BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Jul 2017 | InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information. | IT | Garante | GDPR | €40,000 | ↗ |
| 06 Jun 2024 | Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR. | IT | Garante | GDPR | €250,000 | ↗ |
| 09 Jul 2020 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention. | IT | Garante | GDPR | €800,000 | ↗ |
| 25 Jan 2018 | Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Jul 2024 | Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data. | IT | Garante | GDPR | €22,000 | ↗ |
| 17 Dec 2020 | Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 21 Apr 2011 | Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 May 2018 | Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 May 2015 | Zampino Giuseppe GiovanniZampino Viaggi, operated by Zampino Giuseppe Giovanni, was fined 2,400 EUR by the Garante. The authority found that personal data were collected through the website without the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Apr 2011 | Comune di AdroThe Municipality of Adro was fined 15,000 EUR by the Italian supervisory authority Garante. The case concerned the publication of employees’ personal data, including health information, in a periodical. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Dec 2015 | Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Mar 2015 | Liceo Statale "Farnesina"Liceo Statale Farnesina was fined EUR 4,000 by the Garante for unlawfully publishing lists of student names on its institutional website without a legal basis. The conduct breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Jan 2014 | Goldenbridge s.r.l.Goldenbridge s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice when collecting personal data through a website contact form. The authority found this to be a breach of the Italian data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Jan 2008 | Assioma selezione e sviluppo s.r.l.Assioma selezione e sviluppo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to comply with data protection notification requirements. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2014 | Zheng SuigenZheng Suigen was fined by the Italian data protection authority, Garante, in the amount of EUR 2,400. The case concerned inadequate information about the use of a video surveillance system, which breached privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 15 May 2013 | You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Dec 2022 | Scuola Statale Secondaria di I^ grado “Bianco-Pascoli”, di Fasano (BR)The school was fined by the Garante 3,000 EUR for violations in the processing of personal data, including minors' health information. The authority found that the processing lacked a proper legal basis and sufficient transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 20 Feb 2014 | Paola ZorzoloPaola Zorzolo was fined for failing to provide adequate privacy information in the video surveillance system at her gaming hall. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Mar 2017 | Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Oct 2024 | Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |