BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 May 2024 | Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data. | IT | Garante | GDPR | €3,500 | ↗ |
| 17 Jul 2025 | Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements. | IT | Garante | GDPR | €25,000 | ↗ |
| 13 Feb 2007 | Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Oct 2025 | Ordine delle Professioni Infermieristiche di PisaOrdine delle Professioni Infermieristiche di Pisa was fined by the Garante 16,000 EUR for breaches of data protection principles. The authority cited non-compliance with lawfulness, fairness, transparency, and data minimization requirements. | IT | Garante | GDPR | €16,000 | ↗ |
| 27 Jun 2013 | REY2MOND S.n.c. di Reymond Luciano & C.REY2MOND S.n.c. was fined EUR 4,800 by the Garante for collecting personal data through online forms without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 31 Jan 2013 | Edizioni associative srlEdizioni associative srl was fined EUR 16,000 by the Garante. The authority found that the company sent unsolicited promotional emails without proper consent, breaching data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 15 Apr 2021 | Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Jun 2017 | Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jun 2023 | Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante EUR 1,000,000 for violations linked to an application that processed users’ personal data. The app was used to handle refunds of highway ticket costs for delays caused by construction works. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 13 May 2021 | Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data. | IT | Garante | GDPR | €100,000 | ↗ |
| 09 Oct 2025 | AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Mar 2016 | Giuseppe VesceraGiuseppe Vescera was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate information to data subjects about video surveillance. The authority found a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 29 Apr 2026 | Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data. | IT | Garante | GDPR | €12,000 | ↗ |
| 02 Jul 2015 | Lu JiruLu Jiru was fined EUR 2,400 by the Garante. The authority found that personal data were processed through a video surveillance system without providing the required information to data subjects, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Nov 2018 | Comune di Castel MaggioreComune di Castel Maggiore was fined by the Garante for publishing personal data on its institutional website without a legal basis. The case concerned a breach of data protection rules and unauthorized disclosure of information. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Oct 2012 | Azienda sanitaria provinciale di Vibo ValentiaAzienda sanitaria provinciale di Vibo Valentia was fined by the Garante EUR 15,000 for failing to adopt the required minimum security measures. The authority found that the Security Programmatic Document (DPS) was not updated by the deadline required under the Italian Privacy Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 31 May 2018 | Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |
| 09 Jan 2014 | Ordinanza ingiunzione - 9 gennaio 2014 [4785574]The Garante imposed a fine of EUR 4,000 for sending promotional emails without prior valid consent from recipients. The case concerns a breach of data protection rules and electronic marketing requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Nov 2011 | Idea Service S.r.l.Idea Service S.r.l. was fined EUR 20,000 by the Garante for failing to provide information about an unwanted switch of telephone service provider. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |