Skip to content
Content type · 697 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Italy (50) Clear filter
1–50 of 697 sort newestlargest fineoldest
10297167 10297167 ·Garante
€5,000 Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission… Garante ·Art. 5, 6 Public Authority Supervisory Authorities Personal Data Sep 30, 2026
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Art. 5, 6, 9 Personal Data Retention Period Healthcare Sep 29, 2026
€39,000 Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the… Garante ·Art. 12, 13, 15 Supervisory Authorities Right of Access Personal Data Sep 23, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
€6,500 Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after The data subjects filed a complaint claiming that Top Secret Investigazioni e sicurezza s.r.l. (the controller) violated the protection of personal data, as a result of failing to… Garante ·Art. 5, 13 Supervisory Authorities Retention Period Personal Data Sep 10, 2026
€10,000 Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive The data subject, an employee of the Ministry of Education and Merit (the controller), filed a complaint with the DPA after the controller notified various administrative branches… Garante ·Art. 5, 6 Supervisory Authorities Personal Data Retention Period Sep 9, 2026
€10,000 Garante · 551/2026 The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based… Art. 5, 6, 9 Personal Data Types of Special Categories of Personal Data Integrity and Confidentiality Principle
Garante warns ReLife Recycling for failing to timely respond to GDPR access request The data subject sent a complaint to the DPA regarding correspondence between him and the company ReLife Recycling s.r.l. (the controller), which was sent without his consent to… 515/2026 ·Art. 12 Right of Access Personal Data Supervisory Authorities
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Garante ·Art. 5, 12, 21 +1 Right to Object Personal Data Direct Marketing Sep 3, 2026
€8,000 Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) found that Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento (A.S.I.S.) unlawfully installed video… Garante ·Art. 5, 6, 12 +1 Retention Period Storage Limitation Personal Data Sep 3, 2026
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Garante ·Art. 5, 9, 25 +1 Integrity and Confidentiality Principle Data Breaches Right of Access Sep 3, 2026
€23,750 Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car On 4 January 2024, the newspaper “Il Fatto Quotidiano” (‘the controller’) published an article pertaining to the cable car accident of the data subject. The data subject sent a… Garante ·Art. 5, 83 Personal Data Supervisory Authorities Retention Period Aug 26, 2026
€280,000 Garante · 10269624 The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the… Art. 6, 7, 12 +2 Right to Object Personal Data Direct Marketing
€15,300 10266250 The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone… Garante ·Art. 5, 6, 7 +6 Processors Controllers Personal Data Aug 19, 2026
An Italian broadcasting company (controller) disseminated an episode about the murder of a woman The murder case dates back several years but gained new attention after the investigation into the murder case was re-opened. In the dissemination, the interior of the home of the… 10273026 ·Garante Personal Data Retention Period Right to be Forgotten Aug 18, 2026
€1,000 Leontinoi Società Cooperativa Sociale: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Leontinoi Società Cooperativa Sociale €1,000 for insufficient fulfilment of data subjects' rights, citing violations of… Garante ·Art. 12, 15, 31 Supervisory Authorities Personal Data Supervision Aug 6, 2026
€9.5M TIM S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined TIM S.p.A. €9,516,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 15, 22, 24, 25, 28, and 32,… Garante ·Art. 5, 6, 7 +6 Supervision Personal Data Supervisory Authorities Jul 23, 2026
The case involves media company RTI S.p.a (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. The program aired a segment consisting of satirical, AI-generated deepfakes of… Case number: 577/2026 Internal number (from the DPA): 10281021 ·Garante Transparency Privacy by Design Controllers Jul 23, 2026
€10,000 Bologna University Hospital IRCCS: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Bologna University Hospital IRCCS €10,000 for processing personal data without a sufficient legal basis. The Garante found… Garante ·Art. 5, 6, 9 Legitimate Interest Healthcare Types of Special Categories of Personal Data Jul 23, 2026
€6,500 Top Secrert Investigazioni e sicurezza s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Top Secrert Investigazioni e sicurezza s.r.l. €6,500 for violating the general data processing principles under Article… Garante ·Art. 5, 13 Retention Period Storage Limitation Processing Jul 23, 2026
€30,000 Emiglia-Romagna Regional Employment Agency: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Emiglia-Romagna Regional Employment Agency €30,000 for violations of Articles 5, 6, and 9 of the GDPR concerning an… Garante ·Art. 5, 6, 9 Legitimate Interest Personal Data Processing Jul 23, 2026
€9.5M Garante · 556/2026 Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited… Art. 5, 6, 7 +5 Personal Data Integrity and Confidentiality Principle Controllers Jul 23, 2026
€10,000 Monza and Brianza Local Education Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Monza and Brianza Local Education Authority €10,000 for failing to establish a sufficient legal basis for data processing… Garante ·Art. 5, 6 Personal Data Public Authority Supervision Jul 23, 2026
