BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 May 2015 | Patru Dumitra DanielaPatru Dumitra Daniela was fined by the Garante in the amount of EUR 2,400 for operating a video surveillance system at the bar “New Liberty” without providing adequate simplified information. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Apr 2014 | sig. Jin BangshengThe legal representative of Grande Riccone srl was fined EUR 4,800 by the Garante. The sanction concerned operating a video surveillance system without the required data protection notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 13 Nov 2024 | Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2014 | Omnia energia s.p.a.Omnia energia s.p.a. was fined EUR 8,400 by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority also found that required information was not provided on the company’s website, in breach of data protection rules. | IT | Garante | GDPR | €8,400 | ↗ |
| 29 Apr 2025 | Ordine degli Psicologi della Regione LombardiaThe Garante fined the Ordine degli Psicologi della Regione Lombardia EUR 30,000 for a data breach. The incident exposed personal and sensitive data of about 15,000 individuals, including information covered by professional secrecy and special categories of data. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Sept 2024 | Provvedimento del 12 settembre 2024 [10065894]The Garante imposed a EUR 400 fine for the improper installation of surveillance cameras oriented toward private residences. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €400 | ↗ |
| 10 Jul 2025 | Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Oct 2016 | Comune di FurnariComune di Furnari was fined for publishing personal data on its institutional website. It also failed to respond to information requests from the Garante. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Dec 2015 | A.M.A.M. Azienda Meridionale Acque Messina s.p.a.A.M.A.M. Azienda Meridionale Acque Messina s.p.a. was fined by the Garante for processing employees' biometric data without notification and without requesting prior verification. The authority found that the company breached data protection rules. | IT | Garante | GDPR | €34,000 | ↗ |
| 29 Apr 2026 | Tirrenia Hospital SRLTirrenia Hospital SRL was fined EUR 1,000 by the Garante for failing to provide a comprehensible transcription of a deceased patient's medical records. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Jul 2025 | Perla Odontoiatria Veneta S.r.l.The Garante fined Perla Odontoiatria Veneta S.r.l. EUR 7,500 for failing to meet information and transparency obligations in the processing of health data. The authority cited breaches of GDPR Articles 5, 9, and 15. | IT | Garante | GDPR | €7,500 | ↗ |
| 23 Apr 2015 | Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Mar 2023 | Il Fatto Quotidiano S.p.A.The Garante fined Il Fatto Quotidiano S.p.A. EUR 20,000 for the unlawful dissemination of personal data linked to a judicial case involving the complainants' father. The authority found that the publication breached personal data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Sept 2024 | Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Dec 2025 | Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2013 | Hu YonglianHu Yonglian was fined by the Garante in the amount of EUR 2,400 for inadequate data protection notice in a retail store video surveillance system. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Jun 2023 | Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined 5,000 EUR by the Garante for failing to deactivate former employees' email accounts. This allowed unauthorized access to data and breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 25 Jun 2015 | Comune di ParmaComune di Parma was fined EUR 4,000 by the Garante for unlawfully publishing candidates' personal data on its institutional website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Jan 2013 | Evolution chirurgia estetica s.r.l.Evolution chirurgia estetica s.r.l. was fined 10,000 EUR by the Garante. The authority found that the website contact form required mandatory acceptance of the privacy notice, which breached consent requirements under the Italian privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Sept 2025 | Università degli Studi di VeronaUniversità degli Studi di Verona was fined by the Garante €9,000 for improperly handling personal data during a research project. The authority found a breach of GDPR requirements for lawful, fair, and transparent processing. | IT | Garante | GDPR | €9,000 | ↗ |