BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Mar 2013 | Università Telematica San Raffaele RomaUniversità Telematica San Raffaele Roma was fined by the Garante EUR 6,000 for providing inadequate data protection information through its enrollment and information request forms on its website. The case concerned a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 31 May 2018 | IDEASORRISO S.R.L.IDEASORRISO S.R.L. was fined by the Garante EUR 86,000 for making unsolicited promotional calls without the recipients’ consent. The case concerned data protection rules applicable to telemarketing activities. | IT | Garante | GDPR | €86,000 | ↗ |
| 23 Feb 2023 | Ediscom S.p.A.Ediscom S.p.A. was fined by the Garante 300,000 EUR for lacking clarity and transparency when obtaining user consent for marketing purposes. The authority also found that data was processed despite objections from data subjects. | IT | Garante | GDPR | €300,000 | ↗ |
| 16 Jan 2026 | Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object. | IT | Garante | GDPR | €15,000 | ↗ |
| 21 Mar 2013 | Compu & Games srlCompu & Games srl was fined EUR 54,000 by the Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information. | IT | Garante | GDPR | €54,000 | ↗ |
| 22 May 2018 | Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Feb 2018 | FAMAS S.R.L.FAMAS S.R.L. was fined by the Garante for using a biometric system based on fingerprint recognition to record employee attendance without a proper legal basis. The case concerned the processing of biometric data in an employment context, where specific lawful grounds are required. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Oct 2015 | Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €93,000 | ↗ |
| 10 Nov 2022 | Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Sept 2021 | Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Jan 2014 | Hu ShaozengHu Shaozeng was fined EUR 2,400 by the Garante. The breach concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system in a commercial establishment. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Jul 2020 | Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Mar 2016 | Zhu XiaozhenZhu Xiaozhen was fined by the Garante for failing to provide the simplified information required under the data protection code and the video surveillance rules. The surveillance system was operated without proper notice to the individuals concerned. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 May 2026 | Comune di SciaccaComune di Sciacca was fined EUR 6,000 by the Garante for violations related to the processing and dissemination of personal data in the public sector. The case concerned improper handling of personal data within public administration activities. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Dec 2009 | Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2024 | Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Nov 2012 | G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Mar 2014 | Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 May 2022 | Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls. | IT | Garante | GDPR | €100,000 | ↗ |