Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Nov 2024Mario IonàMario Ionà was fined EUR 2,000 by the Garante for sending unsolicited emails and SMS promoting a tutoring service. The website lezioniprivate.eu did not provide information about the data controller, which added an information-duty breach.ITGaranteGDPR€2,000
01 Jan 2021MARINS PLAYA, S.A.MARINS PLAYA, S.A. was fined by the AEPD in the amount of EUR 30,000 for unlawfully scanning a customer's passport during hotel registration. The authority found that this breached Article 6 of the GDPR because there was no valid legal basis for the processing.ESAEPDGDPR€30,000
31 Jan 2024MARINA SALUD, S.A.MARINA SALUD, S.A. was fined by the AEPD 500,000 EUR for failing to comply with data processing agreement obligations under Article 28 GDPR. The case involved the handling of sensitive health data, which increased the compliance risk.ESAEPDGDPR€500,000
18 Apr 2018Marigliano GianpaoloMarigliano Gianpaolo was fined by the Garante 50,000 EUR for unlawfully using personal data to activate 15 phone cards without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and consent rules.ITGaranteGDPR€50,000
30 May 2022MARIELI GABRIELA, S.L.MARIELI GABRIELA, S.L. was fined by the AEPD in the amount of 3,000 EUR for charging amounts to the complainant's bank account without consent. The authority found a breach of Article 6(1) GDPR, meaning there was no lawful basis for the processing.ESAEPDGDPR€3,000
05 Sept 2013Maria Vita PezzellaMaria Vita Pezzella was fined EUR 6,000 by Garante for failing to provide the required privacy notice in a video surveillance system. The case concerned a breach of the Italian Privacy Code and the duty to inform individuals subject to monitoring.ITGaranteGDPR€6,000
10 Jun 2021MARIA & DESPOINA KOUSATHANA O.E.The company was fined by the HDPA 5,000 EUR for operating a video surveillance system without proper notification and for unlawful camera use in kitchen areas. The authority also found that data subjects were not informed about the processing of their personal data.GRHDPAGDPR€5,000
22 May 2013Margiotta Pietro Antonio e ASL TA 1 – Azienda Sanitaria Locale di TarantoThe Garante fined Margiotta Pietro Antonio and ASL TA 1 10,000 EUR for failing to implement minimum security measures. In some departments, unauthorized personnel accessed patient data and shared authentication credentials were used.ITGaranteGDPR€10,000
25 Oct 2025MAR DEGUSTACIÓN, S.LMAR DEGUSTACIÓN, S.L was fined by the AEPD 1,000 EUR for installing a video surveillance system without proper consent and for failing to inform affected individuals. The authority cited breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
08 Jun 2023Marcozzi Brand s.r.l.Marcozzi Brand s.r.l. was fined €8,400 by the Garante. The case concerned the failure to provide the complainant with the name of the occupational physician and the specific reasons for a negative fitness-for-work assessment, breaching GDPR transparency and access rights.ITGaranteGDPR€8,400
20 Mar 2008Marco TardelliMarco Tardelli was fined by the Garante for failing to provide a complete response to a personal data access request. The authority found a breach of the Italian data protection code.ITGaranteGDPR€4,000
03 May 2018Marconi RobertoMarconi Roberto, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum security measures to protect patients' personal and sensitive data were not adopted, allowing unauthorized access to the healthcare system.ITGaranteGDPR€10,000
02 Feb 2017Marc 1 s.r.l.Marc 1 s.r.l. was fined €850,000 by the Garante for transferring money to China using techniques designed to avoid anti-money laundering rules. The authority also found that the actual senders had not given consent for the processing of their personal data.ITGaranteGDPR€850,000
16 Jun 2021MARBELLA RESORTS, S.L.MARBELLA RESORTS, S.L. was fined EUR 7,000 by the AEPD for non-compliance with data protection rules. The breaches concerned the handling of personal data and the website cookie policy.ESAEPDePrivacy€7,000
19 May 2025Maravet S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Maravet S.R.L. and found a violation of GDPR provisions. The operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
31 May 2024MAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.AMAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.A was fined EUR 300,000 by the AEPD. The authority found that the company carried out unauthorized investment transactions using personal data without consent, in breach of data protection rules.ESAEPDGDPR€300,000
09 Sept 2022MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims.ESAEPDGDPR€30,000
03 Oct 2023MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€1,140,000
01 Jan 2019MAPEX AGENCIA CONSULTING, S.L.MAPEX AGENCIA CONSULTING, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited emails promoting its services without prior recipient authorization. The conduct breached Article 21.1 of the LSSI on electronic commercial communications.ESAEPDePrivacy€1,000
02 Jul 2020Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles.ITGaranteGDPR€15,000