€8,000 Municipality of Terralba: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Terralba €8,000 for processing personal data without a sufficient legal basis. The Garante found that the… Garante ·Art. 5, 6, 24 +2 Personal Data Processing Public Authority Jul 23, 2026
€2,000 Ancel Keys Comprehensive School Castelnuovo Cilento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Ancel Keys Comprehensive School Castelnuovo Cilento €2,000 for processing personal data without a sufficient legal basis,… Garante ·Art. 5, 6, 9 Personal Data Public Authority Supervisory Authorities Jul 23, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Art. 4, 5, 6 +2 Personal Data Health Data Types of Special Categories of Personal Data
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Art. 5, 6, 10 +1 Personal Data Retention Period Criminal Data Jul 18, 2026
€50,000 Garante · 10128005 The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Art. 5, 6, 13 +3 Personal Data Monitoring DPIA
€16,000 10192784 The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Garante ·Art. 1, 5, 6 +3 Personal Data Retention Period Fairness & Transparency
€6,000 Municipality of Rieti: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Rieti €6,000 for violations of general data processing principles under the GDPR. The enforcement action… Garante ·Art. 5, 12, 24 +3 Privacy by Design Retention Period Supervision Jul 14, 2026
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
€120,000 NIER Ingeriegna S.p.A. SB: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined NIER Ingegneria S.p.A. SB €120,000 for failing to implement adequate technical and organizational measures to ensure… Garante ·Art. 5, 32 Security Supervision Supervisory Authorities Jul 14, 2026
€700 La Terrazza: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined La Terrazza, an entity in the accommodation and hospitality sector, €700 for failing to adequately fulfill its information… Garante ·Art. 5, 6, 13 Transparency Supervisory Authorities Jul 14, 2026
€5.8M 483/2026 Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Garante ·Art. 5, 12, 13 +3 Controllers Processors Personal Data Jul 3, 2026
€2,000 Municipality of Villaputzu: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Villaputzu €2,000 for processing personal data without a sufficient legal basis. The enforcement action… Garante ·Art. 5, 6 Personal Data Processing Public Authority Jul 3, 2026
€15,000 University of Pisa: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the University of Pisa €15,000 for failing to implement adequate technical and organizational measures to ensure information… Garante ·Art. 5, 6, 25 +1 Security Personal Data Public Authority Jul 3, 2026
€10,000 Giuliano Isontina University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Giuliano Isontina University Health Authority €10,000 for failing to implement adequate technical and organizational… Garante ·Art. 5, 9, 25 +1 Security Healthcare Types of Special Categories of Personal Data Jul 3, 2026
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Art. 3, 5, 12 +7 Child Consent Personal Data Right to Object Jul 3, 2026
€1.4M EstEnergy S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined EstEnergy S.p.A. €1,400,000 for violations of general data processing principles under Article 5(1) of the GDPR, alongside… Garante ·Art. 5, 12, 13 +3 Controllers Processors Retention Period Jul 3, 2026
€5.8M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Hera Comm S.p.A. €5,800,000 for violations of the general data processing principles under Article 5 of the GDPR, alongside… Garante ·Art. 5, 12, 13 +3 Processors Controllers Supervision Jul 3, 2026
€1.4M Garante · 484/2026 EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Art. 5, 13, 14 +2 Retention Period Controllers Right of Access Jul 3, 2026
€120,000 Experian Italia S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Experian Italia S.p.A. €120,000 for violating GDPR Articles 5(1)(a) and (c), 12, 15, and 25, concerning non-compliance with… Garante ·Art. 5, 12, 15 +1 Privacy by Design Right of Access Supervision Jul 3, 2026
€2,000 Municipality of San Genesio and Uniti: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of San Genesio and Uniti €2,000 for processing personal data without a sufficient legal basis. The Authority… Garante ·Art. 5, 6, 9 Personal Data Processing Public Authority Jul 3, 2026
€158,000 Character Technologies Inc.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Character Technologies Inc. €158,000 for violations of multiple GDPR provisions, including Article 5(2) on general data… Garante ·Art. 5, 12, 13 +5 Accountability Transparency Representatives Jul 3, 2026
€400,000 Cerved Group S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Cerved Group S.p.A. €400,000 for insufficient fulfillment of data subjects' rights, including violations of Article 5(1)(a),… Garante ·Art. 5, 12, 15 Supervisory Authorities Transparency Insurance Jul 3, 2026
€23,750 Società Editoriale Il Fatto S.p.A.: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Società Editoriale Il Fatto S.p.A. €23,750 for processing personal data without a sufficient legal basis, in violation of… Garante ·Art. 5 Personal Data Processing Transparency Jul 3, 2026
€20,000 Enna Provincial Health Authority: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Enna Provincial Health Authority €20,000 for violating GDPR Articles 5, 6, 10, and 12, which concern general data… Garante ·Art. 5, 6, 10 +1 Supervision Supervisory Authorities Transparency Jun 18, 2026
€90,000 Acquirente Unico S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Acquirente Unio S.p.A. €90,000 for insufficient fulfilment of data subjects' rights under GDPR Articles 12, 16, and 28. The… Garante ·Art. 12, 16, 28 Processors Supervision Controllers Jun 18, 2026