BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Jul 2006 | Mediatec-Mr s.r.l.Mediatec-Mr s.r.l. was fined by the Garante for sending unsolicited promotional emails without providing the required information on data processing. The authority found a breach of the information obligation under data protection law. | IT | Garante | GDPR | €1,549 | ↗ |
| 10 Dec 2015 | Nuovo Pic Nic s.r.l.Nuovo Pic Nic s.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Jun 2014 | Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations. | IT | Garante | GDPR | €12,000 | ↗ |
| 10 Mar 2011 | Gruppo Guide Italia s.r.l.Gruppo Guide Italia s.r.l. was fined 8,000 EUR by the Garante for publishing personal data without authorization in a guide. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 12 Sept 2013 | Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Nov 2008 | XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Oct 2012 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 14 Nov 2024 | D’Anna Assicurazioni S.r.l.D’Anna Assicurazioni S.r.l. was fined by the Garante 5,000 EUR for sending unsolicited promotional emails despite the recipient’s objection. The authority found this breached GDPR rules on data subject rights and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 31 Jan 2019 | Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Jun 2011 | New Stereo In srlNew Stereo In srl was fined by the Garante 15,000 EUR for unlawful processing of personal data. The case concerned the activation of two unsolicited phone cards, in breach of Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 02 Feb 2019 | Ordinanza ingiunzione - 2 febbraio 2019 [9100784]The Garante imposed an administrative fine for violating data protection rules. The case concerned retaining surveillance footage for longer than the permitted 7 days. | IT | Garante | GDPR | €11,940 | ↗ |
| 17 Apr 2026 | Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay. | IT | Garante | GDPR | €2,500 | ↗ |
| 24 Jul 2014 | Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Sept 2021 | Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Jun 2021 | Ministero dell’InternoThe Italian Data Protection Authority fined Ministero dell’Interno EUR 75,000 for posting videos on social media that breached data protection rules. The footage related to a criminal case was shared by the police and contained violent content, which was found inconsistent with data protection principles. | IT | Garante | GDPR | €75,000 | ↗ |
| 04 Jul 2024 | Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities. | IT | Garante | GDPR | €7,000 | ↗ |
| 04 Apr 2007 | Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 May 2020 | Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Sept 2024 | CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Apr 2021 | Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5. | IT | Garante | GDPR | €20,000 | ↗ |