BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Oct 2010 | Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Oct 2017 | Pittaluga servizio containers S.p.A.Pittaluga servizio containers S.p.A. was fined by the Garante €8,000 for using a geolocation system on its vehicles without full compliance with data protection rules. The case concerned improper processing of location data linked to vehicles or employees. | IT | Garante | GDPR | €8,000 | ↗ |
| 26 Feb 2026 | Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls. | IT | Garante | GDPR | €1,000 | ↗ |
| 27 Mar 2014 | Tarulli Francesca e Comune di ConversanoThe Garante imposed a EUR 4,000 fine on Tarulli Francesca and the Comune di Conversano for failing to designate data processors under the Italian Data Protection Code. The conduct breached Articles 30 and 33 and reflected a deficiency in data processing governance. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | Comune di CastellanzaComune di Castellanza was fined by the Garante EUR 4,000 for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. Personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 May 2024 | Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €25,000 | ↗ |
| 15 Sept 2022 | Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation. | IT | Garante | GDPR | €100,000 | ↗ |
| 19 Mar 2015 | avv. Luciana Candriella CadettoThe lawyer transmitted a legal document containing excessive personal and sensitive data, including data relating to a minor, without proper consent. The authority found a breach of data protection rules and imposed a 4,000 EUR fine. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Jun 2024 | FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 04 Jul 2024 | Lapis SasThe Garante fined Lapis Sas EUR 1,500 for incorrectly presenting itself as the data controller. This created public confusion and constituted a prolonged breach of GDPR requirements. | IT | Garante | GDPR | €1,500 | ↗ |
| 17 May 2023 | Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Laboratorio di analisi cliniche Pasini MarioLaboratorio di analisi cliniche Pasini Mario was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Jul 2011 | Il Tarì società consortile per azioniIl Tarì società consortile per azioni was fined €30,000 by the Garante for failing to provide adequate information and notification about the processing of personal data using biometric systems. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Sept 2011 | Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 03 Oct 2013 | Eventi Doc di Myriam VallegraEventi Doc di Myriam Vallegra was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide adequate information to data subjects, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 31 May 2018 | Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities. | IT | Garante | GDPR | €86,000 | ↗ |
| 06 Sept 2012 | One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Nov 2012 | Synergo s.r.l.Synergo s.r.l. was fined by the Italian Garante for failing to notify the processing of sensitive health data. The case involved information on HIV status and infectious diseases, which should have been notified under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 02 Mar 2023 | Razmataz Live S.r.l.Razmataz Live S.r.l. was fined by the Garante 1,000 EUR for failing to take measures to mitigate or eliminate the consequences of a data protection breach linked to promotional activities. The authority also noted that informed consent for commercial communications was not ensured. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 May 2022 | Singh Market S.r.l.The Garante fined Singh Market S.r.l. 2,000 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |