BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Apr 2022 | Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information. | IT | Garante | GDPR | €70,000 | ↗ |
| 19 Nov 2017 | Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Nov 2010 | Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 May 2015 | Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Apr 2017 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Apr 2018 | Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2014 | Antonio FrazzanoAntonio Frazzano was fined EUR 4,000 by the Garante for sending promotional faxes without the required information notice and without obtaining recipient consent. The case concerned violations of data protection and direct marketing rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Dec 2020 | Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users. | IT | Garante | GDPR | €500,000 | ↗ |
| 29 Apr 2026 | Nuova Corrente S.r.l.Nuova Corrente S.r.l. was fined EUR 15,000 by the Garante for making promotional calls without a valid legal basis. The authority found this to be a breach of GDPR lawfulness principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Jul 2015 | Giuseppe De MartinoGiuseppe De Martino was fined EUR 2,400 by the Garante for failing to provide adequate information on the processing of personal data through a website form and a video surveillance system. The authority found a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Dec 2024 | Ambiente 2000 S.r.l.Ambiente 2000 S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company required employees to disclose passwords to their work email and files containing personal data, in breach of the GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Mar 2024 | Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €120,000 | ↗ |
| 30 Jun 2011 | Porto di Tropea s.p.a.Porto di Tropea s.p.a. was fined by the Garante 10,000 EUR for failing to provide adequate information about video surveillance. The authority also found that data processors were not formally appointed for customer data collected through mooring contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2019 | Ordinanza ingiunzione - 4 aprile 2019 [9117119]A municipal councillor was fined by the Garante for unlawfully disclosing personal data obtained from a document without legal justification. The authority found a breach of the principles of lawful processing and data protection. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Oct 2014 | Comune di UdineThe Municipality of Udine was fined 14,000 EUR by the Garante. The authority found that the Security Policy Document (DPS) had not been updated from 2005 to 2011, which breached data protection rules. | IT | Garante | GDPR | €14,000 | ↗ |
| 25 Feb 2016 | Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted. | IT | Garante | GDPR | €14,400 | ↗ |
| 02 Apr 2015 | Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Oct 2023 | S.T.A. Società Trattamento Acque s.r.l.S.T.A. Società Trattamento Acque s.r.l. was fined €75,000 by the Garante. The authority found a breach of Article 15 GDPR after the company failed to respond to an employee's request for access to professional training records. | IT | Garante | GDPR | €75,000 | ↗ |
| 27 Nov 2024 | Faro di RomaFaro di Roma was fined 15,000 EUR by the Garante for failing to comply with data protection rules. The case concerned the failure to honor requests for erasure and rectification of personal data linked to a judicial matter. | IT | Garante | GDPR | €15,000 | ↗ |