BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2026 | Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data. | IT | Garante | GDPR | €12,000 | ↗ |
| 05 Jun 2014 | Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 28 Apr 2022 | Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jan 2026 | Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 12 May 2022 | Minimarket di Alam SaifulThe Garante fined Minimarket di Alam Saiful 1,000 EUR for operating a video surveillance system without the required notice to individuals being recorded. The case concerned a breach of data protection information obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 31 May 2018 | Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities. | IT | Garante | GDPR | €86,000 | ↗ |
| 24 Nov 2016 | Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Feb 2023 | Mindenki Magyarországa MozgalomNAIH imposed a HUF 3,000,000 fine on Mindenki Magyarországa Mozgalom and Márki-Zay Péter for GDPR violations. The authority found inadequate data processing information and failure to respect the right to object in Facebook Messenger communications. | HU | NAIH | GDPR | €7,830 | ↗ |
| 09 Apr 2021 | Miljø- og Kvalitetsledelse ASMiljø- og Kvalitetsledelse AS was fined 35,000 NOK by Datatilsynet for unlawfully sending personal data from camera recordings to an employer without a legal basis. The authority cited breaches of GDPR Articles 6 and 5. | NO | Datatilsynet | GDPR | €3,461 | ↗ |
| 21 Feb 2017 | MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days. | GR | HDPA | GDPR | €1,000 | ↗ |
| 24 Jun 2020 | MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified. | ES | AEPD | GDPR | €3,000 | ↗ |
| 22 Jun 2023 | MIFARMA TIENDA ON-LINE, S.L.MIFARMA TIENDA ON-LINE, S.L. was fined by the AEPD €2,000 for sending commercial electronic communications after the recipient had requested that they stop. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 02 Apr 2015 | Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 01 Jun 2016 | Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Apr 2013 | Mida S.a.s.Mida S.a.s. was fined by the Italian Garante 2,400 EUR for an inadequate privacy notice relating to its video surveillance system. The notice did not include the data controller’s information, which failed to meet the required transparency obligations. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Jan 2012 | MICROLOANS, S.L.MICROLOANS, S.L. was fined EUR 600 by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent from recipients, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 23 May 2022 | MH VILASECA S.L.MH VILASECA S.L. was fined by the AEPD 400 EUR for installing a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €400 | ↗ |
| 12 Feb 2024 | MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €80,000 | ↗ |
| 26 Jul 2018 | MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 27 Jun 2024 | METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure. | GR | HDPA | GDPR | €20,000 | ↗ |