BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Sept 2021 | Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 May 2019 | SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Dec 2023 | Nirvam S.r.l.Nirvam S.r.l., an online dating platform, was fined 200,000 EUR by the Garante. The authority found inadequate personal data protection measures and GDPR breaches related to data processing and security. | IT | Garante | GDPR | €200,000 | ↗ |
| 11 Jan 2024 | Findomestic Banca S.p.A.Findomestic Banca S.p.A. was fined by the Garante 100,000 EUR for sending unsolicited promotional communications by phone and mail. The authority found that these contacts were made without obtaining proper consent from the data subject. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Mar 2018 | Fin Solution Italia S.p.a.Fin Solution Italia S.p.a. was fined EUR 20,000 by the Garante for inadequate security measures in the processing of personal data. The authority found that weak passwords were used on company PCs, increasing the risk of unauthorized access. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 May 2019 | Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Oct 2020 | Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jul 2013 | Parco Faunistico Le Cornelle S.r.l.Parco Faunistico Le Cornelle S.r.l. was fined by the Garante EUR 2,400 for collecting personal data through a website contact form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 24 Jun 2021 | Comune di Cogollo del CengioThe Municipality of Comune di Cogollo del Cengio was fined by the Garante 1,000 EUR for unlawfully publishing personal data related to a disciplinary procedure. The authority found no legal basis for the disclosure and held that it breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 20 Feb 2014 | Società Editrice Sud s.p.a.Società Editrice Sud s.p.a. was fined by the Garante in the amount of 16,800 EUR for using inadequate information notices on data collection forms. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 27 Jan 2021 | Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €50,000 | ↗ |
| 14 Jun 2018 | Azienda Ospedaliera Pugliese CiaccioAzienda Ospedaliera Pugliese Ciaccio was fined EUR 16,000 by the Garante. The authority found that patients were not informed about data processing and that consent was not obtained for processing sensitive data, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,000 | ↗ |
| 26 Oct 2017 | M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Jul 2023 | Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 22 Jul 2021 | Regione LombardiaRegione Lombardia was fined by the Garante 200,000 EUR for publishing personal data on its website that could reveal individuals' economic and social hardship. The authority found that this breached GDPR transparency and data protection requirements. | IT | Garante | GDPR | €200,000 | ↗ |
| 15 May 2013 | Chen JingChen Jing was fined by the Italian Garante in the amount of EUR 2,400 for providing inadequate information about a video surveillance system at Ottimoda S.a.s. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Apr 2016 | Comune di LizzanoComune di Lizzano was fined by the Garante for publishing personal data, including health information about a minor, on its online notice board. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Dec 2022 | Giessegi Industria Mobili S.p.A.Giessegi Industria Mobili S.p.A. was fined by the Garante 50,000 EUR for unlawful processing of personal data. The company installed a device to track the geographical location of a vehicle used by an employee, in breach of GDPR requirements. | IT | Garante | GDPR | €50,000 | ↗ |
| 10 Apr 2025 | Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents. | IT | Garante | GDPR | €3,000,000 | ↗ |
| 22 May 2018 | C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €28,000 | ↗ |