Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Nov 2021Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals.NLAPGDPR€400,000
31 Mar 2021Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay.NLAPGDPR€475,000
16 Jan 2024International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR.NLAPGDPR€150,000
06 Apr 2022Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications.NLAPGDPR€565,000
29 Apr 2021Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6.NLAPGDPR€600,000
22 Jul 2021TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form.NLAPGDPR€750,000
01 Nov 2018UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures.NLAPGDPR€150,000
26 Aug 2024Uber Technologies Inc.Uber Technologies Inc. was fined by the Dutch data protection authority AP in the amount of EUR 290,000,000. The authority found that the company transferred personal data to the United States without appropriate safeguards, in breach of Article 44 GDPR.NLAPGDPR€290,000,000
27 Aug 2024YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine.BEAPDGDPR€8,000
09 Jul 2020YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners.BEAPDGDPR€5,000
14 May 2020Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements.BEAPDGDPR€50,000
12 May 2026SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles.BEAPDGDPR€50,000
28 Jul 2020Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
25 Nov 2019YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
01 Sept 2020Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures.BEAPDGDPR€2,000
17 Sept 2019vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17.BEAPDGDPR€2,000
13 Nov 2020Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency.BEAPDGDPR€528,000
28 May 2019Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
23 Aug 2024Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights.BEAPDGDPR€5,000
11 May 2026Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights.BEAPDGDPR€5,000