BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Dec 2020 | ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident. | HU | NAIH | GDPR | €56,000 | ↗ |
| 09 Dec 2020 | Twitter International CompanyThe Irish DPC imposed a fine of EUR 450,000 on Twitter International Company in inquiry IN-19-1-1. The fine was collected. | IE | DPC | GDPR | €450,000 | ↗ |
| 09 Dec 2020 | DKN.5131.5.2020StatusprawomocnaTytuA monetary penalty was imposed for failing to report a personal data breach to the President of UODO and for failing to notify the affected individuals. The case concerns non-compliance with breach notification obligations after a data security incident. | PL | UODO | GDPR | €19,344 | ↗ |
| 10 Dec 2020 | Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing. | HU | NAIH | GDPR | €22,480 | ↗ |
| 10 Dec 2020 | Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds. | HU | NAIH | GDPR | €22,480 | ↗ |
| 10 Dec 2020 | Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements. | SE | IMY | GDPR | €53,713 | ↗ |
| 14 Dec 2020 | Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f). | SE | IMY | GDPR | €29,433 | ↗ |
| 16 Dec 2020 | [...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group. | HU | NAIH | GDPR | €1,012 | ↗ |
| 16 Dec 2020 | Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles. | HU | NAIH | GDPR | €98,350 | ↗ |
| 17 Dec 2020 | Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data. | PL | UODO | GDPR | €240,000 | ↗ |
| 17 Dec 2020 | University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected. | IE | DPC | GDPR | €70,000 | ↗ |
| 17 Dec 2020 | Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users. | IT | Garante | GDPR | €500,000 | ↗ |
| 17 Dec 2020 | Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Dec 2020 | Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 17 Dec 2020 | Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Dec 2020 | Ordine degli Assistenti Sociali della Regione LazioOrdine degli Assistenti Sociali della Regione Lazio was fined EUR 2,000 by the Garante. The authority found that the entity failed to respond to a request for access to personal data, which is a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Dec 2020 | LABORATORIO OCTOGÓN, S.L.LABORATORIO OCTOGÓN, S.L. was fined by the AEPD €1,000 for improperly positioning a surveillance camera. The camera captured third-party areas without justification, which breached data protection principles. | ES | AEPD | GDPR | €1,000 | ↗ |
| 17 Dec 2020 | Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Dec 2020 | Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR. | CZ | UOOU | GDPR | €1,141 | ↗ |
| 23 Dec 2020 | Anonymizováno (ÚOOÚ UOOU-02528/20-14)The entity was fined by the UOOU for breaching a legal prohibition on disclosing personal data under another regulation. The case concerned information about criminal proceedings and the persons involved. | CZ | UOOU | GDPR | €38 | ↗ |