BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2021 | Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals. | NL | AP | GDPR | €400,000 | ↗ |
| 31 Mar 2021 | Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay. | NL | AP | GDPR | €475,000 | ↗ |
| 16 Jan 2024 | International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR. | NL | AP | GDPR | €150,000 | ↗ |
| 06 Apr 2022 | Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications. | NL | AP | GDPR | €565,000 | ↗ |
| 29 Apr 2021 | Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 22 Jul 2021 | TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form. | NL | AP | GDPR | €750,000 | ↗ |
| 01 Nov 2018 | UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures. | NL | AP | GDPR | €150,000 | ↗ |
| 26 Aug 2024 | Uber Technologies Inc.Uber Technologies Inc. was fined by the Dutch data protection authority AP in the amount of EUR 290,000,000. The authority found that the company transferred personal data to the United States without appropriate safeguards, in breach of Article 44 GDPR. | NL | AP | GDPR | €290,000,000 | ↗ |
| 27 Aug 2024 | YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine. | BE | APD | GDPR | €8,000 | ↗ |
| 09 Jul 2020 | YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners. | BE | APD | GDPR | €5,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements. | BE | APD | GDPR | €50,000 | ↗ |
| 12 May 2026 | SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles. | BE | APD | GDPR | €50,000 | ↗ |
| 28 Jul 2020 | Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness. | BE | APD | GDPR | €5,000 | ↗ |
| 25 Nov 2019 | YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle. | BE | APD | GDPR | €2,000 | ↗ |
| 01 Sept 2020 | Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures. | BE | APD | GDPR | €2,000 | ↗ |
| 17 Sept 2019 | vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17. | BE | APD | GDPR | €2,000 | ↗ |
| 13 Nov 2020 | Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency. | BE | APD | GDPR | €528,000 | ↗ |
| 28 May 2019 | Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle. | BE | APD | GDPR | €2,000 | ↗ |
| 23 Aug 2024 | Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights. | BE | APD | GDPR | €5,000 | ↗ |
| 11 May 2026 | Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights. | BE | APD | GDPR | €5,000 | ↗ |