BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Sept 2021 | Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Jan 2014 | Hu ShaozengHu Shaozeng was fined EUR 2,400 by the Garante. The breach concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system in a commercial establishment. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Jul 2020 | Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Mar 2016 | Zhu XiaozhenZhu Xiaozhen was fined by the Garante for failing to provide the simplified information required under the data protection code and the video surveillance rules. The surveillance system was operated without proper notice to the individuals concerned. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 May 2026 | Comune di SciaccaComune di Sciacca was fined EUR 6,000 by the Garante for violations related to the processing and dissemination of personal data in the public sector. The case concerned improper handling of personal data within public administration activities. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Dec 2009 | Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2024 | Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Nov 2012 | G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Mar 2014 | Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 May 2022 | Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls. | IT | Garante | GDPR | €100,000 | ↗ |
| 13 Feb 2007 | Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2026 | dottoressa GuzzoThe Garante imposed a fine of EUR 5,000 on dottoressa Guzzo for unlawfully processing personal data by publishing images of a deceased minor without consent. The authority found that this breached core data protection principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 18 Jul 2023 | Ermeslink di Giovanni Di StefanoThe Garante imposed a fine of EUR 5,000 on Ermeslink di Giovanni Di Stefano for improperly handling video surveillance data. The breach concerned data protection rules and could have affected all residents and non-residents of the Municipality of Modica. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Sept 2025 | Ente Parco Regionale Migliarino San Rossore MassaciuccoliEnte Parco Regionale Migliarino San Rossore Massaciuccoli was fined EUR 8,000 by the Garante for failing to implement adequate technical and organizational measures. The authority found that more personal data was processed than necessary, in breach of the GDPR and national data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 21 Feb 2013 | Terme Rosapepe s.a.s.Terme Rosapepe s.a.s. was fined EUR 4,800 by the Garante. The authority found that the company collected personal data through a website registration form without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 28 May 2026 | Regione Autonoma della SardegnaThe Garante fined Regione Autonoma della Sardegna EUR 3,000 for sharing disciplinary sanction information with unauthorized internal units. The authority found this breached the GDPR and national data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Jun 2024 | Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules. | IT | Garante | GDPR | €6,419,000 | ↗ |
| 16 Nov 2023 | Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Mar 2020 | Comune di San Giorgio JonicoComune di San Giorgio Jonico was fined by the Garante for publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €3,000 | ↗ |