BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Apr 2015 | Regione CampaniaThe Garante fined Regione Campania EUR 4,000 for failing to provide requested information related to a disciplinary procedure. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Nov 2019 | Comune di TivoliThe Municipality of Tivoli was fined by the Italian data protection authority, Garante, for unlawfully publishing personal data on its institutional website. The publication also included information about a pending criminal proceeding, breaching the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €6,000 | ↗ |
| 02 Mar 2011 | Skiarea Valchiavenna S.p.A.Skiarea Valchiavenna S.p.A. was fined EUR 12,000 by the Garante. The authority found that the company failed to provide the required data protection information to skiers using its facilities, in breach of Articles 13 and 161 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Apr 2021 | Tiberia Assicurazioni s.a.s.Tiberia Assicurazioni s.a.s. was fined by the Garante 1,500 EUR for sending an insurance contract proposal by email without the recipient's consent. The authority found this to be a breach of GDPR Article 6. | IT | Garante | GDPR | €1,500 | ↗ |
| 04 Jun 2015 | Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 May 2021 | Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Dec 2022 | Azienda Universitaria Friuli CentraleAzienda Universitaria Friuli Centrale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found failures to provide instructions for data deletion and to stop unauthorized processing by Insiel spa. | IT | Garante | GDPR | €55,000 | ↗ |
| 29 Apr 2021 | Comune di Santa NinfaComune di Santa Ninfa was fined by the Garante 2,000 EUR for publishing a complainant’s personal data online. The publication also included detailed references to enforcement proceedings, which breached GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Sept 2022 | Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Nov 2024 | Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2026 | Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements. | IT | Garante | GDPR | €34,000 | ↗ |
| 06 Jul 2006 | Mediatec-Mr s.r.l.Mediatec-Mr s.r.l. was fined by the Garante for sending unsolicited promotional emails without providing the required information on data processing. The authority found a breach of the information obligation under data protection law. | IT | Garante | GDPR | €1,549 | ↗ |
| 10 Dec 2015 | Nuovo Pic Nic s.r.l.Nuovo Pic Nic s.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Jun 2014 | Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations. | IT | Garante | GDPR | €12,000 | ↗ |
| 10 Mar 2011 | Gruppo Guide Italia s.r.l.Gruppo Guide Italia s.r.l. was fined 8,000 EUR by the Garante for publishing personal data without authorization in a guide. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 12 Sept 2013 | Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Nov 2008 | XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Oct 2012 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 14 Nov 2024 | D’Anna Assicurazioni S.r.l.D’Anna Assicurazioni S.r.l. was fined by the Garante 5,000 EUR for sending unsolicited promotional emails despite the recipient’s objection. The authority found this breached GDPR rules on data subject rights and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 31 Jan 2019 | Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data. | IT | Garante | GDPR | €4,000 | ↗ |