Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2026Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data.ITGaranteGDPR€12,000
05 Jun 2014Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules.ITGaranteGDPR€4,000
28 Apr 2022Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
29 Jan 2026Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules.ITGaranteGDPR€12,000
12 May 2022Minimarket di Alam SaifulThe Garante fined Minimarket di Alam Saiful 1,000 EUR for operating a video surveillance system without the required notice to individuals being recorded. The case concerned a breach of data protection information obligations.ITGaranteGDPR€1,000
31 May 2018Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities.ITGaranteGDPR€86,000
24 Nov 2016Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€10,000
20 Feb 2023Mindenki Magyarországa MozgalomNAIH imposed a HUF 3,000,000 fine on Mindenki Magyarországa Mozgalom and Márki-Zay Péter for GDPR violations. The authority found inadequate data processing information and failure to respect the right to object in Facebook Messenger communications.HUNAIHGDPR€7,830
09 Apr 2021Miljø- og Kvalitetsledelse ASMiljø- og Kvalitetsledelse AS was fined 35,000 NOK by Datatilsynet for unlawfully sending personal data from camera recordings to an employer without a legal basis. The authority cited breaches of GDPR Articles 6 and 5.NODatatilsynetGDPR€3,461
21 Feb 2017MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days.GRHDPAGDPR€1,000
24 Jun 2020MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified.ESAEPDGDPR€3,000
22 Jun 2023MIFARMA TIENDA ON-LINE, S.L.MIFARMA TIENDA ON-LINE, S.L. was fined by the AEPD €2,000 for sending commercial electronic communications after the recipient had requested that they stop. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
02 Apr 2015Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€15,000
01 Jun 2016Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
18 Apr 2013Mida S.a.s.Mida S.a.s. was fined by the Italian Garante 2,400 EUR for an inadequate privacy notice relating to its video surveillance system. The notice did not include the data controller’s information, which failed to meet the required transparency obligations.ITGaranteGDPR€2,400
01 Jan 2012MICROLOANS, S.L.MICROLOANS, S.L. was fined EUR 600 by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent from recipients, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
23 May 2022MH VILASECA S.L.MH VILASECA S.L. was fined by the AEPD 400 EUR for installing a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€400
12 Feb 2024MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€80,000
26 Jul 2018MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€26,000
27 Jun 2024METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure.GRHDPAGDPR€20,000