Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Garante per la protezione dei dati personali €91.5m 100 % · 8 cases
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €79.1m |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €5m |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 2 | €135,000 |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €1.72m |
| Q3 2026 | 3 | €5.54m |
8 cases
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator €8,000
Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.
Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante – Provvedimento n. 619 del 3 settembre 2026 [10294255] (ASIS Trento) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style €120,000
At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.
Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.
Employee monitoring through telematics
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- Mitigating circumstances
- Small number of data subjects (five employees), immediate suspension of the processing.
- Provvedimento del 18 dicembre 2025 [10213711] (Reg. 755/2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees €15,000
The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).
Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.
Purpose limitation in video surveillance and employee data
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 5, 6, 12, 13, 35, 88
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Provvedimento del 23 ottobre 2025 [10196164] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 Foodinho S.r.l. (Glovo-Gruppe)Garante: 5 million EUR against Glovo subsidiary Foodinho over monitoring of riders €5m
The delivery platform unlawfully processed data on more than 35,000 riders: facial recognition for identity verification, location tracking even outside working hours and automated assessments without human review. Foodinho had already been sanctioned with 2.6 million EUR in 2021; in addition to 5 million EUR, the Italian data protection authority (Garante per la protezione dei dati personali) prohibited the biometric processing.
Algorithmic management of workers requires transparency and human review, and must not include tracking outside working hours.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO (u. a. Transparenz, biometrische Daten, automatisierte Entscheidungen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Repeat case
- yes
- Published
- 22 Nov 2024
- Rider, Garante privacy: no all'algoritmo incontestabile dai lavoratori Press release of an authority
- Garante – Rider: Sanzione di 2,6 milioni di euro a una piattaforma del gruppo Glovo (2021) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Feb 2024 Enel Energia S.p.A.Garante: record fine of 79 million EUR against Enel Energia over illegal telemarketing €79.1m
Unauthorised intermediaries exploited security gaps in Enel's customer and activation systems for illegal telemarketing; over several years, at least 9,300 contracts were activated, 978 of which were purchased from companies outside the sales network. The Italian data protection authority (Garante per la protezione dei dati personali) imposed 79,107,101 EUR; the Rome court (Tribunale di Roma) upheld the decision on 18 September 2025, and an appeal is pending.
Companies that organise sales through partners must secure their systems against third-party access and reject contracts from unknown sources.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO; Codice privacy (Telemarketing)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- Employees
- 10,000 or more
- Published
- 29 Feb 2024
- Telemarketing: il Garante privacy sanziona Enel Energia Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link