BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Sept 2024 | Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 May 2026 | Mediaworks Hungary Zrt.Mediaworks Hungary Zrt. was fined by NAIH 50,000,000 HUF for publishing links to a map containing personal data and special category data, including political opinions. The authority found that the processing lacked a lawful basis. | HU | NAIH | GDPR | €140,000 | ↗ |
| 06 Jul 2006 | Mediatec-Mr s.r.l.Mediatec-Mr s.r.l. was fined by the Garante for sending unsolicited promotional emails without providing the required information on data processing. The authority found a breach of the information obligation under data protection law. | IT | Garante | GDPR | €1,549 | ↗ |
| 31 Jul 2012 | MEDIASTAY SASMEDIASTAY SAS was fined 30,001 EUR by the AEPD for sending commercial emails to a user despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by NAIH 2,500,000 HUF for publishing personal data without a proper legal basis. The authority also found that the company failed to provide adequate information to the data subjects in connection with the Forbes publication. | HU | NAIH | GDPR | €7,200 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,500,000 HUF for failing to provide adequate information to data subjects about processing and their rights. The authority also found that the company did not demonstrate compelling legitimate grounds for continued processing after objections were raised. | HU | NAIH | GDPR | €7,200 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,000,000 HUF for insufficient data protection measures in its Forbes publications. The authority also found that data subjects were not adequately informed and that several GDPR provisions were breached. | HU | NAIH | GDPR | €5,760 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe authority found that Mediarey Hungary Services Zrt. unlawfully processed personal data related to Forbes magazine publications. It also failed to adequately inform data subjects about their rights, resulting in breaches of several GDPR provisions. | HU | NAIH | GDPR | €5,760 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe NAIH imposed a 2,500,000 HUF fine on Mediarey Hungary Services Zrt. for unlawful data processing related to Forbes magazine publications. The authority found that data subjects were not adequately informed and that their rights to object and erasure were not respected. | HU | NAIH | GDPR | €7,200 | ↗ |
| 01 Jan 2016 | MEDIA MOTIVE, S.L.MEDIA MOTIVE, S.L. was fined by the AEPD EUR 1,400 for sending unsolicited commercial SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 16 Apr 2015 | Media Lab Italia s.r.l.Media Lab Italia s.r.l. was fined by the Garante EUR 10,000 for processing personal data through a website form without obtaining separate consent for different purposes. The purposes included promotional communications and market research. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Feb 2026 | MediaLab.AI, Inc.The ICO imposed a 247,590 GBP penalty on MediaLab.AI, Inc. for breaches of Articles 5(1)(a), 6, 8 and 35 UK GDPR. The company operated Imgur in the UK and allowed children under 13 to access the platform without a reliable way to verify age or obtain the required parental consent. It also failed to carry out a DPIA before high-risk processing involving children under 18. | GB | ICO | GDPR | €287,000 | ↗ |
| 21 Dec 2023 | MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jul 2025 | MEDIADENTMEDIADENT was fined for failing to cooperate with the supervisory authority. The case concerned Article 31 GDPR, which requires controllers and processors to cooperate with the authority during its work. | GR | HDPA | GDPR | €2,000 | ↗ |
| 11 Mar 2021 | Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes. | IT | Garante | GDPR | €15,000 | ↗ |
| 22 Nov 2012 | Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 07 Jun 2021 | MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing. | SE | IMY | GDPR | €1,193,000 | ↗ |
| 30 Jul 2021 | Mederos Moviten, S.L.Mederos Moviten, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. Several unauthorized contracts were created using the complainant’s personal information, indicating unlawful use of personal data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 05 Feb 2026 | MÉDECIN (procédure simplifiée)The CNIL imposed EUR 1,000 on MÉDECIN (simplified procedure) as a liquidation of an astreinte. The case concerns compliance with a prior obligation set by the supervisory authority. | FR | CNIL | GDPR | €1,000 | ↗ |
| 03 Jul 2025 | MEDECIN (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on MEDECIN and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |