Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Nov 2019MEGASTAR, S.L.MEGASTAR, S.L. was fined by the AEPD EUR 2,000 for surveillance cameras that were improperly oriented and captured disproportionate images. The authority also found that the required informational signage was missing, constituting a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€2,000
01 Oct 2020Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations.ROANSPDCPGDPR€3,000
03 May 2022Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined by ANSPDCP in the amount of EUR 4,000 for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR.ROANSPDCPGDPR€4,000
26 Jul 2012Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects.ITGaranteGDPR€6,000
19 Nov 2021MEETING PUERTO C.B.MEETING PUERTO C.B. was fined by the AEPD EUR 2,000 for unlawful processing of personal data. The breach involved posting images and comments on social media without the consent of the data subjects, contrary to Article 6(1) of the GDPR.ESAEPDGDPR€2,000
17 Feb 2025Meedea Construct Prest SRLThe company was fined for violating the principles and lawfulness of personal data processing, specifically Articles 6 and 9 of the GDPR. A corrective measure was also imposed to ensure GDPR compliance in data collection and processing and to reduce the risk of unauthorized access and disclosure.ROANSPDCPGDPR€2,000
08 Feb 2024Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data.ITGaranteGDPR€300,000
20 Feb 2025Medstar S.R.L.Medstar S.R.L. was fined by ANSPDCP for failing to notify the data breach to the supervisory authority. The company also did not inform the affected individuals about the unauthorized disclosure of their personal data.ROANSPDCPGDPR€2,000
24 May 2022MEDLIFE S.A.In April 2022, ANSPDCP completed an investigation into MEDLIFE S.A. and found a breach of GDPR provisions. As a result, a fine of EUR 5,000 was imposed.ROANSPDCPGDPR€5,000
03 Aug 2023Med Life SAMed Life SA was fined EUR 2,000 by ANSPDCP. The authority found that the company violated the complainant’s right of access by refusing to provide certain video recordings from the reception area of one of its hospitals.ROANSPDCPGDPR€2,000
17 Sept 2021Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR.CYCyDPCGDPR€10,000
08 Jan 2026MEDIOS DE PREVENCIÓN EXTERNOS SUR, S.L.The company suffered a ransomware attack that caused a breach of the confidentiality and availability of personal data. AEPD found a violation of Article 5(1)(f) GDPR.ESAEPDGDPR€60,000
03 Dec 2021MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications.ESAEPDePrivacy€2,000
31 May 2024MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules.ESAEPDGDPR€100,000
12 Jun 2014Mediolanum Hotel s.r.l.Mediolanum Hotel s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required notice under Article 13 of the Italian Data Protection Code. The breach concerned the absence of the mandatory privacy information for job applicants.ITGaranteGDPR€2,400
08 Feb 2023Medijobs Platform SRLMedijobs Platform SRL was fined EUR 5,000 by ANSPDCP after unauthorized access to its IT infrastructure. The incident led to the downloading and deletion of certain personal data.ROANSPDCPGDPR€5,000
09 May 2024MEDICOVER SRLMEDICOVER SRL was fined EUR 1,000 by ANSPDCP for the unauthorized disclosure of personal data from a medical consultation report to an unintended patient. The case concerns a breach of confidentiality involving special-category data and indicates a need to strengthen access controls and recipient verification procedures.ROANSPDCPGDPR€1,000
24 Nov 2022Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data.ROANSPDCPGDPR€1,000
13 Jan 2022Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€4,000
09 Jul 2021Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls.DKDatatilsynetGDPR€53,788