BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Sept 2010 | Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Mar 2010 | Alma s.r.l.Alma s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 10,000 EUR. The case concerned the processing of personal data without the notification required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jun 2020 | Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Sept 2011 | Jenius Communication sasJenius Communication sas was fined by the Garante 8,000 EUR for sending an unsolicited promotional email. The case concerns a breach of data protection rules governing marketing communications. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Apr 2022 | ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Apr 2026 | Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 May 2017 | Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 20 Jan 2012 | Manage Consulting International s.r.l.Manage Consulting International s.r.l. was fined by the Italian Garante in the amount of 10,400 EUR. The sanction concerned sending unsolicited promotional faxes without proper consent and required information. | IT | Garante | GDPR | €10,400 | ↗ |
| 01 Jun 2023 | Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Oct 2013 | Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Dec 2011 | Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations. | IT | Garante | GDPR | €26,000 | ↗ |
| 09 Feb 2011 | Futurgroup s.r.l.Futurgroup s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 9,000. The case concerned the failure to provide timely information to the data subject as required by the data protection code. | IT | Garante | GDPR | €9,000 | ↗ |
| 11 Apr 2019 | AD Sphera Group s.r.l.AD Sphera Group s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Jun 2016 | Istituto Maria Angelica Miliziano s.r.l.Istituto Maria Angelica Miliziano s.r.l. was fined by the Garante 2,400 EUR for collecting users’ personal data through its website without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2023 | Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2022 | Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 Dec 2012 | Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 05 Dec 2013 | Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority. | IT | Garante | GDPR | €30,000 | ↗ |
| 21 Mar 2018 | Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €92,000 | ↗ |