Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2023Meta Platforms Ireland Limited (previously known as Facebook Ireland Limited)The Irish DPC imposed a fine of EUR 1,200,000,000 on Meta Platforms Ireland Limited (formerly Facebook Ireland Limited) in case IN-20-8-1. The decision is currently under appeal.IEDPCGDPR€1,200,000,000
26 Sept 2024Meta Platforms Ireland Limited (MPIL)The Irish DPC imposed a fine of 91,000,000 EUR on Meta Platforms Ireland Limited. The case relates to an inquiry and is currently pending appeal.IEDPCGDPR€91,000,000
31 Dec 2022Meta Platforms Ireland Limited - encompassing two decisions for Facebook & Instagram servicesThe Irish DPC fined Meta Platforms Ireland Limited EUR 390,000,000 in two decisions concerning the Facebook and Instagram services. The case relates to inquiries IN-18-5-5 and IN-18-5-7, and the status is pending appeal.IEDPCGDPR€390,000,000
12 Dec 2024Meta Platforms Ireland LimitedThe Irish DPC imposed a fine of EUR 251,000,000 on Meta Platforms Ireland Limited in connection with inquiries IN-18-10-1 and IN-18-11-1. The matter is currently pending appeal.IEDPCGDPR€251,000,000
02 Sept 2022Meta (Instagram)The Irish DPC imposed a fine of EUR 405,000,000 on Meta (Instagram) in inquiry IN-20-7-4. The decision is currently under appeal.IEDPCGDPR€405,000,000
15 Mar 2022Meta (Facebook)The Irish DPC fined Meta (Facebook) EUR 17,000,000 in case IN-18-11-5. The penalty has been collected.IEDPCGDPR€17,000,000
25 Nov 2022Meta DatasetThe Irish DPC fined Meta Dataset EUR 265,000,000 in inquiry IN-21-4-2. The matter is currently pending appeal.IEDPCGDPR€265,000,000
23 Apr 2025MetaThe European Commission fined Meta EUR 200 million for breaching the Digital Markets Act. The sanction concerns Meta’s “consent or pay” model used for Facebook and Instagram users in Europe.IEEuropean CommissionDMA€200,000,000
26 Mar 2026Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts.ITGaranteGDPR€10,000
09 Jul 2020Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre.ITGaranteGDPR€200,000
18 Sept 2014Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures.ITGaranteGDPR€40,000
09 May 2018Mercuri SalvatoreMercuri Salvatore was fined by the Garante EUR 60,000 for making unsolicited promotional calls to individuals whose phone numbers were listed in the opposition register. This conduct infringed their right to object to such communications.ITGaranteGDPR€60,000
12 Jun 2021MERCEDES GERENCIA, S.L.MERCEDES GERENCIA, S.L. was fined by the AEPD in the amount of 3,000 EUR for breaching Article 58.1 of the GDPR. The case concerned non-compliance with obligations related to the supervisory authority’s powers.ESAEPDGDPR€3,000
26 Jul 2018Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
03 Feb 2021MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6.ESAEPDGDPR€170,000
14 Feb 2023MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients.ESAEPDGDPR€2,000
24 Oct 2023Mensajero SRLMensajero SRL was fined EUR 3,000 by ANSPDCP for a data security breach on its website. A link allowed access to downloadable files containing customer invoices and product warranty certificates.ROANSPDCPGDPR€3,000
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
18 Jan 2021MEJORFRESCO TIENDA ONLINE, S.L.MEJORFRESCO TIENDA ONLINE, S.L. was fined by the AEPD EUR 2,000 for sending advertising emails without the recipient's consent. The case concerned Article 21 of the LSSI and reflects unlawful direct marketing practices.ESAEPDePrivacy€2,000
14 Nov 2022Megismételt eljárásban bírság kiszabásaThe authority imposed a fine for violations related to the processing of personal data and special categories of data, including health data, without proper notification and consent. The case also concerned actions linked to the termination of an employment relationship.HUNAIHGDPR€1,230