing personal data revealing health status without notifying the Garante. The authority also found that required information was not provided to data subjects in job advertisements. | IT | Garante | GDPR | €10,400 | ↗ |
| 08 Mar 2018 | Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 Mar 2018 | Tekne Progetti s.r.l.Tekne Progetti s.r.l. was fined for failing to respond to an information request from the Garante concerning its data processing activities. The conduct was found to violate Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Mar 2018 | Directafin s.p.a.Directafin s.p.a. was fined by the Garante in the amount of EUR 20,000 for using a single consent flag for multiple processing purposes. This included marketing and sharing personal data with third parties without valid consent. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Mar 2018 | Lombardia Informatica S.p.A.Lombardia Informatica S.p.A. was fined EUR 40,000 by the Garante for allowing unauthorized access to personal data through its portal. The case concerned a breach of data protection rules and indicated insufficient access controls. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Mar 2018 | Studio Silver Consulting S.r.l.s.Studio Silver Consulting S.r.l.s. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in its debt management activities. The case concerned improper handling of personal data in the context of debt collection operations. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Mar 2018 | Istituto Tecnico Statale Commerciale e per Geometri Masullo ThetiIstituto Tecnico Statale Commerciale e per Geometri Masullo Theti was fined by the Garante €12,000 for operating a video surveillance system without the required authorization. The case concerns a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Mar 2018 | S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Mar 2018 | Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code. | IT | Garante | GDPR | €26,000 | ↗ |
| 21 Mar 2018 | Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €92,000 | ↗ |
| 21 Mar 2018 | Società agricola Medici Claudio s.r.l.The company was fined for failing to comply with data protection obligations. The breach concerned not providing personal data and information related to employment management when requested by the Garante. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2018 | Azienda Sanitaria Locale Napoli 2 NordAzienda Sanitaria Locale Napoli 2 Nord was fined by the Garante for allowing personal data of registered users to be accessed and modified by anyone through its institutional website. The case concerned inadequate protection of personal data and non-compliance with data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Mar 2018 | Ditta individuale Smile di Remmert OriettaThe company was fined for processing the personal data of 36 individuals without consent in connection with training enrollments. It also submitted false documents to the Province of Turin to account for courses that were never conducted. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Mar 2018 | ARGOINFOR S.L.ARGOINFOR S.L. was fined by the AEPD in the amount of 1,000 EUR. The case concerned the sending of unsolicited commercial emails, which breaches Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 29 Mar 2018 | Farmacia del Sole delle dottoresse De Vito Luana e Lubelli Chiara s.n.c.Farmacia del Sole was fined by the Garante for issuing receipts that showed medication names instead of the authorization number. This practice breached privacy rules and exposed sensitive customer information. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Mar 2018 | SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk. | IT | Garante | GDPR | €20,000 | ↗ |