BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Nov 2024 | NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests. | NL | Autoriteit Persoonsgegevens | GDPR | €4,750,000 | ↗ |
| 25 Mar 2021 | Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance. | IT | Garante | GDPR | €4,501,000 | ↗ |
| 05 Feb 2025 | FacharztThis case concerns a confirmed fine by the Austrian Federal Administrative Court (BVwG) against Facharzt for disclosing health data in an online review. The conduct indicates a breach of personal data protection rules involving medical information. | AT | Bundesverwaltungsgericht (BVwG) | GDPR | €4,500,000 | ↗ |
| 27 Oct 2023 | Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents. | HR | AZOP | GDPR | €4,500,000 | ↗ |
| 23 Jul 2025 | ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR. | PL | President of the Personal Data Protection Office | GDPR | €4,375,000 | ↗ |
| 20 Aug 2024 | Dane anonimowe (X. S.A.)The UODO imposed an administrative fine of PLN 4,053,173 on X. S.A. for breaching Article 34(1) and (2) of the GDPR. The case concerned failure to meet the obligations to notify affected individuals about a personal data breach. | PL | UODO | GDPR | €950,000 | ↗ |
| 04 Nov 2025 | McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident. | PL | Polish Data Protection Authority | GDPR | €4,022,000 | ↗ |
| 23 Aug 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for breaching data protection principles. The case involved issuing SIM card duplicates to unauthorized individuals, which compromised data integrity and confidentiality. | ES | AEPD | GDPR | €4,000,000 | ↗ |
| 02 May 2023 | KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards. | IS | Persónuvernd | GDPR | €26,720 | ↗ |
| 02 Dec 2020 | Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €389,000 | ↗ |
| 01 Jan 2024 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft. | ES | AEPD | GDPR | €4,000,000 | ↗ |
| 01 Oct 2023 | TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated. | IT | Italian Competition Authority (AGCM) | Omnibus | €4,000,000 | ↗ |
| 23 Nov 2020 | Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data. | SE | IMY | GDPR | €391,000 | ↗ |
| 17 Jan 2024 | Dane anonimowe (V. sp. z o. o. z siedzibą w S. za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 lit. b) i lit. d) i ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 3,819,960 on V. sp. z o.o. for breaches of GDPR rules on data security and confidentiality. The case concerned, among other things, data processing principles, data protection by design, and the implementation of appropriate technical and organizational measures. | PL | UODO | GDPR | €868,000 | ↗ |
| 12 Apr 2022 | Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles. | NL | AP | GDPR | €3,700,000 | ↗ |
| 02 Dec 2020 | Sahlgrenska UniversitetssjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €340,000 | ↗ |
| 30 Dec 2025 | SOCIETE DU SECTEUR TERTIAIREThe CNIL imposed an administrative fine of EUR 3,500,000 on SOCIETE DU SECTEUR TERTIAIRE. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €3,500,000 | ↗ |
| 27 Jun 2023 | A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration. | IS | Persónuvernd | GDPR | €23,520 | ↗ |
| 17 Oct 2023 | Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children. | IS | Persónuvernd | GDPR | €23,905 | ↗ |
| 24 Feb 2025 | UNICAJA BANCO, S.A.U.UNICAJA BANCO, S.A.U. was fined by the AEPD EUR 3,500,000 for inadequate security measures in its video surveillance system. The authority found a breach of data protection requirements. | ES | AEPD | GDPR | €3,500,000 | ↗ |