BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Mar 2026 | Liceo Scientifico MorgagniLiceo Scientifico Morgagni was fined by the Garante for violations related to the processing of sensitive data. The authority cited inadequate security measures in the protection of those data. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Jul 2016 | La Fourchette (Italy) s.r.l.La Fourchette (Italy) s.r.l. was fined EUR 10,000 by the Garante. The authority found that the company collected personal data for promotional purposes without obtaining specific consent from users. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Apr 2014 | Gambero Rosso Holding s.p.a.Gambero Rosso Holding s.p.a. was fined by the Italian data protection authority, Garante, for sending promotional emails without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,000 | ↗ |
| 22 May 2013 | Romulus PopescuRomulus Popescu was fined EUR 16,000 by the Garante. The sanction concerned sending unsolicited promotional communications to a minor without proper consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 12 Apr 2012 | Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law. | IT | Garante | GDPR | €120,000 | ↗ |
| 26 Mar 2026 | Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €96,000 | ↗ |
| 05 Jun 2014 | Comune di TerniThe Garante fined Comune di Terni €4,000 for publishing personal data on its website for longer than the legally permitted 15 days. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Oct 2014 | People & Communication s.r.l.People & Communication s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned the sending of pre-recorded promotional phone calls without obtaining the required consent from recipients. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles. | IT | Garante | GDPR | €84,000 | ↗ |
| 12 Nov 2015 | Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2024 | Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Oct 2015 | Liceo scientifico statale Plinio SenioreLiceo scientifico statale Plinio Seniore was fined EUR 10,400 by the Garante for processing biometric data and using video surveillance without providing adequate information to the data subjects. The authority found this conduct to be in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,400 | ↗ |
| 18 Jul 2023 | Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed. | IT | Garante | GDPR | €45,000 | ↗ |
| 13 Nov 2024 | Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners. | IT | Garante | GDPR | €678,000 | ↗ |
| 20 Jul 2017 | S.I.T. s.r.l.S.I.T. s.r.l. was fined by the Garante in the amount of EUR 6,400 for unauthorized access to surveillance images and for processing customer data without proper notice to data subjects. The authority found that these actions breached data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 26 Feb 2026 | Dante Labs S.r.l.Dante Labs S.r.l. was fined EUR 600 by the Garante for failing to provide the results of a genetic test after receiving a customer's DNA sample. Despite multiple attempts by the customer to contact the company, the results were not delivered or explained. | IT | Garante | GDPR | €600 | ↗ |
| 29 May 2008 | Consulting S.p.A.Consulting S.p.A. was fined for collecting personal data through its website without providing adequate prior information. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 15 Dec 2022 | Edison Energia S.p.A.Edison Energia S.p.A. was fined for running promotional campaigns to non-customers without adequate checks on data lists supplied by third parties. The authority found breaches of GDPR requirements on data processing and consent. | IT | Garante | GDPR | €4,900,000 | ↗ |
| 17 Oct 2013 | Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures. | IT | Garante | GDPR | €10,000 | ↗ |