Skip to content

🇪🇺 ITALY

548 decisions · €190.0M total fines · Italian Data Protection Authority (Garante)

Date ↓ Company / party Authority Articles Fine
2024-05-09 Azienda ospedale università di Padova
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €75,000
2024-05-09 Azzurro Club Hotels S.r.l.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 6Art. 12Art. 15Art. 130 €10,000
2024-05-09 Polisportiva Mimmo Ferrito s.r.l..
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €3,000
2024-05-09 Medical association
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 2 €3,000
2024-04-24 Rossi Carta S.r.l.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 6Art. 7Art. 12Art. 15 €30,000
2024-04-24 Gestore Dei Servizi Energetici - Gse S.p.A.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €30,000
2024-04-24 C.I.E.L. S.p.A.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €10,000
2024-04-24 Dly S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 88Art. 114 €5,000
2024-04-24 I.N.P.A.S.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 2 €3,000
2024-04-11 Facile.Energy S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 24Art. 25 €100,000
2024-04-11 Olimpia S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 24Art. 25 €100,000
2024-04-11 Innova Camara
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5 €25,000
2024-04-11 Istituto Nazionale di Previdenza Sociale
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 2 €20,000
2024-04-11 Libero Consorzio comunale di Enna
Insufficient involvement of data protection officer
🇪🇺 Italian Data Protection Authority (Garante) Art. 37Art. 38 €6,000
2024-04-11 Store owner
Insufficient fulfilment of information obligations
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13 €1,000
2024-03-21 Azienda sanitaria locale Roma 3
Insufficient fulfilment of data breach notification obligations
🇪🇺 Italian Data Protection Authority (Garante) Art. 33 €10,000
2024-03-07 Centro Riparazioni Piacentino S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13 €20,000
2024-03-07 Banca di Credito Cooperativo Appulo Lucana soc. cooperativa
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €20,000
2024-03-07 Bar
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 114 €2,000
2024-02-22 Azienda Trasporto Passeggeri Emilia-Romagna S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €50,000
2024-02-22 Camera di Commercio Industria Artigianato e Agricoltura
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 2 €2,000
2024-02-08 UniCredit S.p.a.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 32 €2,800,000
2024-02-08 NTT Data Italia S.P.A
Insufficient fulfilment of data breach notification obligations
🇪🇺 Italian Data Protection Authority (Garante) Art. 28Art. 33 €800,000
2024-02-08 Medtronic Italia
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 12Art. 13 €300,000
2024-02-08 Azienda socio-sanitaria locale n. 1 di Sassari
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 32 €18,000