BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Nov 2022 | STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Apr 2022 | Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2023 | Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Dec 2011 | Casa di cura Villa Domelia s.r.l.Casa di cura Villa Domelia s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 May 2018 | Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Oct 2023 | Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Mar 2021 | Azienda Ospedaliera San Giovanni AddolorataAzienda Ospedaliera San Giovanni Addolorata was fined EUR 20,000 by the Garante for inadequate data protection measures concerning patient health data. The authority found breaches of GDPR Articles 5 and 32. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Mar 2018 | Massimo FarinaMassimo Farina was fined EUR 280,000 by the Garante. The case concerned the use of prepaid credit cards under false names without obtaining consent, which breached data protection rules. | IT | Garante | GDPR | €280,000 | ↗ |
| 17 May 2023 | Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2025 | Liceo scientifico e linguistico statale “Principe Umberto di Savoia”Liceo scientifico e linguistico statale “Principe Umberto di Savoia” was fined EUR 1,000 by the Garante for breaching the principles of lawfulness, fairness, and transparency in data processing. The authority also found that the school failed to provide adequate information to data subjects. | IT | Garante | GDPR | €1,000 | ↗ |
| 23 Jul 2015 | Filippo Spada e c. sasFilippo Spada e c. sas was fined by the Italian supervisory authority Garante in the amount of €2,400. The sanction was imposed for failing to provide the required privacy notice on its website, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Feb 2021 | Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 12 Nov 2020 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined by the Garante 12,251,601 EUR for making unauthorized promotional calls and sending messages. The authority also found that effective measures to ensure data processing security and GDPR compliance were not in place. | IT | Garante | GDPR | €12,251,000 | ↗ |
| 16 Apr 2015 | Web performance s.r.l.Web performance s.r.l. was fined by the Garante for collecting personal data through website forms without proper consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Jan 2019 | Comune di BardolinoThe Municipality of Bardolino was fined EUR 8,000 by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The disclosure included names and tax codes of beneficiaries of economic contributions, as well as personal information of two municipal employees. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Jul 2025 | Comune di LanghiranoThe Municipality of Langhirano was fined by the Garante for the unauthorized disclosure of personal data on its institutional website. The data was removed, but the authority imposed a monetary penalty of EUR 12,000. | IT | Garante | GDPR | €12,000 | ↗ |