BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Oct 2022 | Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €900 | ↗ |
| 29 Apr 2021 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jan 2015 | Francesco Saverio ManesFrancesco Saverio Manes was fined by the Garante EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at the cultural club “K2”. The case concerned the absence of mandatory notices for individuals captured by the CCTV system. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Jan 2014 | Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 05 May 2011 | Mondolibri s.p.a.Mondolibri s.p.a. was fined EUR 8,000 by the Garante for collecting personal email addresses through its website without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Mar 2024 | Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification. | IT | Garante | GDPR | €100,000 | ↗ |
| 16 Dec 2021 | Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling. | IT | Garante | GDPR | €26,513,000 | ↗ |
| 10 Nov 2022 | Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained. | IT | Garante | GDPR | €40,000 | ↗ |
| 16 Nov 2017 | S.T.E.A.T. S.p.a.S.T.E.A.T. S.p.a. was fined by the Garante for failing to properly notify the installation of electronic monitoring and localization devices on public transport buses. The authority found a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Dec 2015 | G.I.T. s.a.sG.I.T. s.a.s was fined 4,800 EUR by the Garante. The authority found that the company failed to provide adequate simplified information for its video surveillance system and did not give the required notice when collecting personal data through its website. | IT | Garante | GDPR | €4,800 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Sept 2021 | Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 May 2019 | SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Dec 2023 | Nirvam S.r.l.Nirvam S.r.l., an online dating platform, was fined 200,000 EUR by the Garante. The authority found inadequate personal data protection measures and GDPR breaches related to data processing and security. | IT | Garante | GDPR | €200,000 | ↗ |
| 11 Jan 2024 | Findomestic Banca S.p.A.Findomestic Banca S.p.A. was fined by the Garante 100,000 EUR for sending unsolicited promotional communications by phone and mail. The authority found that these contacts were made without obtaining proper consent from the data subject. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Mar 2018 | Fin Solution Italia S.p.a.Fin Solution Italia S.p.a. was fined EUR 20,000 by the Garante for inadequate security measures in the processing of personal data. The authority found that weak passwords were used on company PCs, increasing the risk of unauthorized access. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 May 2019 | Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Oct 2020 | Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jul 2013 | Parco Faunistico Le Cornelle S.r.l.Parco Faunistico Le Cornelle S.r.l. was fined by the Garante EUR 2,400 for collecting personal data through a website contact form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 24 Jun 2021 | Comune di Cogollo del CengioThe Municipality of Comune di Cogollo del Cengio was fined by the Garante 1,000 EUR for unlawfully publishing personal data related to a disciplinary procedure. The authority found no legal basis for the disclosure and held that it breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |