BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Nov 2019 | MEGASTAR, S.L.MEGASTAR, S.L. was fined by the AEPD EUR 2,000 for surveillance cameras that were improperly oriented and captured disproportionate images. The authority also found that the required informational signage was missing, constituting a breach of Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Oct 2020 | Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 03 May 2022 | Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined by ANSPDCP in the amount of EUR 4,000 for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 26 Jul 2012 | Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects. | IT | Garante | GDPR | €6,000 | ↗ |
| 19 Nov 2021 | MEETING PUERTO C.B.MEETING PUERTO C.B. was fined by the AEPD EUR 2,000 for unlawful processing of personal data. The breach involved posting images and comments on social media without the consent of the data subjects, contrary to Article 6(1) of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Feb 2025 | Meedea Construct Prest SRLThe company was fined for violating the principles and lawfulness of personal data processing, specifically Articles 6 and 9 of the GDPR. A corrective measure was also imposed to ensure GDPR compliance in data collection and processing and to reduce the risk of unauthorized access and disclosure. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 20 Feb 2025 | Medstar S.R.L.Medstar S.R.L. was fined by ANSPDCP for failing to notify the data breach to the supervisory authority. The company also did not inform the affected individuals about the unauthorized disclosure of their personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 24 May 2022 | MEDLIFE S.A.In April 2022, ANSPDCP completed an investigation into MEDLIFE S.A. and found a breach of GDPR provisions. As a result, a fine of EUR 5,000 was imposed. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 03 Aug 2023 | Med Life SAMed Life SA was fined EUR 2,000 by ANSPDCP. The authority found that the company violated the complainant’s right of access by refusing to provide certain video recordings from the reception area of one of its hospitals. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 08 Jan 2026 | MEDIOS DE PREVENCIÓN EXTERNOS SUR, S.L.The company suffered a ransomware attack that caused a breach of the confidentiality and availability of personal data. AEPD found a violation of Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 03 Dec 2021 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 31 May 2024 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €100,000 | ↗ |
| 12 Jun 2014 | Mediolanum Hotel s.r.l.Mediolanum Hotel s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required notice under Article 13 of the Italian Data Protection Code. The breach concerned the absence of the mandatory privacy information for job applicants. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Feb 2023 | Medijobs Platform SRLMedijobs Platform SRL was fined EUR 5,000 by ANSPDCP after unauthorized access to its IT infrastructure. The incident led to the downloading and deletion of certain personal data. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 09 May 2024 | MEDICOVER SRLMEDICOVER SRL was fined EUR 1,000 by ANSPDCP for the unauthorized disclosure of personal data from a medical consultation report to an unintended patient. The case concerns a breach of confidentiality involving special-category data and indicates a need to strengthen access controls and recipient verification procedures. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 13 Jan 2022 | Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Jul 2021 | Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls. | DK | Datatilsynet | GDPR | €53,788 | ↗ |