BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2026 | Tirrenia Hospital SRLTirrenia Hospital SRL was fined EUR 1,000 by the Garante for failing to provide a comprehensible transcription of a deceased patient's medical records. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Jul 2025 | Perla Odontoiatria Veneta S.r.l.The Garante fined Perla Odontoiatria Veneta S.r.l. EUR 7,500 for failing to meet information and transparency obligations in the processing of health data. The authority cited breaches of GDPR Articles 5, 9, and 15. | IT | Garante | GDPR | €7,500 | ↗ |
| 23 Apr 2015 | Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Mar 2023 | Il Fatto Quotidiano S.p.A.The Garante fined Il Fatto Quotidiano S.p.A. EUR 20,000 for the unlawful dissemination of personal data linked to a judicial case involving the complainants' father. The authority found that the publication breached personal data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Sept 2024 | Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Dec 2025 | Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2013 | Hu YonglianHu Yonglian was fined by the Garante in the amount of EUR 2,400 for inadequate data protection notice in a retail store video surveillance system. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Jun 2023 | Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined 5,000 EUR by the Garante for failing to deactivate former employees' email accounts. This allowed unauthorized access to data and breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 25 Jun 2015 | Comune di ParmaComune di Parma was fined EUR 4,000 by the Garante for unlawfully publishing candidates' personal data on its institutional website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Jan 2013 | Evolution chirurgia estetica s.r.l.Evolution chirurgia estetica s.r.l. was fined 10,000 EUR by the Garante. The authority found that the website contact form required mandatory acceptance of the privacy notice, which breached consent requirements under the Italian privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Sept 2025 | Università degli Studi di VeronaUniversità degli Studi di Verona was fined by the Garante €9,000 for improperly handling personal data during a research project. The authority found a breach of GDPR requirements for lawful, fair, and transparent processing. | IT | Garante | GDPR | €9,000 | ↗ |
| 11 Sept 2025 | G.Villa S.r.l.G.Villa S.r.l. was fined by the Garante EUR 22,500 for sending unsolicited promotional emails to an address not disclosed for marketing purposes. The company also failed to respond to the data subject's request for access to and deletion of personal data. | IT | Garante | GDPR | €22,500 | ↗ |
| 30 Jan 2020 | Comune di ColledaraComune di Colledara was fined EUR 4,000 by the Garante for publishing personal data in the provisional ranking of a competition on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Feb 2014 | Regione PugliaRegione Puglia was fined EUR 20,000 by the Italian data protection authority, Garante. The breach involved unlawfully publishing health data of individuals with disabilities on its institutional website. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Mar 2025 | Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,600 | ↗ |
| 29 Apr 2009 | Altea Servizi s.r.l.Altea Servizi s.r.l. was fined for processing personal data without providing the required information notice, in connection with sending promotional faxes without consent. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 25 Nov 2021 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The hospital was fined by the Garante 50,000 EUR for unlawfully publishing on its website the personal data of participants in a competitive procedure, including health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €50,000 | ↗ |
| 17 Apr 2014 | SSTC srlSSTC srl was fined EUR 66,000 by the Italian authority Garante. The case concerned telemarketing activities carried out without the prior consent of the contacted individuals, in breach of data protection rules. | IT | Garante | GDPR | €66,000 | ↗ |
| 13 Dec 2018 | Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Feb 2021 | Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website. | IT | Garante | GDPR | €5,000 | ↗ |