Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Dec 2023MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them.ESAEPDePrivacy€5,000
09 Mar 2017Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing.ITGaranteGDPR€14,400
24 Jun 2021Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data.NODatatilsynetGDPR€49,145
22 Jun 2023More News società cooperativa a r.l.The Garante fined More News società cooperativa a r.l. 5,000 EUR for publishing a minor’s personal data without proper anonymization. The disclosure allowed acquaintances to identify the child and caused embarrassment.ITGaranteGDPR€5,000
01 Jan 2019Morele.netMorele.net received an administrative fine from the President of the Personal Data Protection Office (UODO) for a GDPR violation. The 2,830,410 PLN penalty followed a phishing attack that led to unauthorized access to customer data affecting about 2.2 million people.PLPresident of the Personal Data Protection Office (UODO)GDPR€658,000
01 Jan 2025MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined by the AEPD EUR 3,000 for requesting excessive personal data, including banking information, in connection with a free gym access promotion. The authority found that the data requested breached the GDPR data minimisation principle under Article 5(1)(c).ESAEPDGDPR€3,000
24 Jul 2024MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial SMS messages without recipient consent. The case concerned Article 21 of the LSSI, which requires prior consent for electronic marketing communications.ESAEPDePrivacy€5,000
13 Nov 2024Montini Group S.r.l.Montini Group S.r.l. was fined EUR 6,000 by the Garante. The case concerned contacting an employee’s general practitioner without consent, which breached GDPR rules on processing health data.ITGaranteGDPR€6,000
09 Jun 2016Montanaro Auto s.r.l.Montanaro Auto s.r.l. was fined by the Garante in the amount of 4,800 EUR for failing to provide data subjects with information about data processing. The breach concerned a video surveillance system and a web form, in violation of the Italian Data Protection Code.ITGaranteGDPR€4,800
12 Dec 2024Money Bubble Ltd MPNBetween October and November 2022, the company made 168,852 spam calls, leading to further complaints to the ICO and TPS. Money Bubble Ltd MPN did not provide evidence that the called individuals had consented to receive calls. The ICO imposed a £120,000 fine.GBICOGDPR€145,000
14 Dec 2022Monetise Media LimitedBetween 28 July 2020 and 28 July 2021, Monetise Media Limited sent 3,506,157 direct marketing emails and text messages. The recipients had not provided valid consent, which breached regulation 22 of PECR.GBICOePrivacy€145,000
05 May 2011Mondolibri s.p.a.Mondolibri s.p.a. was fined EUR 8,000 by the Garante for collecting personal email addresses through its website without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€8,000
16 Feb 2017Momax s.r.l.Momax s.r.l. was fined by the Garante for improper handling of telephone traffic data. The authority found failures to implement appropriate safeguards, including strong authentication and biometric recognition measures, and retention of data beyond the permitted period for billing and crime prevention purposes.ITGaranteGDPR€60,000
20 Mar 2008MO.MA. s.r.l.MO.MA. s.r.l. was fined by the Garante for failing to comply with a request to confirm the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000
27 Nov 2024Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry.ITGaranteGDPR€10,000
24 Apr 2013ModenaFiere S.r.l.ModenaFiere S.r.l. was fined EUR 16,000 by the Garante for processing personal data without adequate notice and consent. The violations covered promotional communications, statistical activities, and the dissemination of data on its website and in publications.ITGaranteGDPR€16,000
30 Mar 2025MODEL REYNA, C.B.MODEL REYNA, C.B. was fined by the AEPD EUR 3,000 for failing to provide access to personal data and related information. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€3,000
13 Mar 2023Modaone SRLModaone SRL was fined by ANSPDCP EUR 2,000 for sending commercial emails to a data subject after the person had objected. The authority found a breach of the GDPR right to object.ROANSPDCPGDPR€2,000
11 Dec 2025Mobius Solutions LtdThe French CNIL imposed a 1 million EUR fine on Mobius Solutions Ltd for personal data processing violations. The case involved unlawful retention and reuse of data from more than 46 million users after the contract ended, as well as failure to maintain a processing activities register.FRCNILGDPR€1,000,000
20 Aug 2025MOBILITY EVOLUTION S.A.MOBILITY EVOLUTION S.A. was fined EUR 15,000 by the AEPD for failing to properly process data deletion requests submitted through its application. The authority found that the company’s handling of these requests breached Article 25 GDPR on data protection by design and by default.ESAEPDGDPR€15,000