BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Oct 2025 | Comune di CurtaroloComune di Curtarolo was fined EUR 15,000 by the Garante for using surveillance footage for disciplinary purposes without proper legal justification. The authority also found that adequate privacy information was not provided to the individuals concerned. | IT | Garante | GDPR | €15,000 | ↗ |
| 18 Sept 2008 | Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante EUR 20,000 for using an automated calling system without obtaining prior consent from the individuals concerned. The case concerned a breach of data protection rules and consent requirements for automated communications. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Jul 2013 | OASI AZZURRA di Intravaia Lorenzo & C. S.a.s.OASI AZZURRA di Intravaia Lorenzo & C. S.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned inadequate privacy notices for the website contact form and the video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 May 2022 | Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Jan 2017 | Bertolotto Michele e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriesteThe Garante imposed a 10,000 EUR fine on Bertolotto Michele and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste. The case concerned unauthorized access by two doctors to personal health data, including Bertolotto’s data. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Feb 2017 | Avv. Silvana VassalliAvv. Silvana Vassalli was fined by the Garante for unlawful processing of personal data. The breach involved transmitting an email containing personal data without proper authorization. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Jun 2020 | Azienda Pluriservizi Macerata S.p.A.Azienda Pluriservizi Macerata S.p.A. was fined EUR 4,000 by the Garante for processing colleagues’ personal data in a manner that did not comply with data protection principles. The authority cited breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Nov 2022 | Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 22 Jun 2023 | Spaziani FabrizioThe Garante fined Spaziani Fabrizio EUR 1,000 for non-compliant video surveillance practices. The case involved cameras that were not properly signposted and may have captured public areas. | IT | Garante | GDPR | €1,000 | ↗ |
| 20 Jun 2024 | Comune di ForlìThe Municipality of Forlì was fined EUR 15,000 by the Garante for failing to embed data protection principles in the design of its video surveillance system. The authority found breaches of transparency and accountability requirements. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Jul 2015 | Impresa Edile di Alagna GiuseppeThe company was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 Apr 2022 | Direzione Didattica Statale 1° Circolo–EboliDirezione Didattica Statale 1° Circolo–Eboli was fined by the Garante 1,500 EUR for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned improper processing of personal data under the GDPR. | IT | Garante | GDPR | €1,500 | ↗ |
| 20 Nov 2014 | Impresa costruzioni edili e stradali – dr. Ing. Michele Bianchi & C. - s.r.l.The company was fined by the Garante 2,400 EUR for failing to provide the required privacy notice to data subjects when collecting personal data through a web form on its website. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Apr 2025 | Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jul 2023 | Università Telematica E-CampusUniversità Telematica E-Campus was fined EUR 75,000 by the Garante. The authority found that the university sent promotional SMS messages without consent and failed to respond to data deletion requests. These actions breached GDPR requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 11 Apr 2013 | Kihria S.r.l.Kihria S.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate information about data collection through a website contact form. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 31 May 2018 | Autosat S.p.A.Autosat S.p.A. was fined by the Italian Garante in the amount of EUR 30,000 for breaches of data protection rules. The case concerned the handling of personal data and the security measures used in the company’s IT systems. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Nov 2015 | Giuseppina GhezziGiuseppina Ghezzi was fined by the Garante 26,000 EUR for registering 100 phone cards to an unaware third party. The required data protection information was not provided and consent was not obtained, constituting a breach of data protection law. | IT | Garante | GDPR | €26,000 | ↗ |
| 13 Feb 2007 | Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |