BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Apr 2013 | Mida S.a.s.Mida S.a.s. was fined by the Italian Garante 2,400 EUR for an inadequate privacy notice relating to its video surveillance system. The notice did not include the data controller’s information, which failed to meet the required transparency obligations. | IT | Garante | GDPR | €2,400 | ↗ |
| 19 May 2011 | Limbiati oreficeria orologeria ottica s.n.c. di L. Limbiati & C.Limbiati oreficeria orologeria ottica s.n.c. was fined by the Garante for collecting personal data through its website without providing adequate information or obtaining the required consent. The authority found this to be a breach of the Italian Privacy Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 25 Sept 2025 | Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Sept 2023 | Azienda Sanitaria dell'Alto Adige - Suedtiroler SanitaetsbetriebThe Garante fined Azienda Sanitaria dell'Alto Adige EUR 10,000 for failing to provide an adequate response to a data subject's rights request. The case also concerned the processing of sensitive data related to vaccination status. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Mar 2014 | Puglia Service s.r.l.Puglia Service s.r.l. was fined by the Garante €10,000 for making unsolicited promotional phone calls. The conduct violated the right of opposition of a subscriber registered in the public opt-out list. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jun 2018 | Comune di PozzalloComune di Pozzallo was fined for publishing personal and judicial data online without a valid legal basis. It also failed to respond to information requests from the Garante. | IT | Garante | GDPR | €8,000 | ↗ |
| 30 Mar 2017 | Provincia di CasertaProvincia di Caserta was fined EUR 20,000 by the Garante. The authority found that the province failed to designate data processing officers and did not update the security program document required under the data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 May 2024 | Radio Marte S.r.l.Radio Marte S.r.l. was fined EUR 5,000 by the Garante for unlawfully disseminating identifying data of a minor during a radio program. The authority found a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 May 2018 | SO.LOG. SrlSO.LOG. Srl was fined EUR 8,000 by the Italian data protection authority, Garante. The sanction concerned the failure to properly notify processing activities related to vehicle geolocation, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Dec 2022 | Azienda Sanitaria provinciale di CataniaAzienda Sanitaria provinciale di Catania was fined 5,000 EUR by the Garante for unlawfully publishing personal data on its website concerning an employee's disciplinary and criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 05 Mar 2015 | Comune di AvolaComune di Avola was fined 10,000 EUR by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The case involved a breach of privacy rules and the unlawful processing of special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Sept 2015 | Layla SerenelliLayla Serenelli was fined 2,400 EUR by the Italian data protection authority, Garante. The case concerned inadequate simplified information about video surveillance, which breached data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Dec 2011 | Edreams s.r.l.Edreams s.r.l. was fined €160,000 by the Garante for sending unsolicited commercial emails without obtaining the required consent. The case concerned breaches of data protection rules and direct marketing requirements. | IT | Garante | GDPR | €160,000 | ↗ |
| 03 Jun 2025 | Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data. | IT | Garante per la protezione dei dati personali | GDPR | €50,000 | ↗ |
| 10 Apr 2025 | Undici S.r.l.s.Undici S.r.l.s. was fined 8,000 EUR by the Garante for making unsolicited telemarketing calls. The authority found that the company did not verify the lawfulness of the data used for contact, breaching GDPR requirements on consent and data processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 17 Apr 2026 | Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Nov 2012 | La Villa s.p.a.La Villa s.p.a. was fined EUR 16,000 by the Garante. The company failed to update its notification of data processing activities after changing its registered office address, which breached privacy rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 13 May 2021 | Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Mar 2023 | Paolo MeloniThe condominium administrator, Paolo Meloni, was fined for disclosing to all residents that a family had tested positive for COVID-19. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Mar 2010 | Fastweb s.p.a.Fastweb s.p.a. was fined by the Garante for failing to provide adequate information to data subjects about the processing of their personal data. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €15,000 | ↗ |