Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Dec 2022MEDECIN (procédure simplifiée)The CNIL imposed a EUR 5,000 fine on MEDECIN under a simplified procedure. The authority also issued an injunction subject to a penalty payment, indicating the need for prompt remediation.FRCNILGDPR€5,000
27 Dec 2023MEDECIN PEDIATRE (procédure simplifiée)The CNIL imposed a 1,000 EUR fine on MEDECIN PEDIATRE under a simplified procedure. The case concerns a regulatory breach, with no further details provided in the record.FRCNILGDPR€1,000
11 Sept 2025MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of 3,000 EUR on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
08 Feb 2023MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on MEDECIN GENERALISTE under a simplified procedure. The authority also issued an injunction to remedy the identified deficiencies.FRCNILGDPR€3,000
19 Dec 2024MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed EUR 2,000 on MEDECIN GENERALISTE under a simplified procedure as a liquidation of a penalty payment. The decision relates to failure to comply with a prior obligation within the required timeframe.FRCNILGDPR€2,000
10 Jun 2024MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of EUR 4,000 on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€4,000
04 Apr 2025MEDCENTER SRLMEDCENTER SRL was fined EUR 30,000 by ANSPDCP for breaching GDPR requirements. The company failed to inform affected individuals about a personal data security breach.ROANSPDCPGDPR€30,000
13 Feb 2025MDE – Movimento Diritti Europei s.r.l.s.MDE – Movimento Diritti Europei s.r.l.s. was fined 15,000 EUR by the Garante. The authority found that the company failed to provide shareholders with the information required under GDPR Article 14 and instead referred them to a website that did not contain sufficient details.ITGaranteGDPR€15,000
28 Sept 2023MCP Online LtdThe ICO fined MCP Online Ltd 55,000 GBP after finding that 20,939 calls were made between 1 January 2022 and 28 September 2022 to numbers registered with the CTPS or TPS. The conduct breached Regulations 21 and 24 of PECR and came to light through Operation Torc, which investigates unsolicited pensions calls.GBICOePrivacy€63,707
23 Jun 2025McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures.PLPresident of the Personal Data Protection OfficeGDPR€3,960,000
04 May 2017McDonald’s Development ItalyMcDonald’s Development Italy was fined EUR 15,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under the video surveillance guidelines.ITGaranteGDPR€15,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000
17 May 2022MAYR MELNHOF PACKAGING ROMANIA S.R.L.The company was fined by ANSPDCP for processing images in a manner that was not adequate, relevant, or limited to what was necessary for the stated purpose. The authority found a breach of the data minimization principle.ROANSPDCPGDPR€1,500
22 Nov 2024Maynooth UniversityThe Irish DPC imposed a fine of EUR 40,000 on Maynooth University in inquiry IN-19-9-3. The penalty has been collected.IEDPCGDPR€40,000
22 Nov 2024MAXPOWER FITNESS NUTRITION, S.L.MAXPOWER FITNESS NUTRITION, S.L. was fined by the AEPD in the amount of 2,000 EUR for deficiencies in its cookie policy. The breach concerned the information and consent requirements under the LSSI.ESAEPDePrivacy€2,000
20 Jun 2024Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations.ITGaranteGDPR€5,000
18 Jul 2023Maximum International Corp. S.r.l.The Garante fined Maximum International Corp. S.r.l. 5,000 EUR for making promotional calls without consent and for failing to respond to data access and deletion requests. The case concerns breaches of personal data processing rules and data subject rights.ITGaranteGDPR€5,000
27 Nov 2024Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations.ITGaranteGDPR€10,000
08 Jun 2023Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice.GBICOePrivacy€139,000
01 Jan 2021MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis.ESAEPDGDPR€4,000