BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 May 2021 | Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles. | IT | Garante | GDPR | €84,000 | ↗ |
| 12 Nov 2015 | Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2024 | Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Oct 2015 | Liceo scientifico statale Plinio SenioreLiceo scientifico statale Plinio Seniore was fined EUR 10,400 by the Garante for processing biometric data and using video surveillance without providing adequate information to the data subjects. The authority found this conduct to be in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,400 | ↗ |
| 18 Jul 2023 | Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed. | IT | Garante | GDPR | €45,000 | ↗ |
| 13 Nov 2024 | Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners. | IT | Garante | GDPR | €678,000 | ↗ |
| 20 Jul 2017 | S.I.T. s.r.l.S.I.T. s.r.l. was fined by the Garante in the amount of EUR 6,400 for unauthorized access to surveillance images and for processing customer data without proper notice to data subjects. The authority found that these actions breached data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 26 Feb 2026 | Dante Labs S.r.l.Dante Labs S.r.l. was fined EUR 600 by the Garante for failing to provide the results of a genetic test after receiving a customer's DNA sample. Despite multiple attempts by the customer to contact the company, the results were not delivered or explained. | IT | Garante | GDPR | €600 | ↗ |
| 29 May 2008 | Consulting S.p.A.Consulting S.p.A. was fined for collecting personal data through its website without providing adequate prior information. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 15 Dec 2022 | Edison Energia S.p.A.Edison Energia S.p.A. was fined for running promotional campaigns to non-customers without adequate checks on data lists supplied by third parties. The authority found breaches of GDPR requirements on data processing and consent. | IT | Garante | GDPR | €4,900,000 | ↗ |
| 17 Oct 2013 | Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2022 | STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Apr 2022 | Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2023 | Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Dec 2011 | Casa di cura Villa Domelia s.r.l.Casa di cura Villa Domelia s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 May 2018 | Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Oct 2023 | Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |