Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Oct 2023MOBILITY AUTOCENTRO, S.L.MOBILITY AUTOCENTRO, S.L. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached the Spanish LSSI.ESAEPDePrivacy€2,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules.ITGaranteGDPR€20,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 16,000 by the Italian Garante. The case concerned promotional calls made without providing the required data protection information and without obtaining consent, in breach of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€16,000
26 Oct 2017M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code.ITGaranteGDPR€20,000
08 May 2026MLU B.V.MLU B.V. was fined €100,000,000 by AP for transferring personal data of users in Finland and Norway to Russia without adequate safeguards. The authority found breaches of GDPR Articles 44, 46, and 5.NLAPGDPR€100,000,000
08 May 2026MLU B.V.The Dutch data protection authority imposed a EUR 100 million fine on MLU B.V. for transferring personal data to Russia without adequate safeguards. It also ordered the company to stop transferring personal data of individuals in Norway and Finland to Russia via the Yango app.NLAutoriteit PersoonsgegevensGDPR€100,000,000
26 Jun 2014Mitomet s.r.l.Mitomet s.r.l. was fined 12,000 EUR by the Garante for using an integrated video surveillance system. The system allowed viewing images from workplaces without implementing the required privacy safeguards.ITGaranteGDPR€12,000
25 Feb 2021Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
05 Aug 2022Mister Brick S.a.s.Mister Brick S.a.s. was fined EUR 1,000 by the Garante for sending an unsolicited promotional email without obtaining prior consent from the recipient. The authority found this to be a breach of GDPR requirements on lawful processing and consent.ITGaranteGDPR€1,000
01 Jan 2013MISCOTA E-COMMERCE, S.L.MISCOTA E-COMMERCE, S.L. was fined by the AEPD 1,800 EUR for sending unsolicited advertising emails to a complainant. The emails continued despite requests to be removed from the mailing list.ESAEPDePrivacy€1,800
08 Jun 2023Mirva s.r.l.Mirva s.r.l. was fined by the Garante 5,000 EUR for installing a video surveillance system without proper informational signage. The system also captured areas not pertaining to the company, which breached data protection rules.ITGaranteGDPR€5,000
17 Dec 2020Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities.ITGaranteGDPR€40,000
27 Jan 2022MIRACLE IBIZA S.L.MIRACLE IBIZA S.L. was fined by the AEPD in the amount of EUR 500 for improperly positioning a surveillance camera. The camera captured the entrance to a private residence, affecting the privacy of individuals.ESAEPDGDPR€500
01 Jan 2013MIPE COMUNICATION, S.L.MIPE COMUNICATION, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without recipient consent. The authority also found that the messages did not include an opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€600
26 Feb 2024Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP.GBICOGDPR€409,000
20 Dec 2023Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR.PLUODOGDPR€23,035
17 Mar 2025Ministra CyfryzacjiUODO imposed an administrative fine of 100,000 PLN on the Minister of Digital Affairs. The breach concerned Article 6(1) and Article 5(1)(a) of Regulation 2016/679.PLUODOGDPR€23,887
07 Dec 2021Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws.NLAPGDPR€2,750,000
12 Apr 2022Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles.NLAPGDPR€3,700,000
06 Apr 2022Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications.NLAPGDPR€565,000