BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Oct 2022 | IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury. | BE | APD | ePrivacy | €10,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance. | BE | APD | GDPR | €50,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data. | BE | APD | GDPR | €250,000 | ↗ |
| 28 Apr 2026 | Fondation YThe APD Litigation Chamber fined Fondation Y EUR 1,000 for failing to respond to a data erasure request. The authority also found negligent cooperation with the data protection authority, constituting a breach of Article 31 GDPR. | BE | APD | GDPR | €1,000 | ↗ |
| 17 Dec 2024 | Geanonimiseerd (APD 166/2024)The hospital was fined by the APD for failing to carry out a data protection impact assessment and for lacking effective information security policies. These deficiencies contributed to a ransomware incident affecting up to 300,000 individuals. | BE | APD | GDPR | €50,000 | ↗ |
| 17 Sept 2019 | Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000. | BE | APD | GDPR | €10,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations. | BE | APD | GDPR | €250,000 | ↗ |
| 25 May 2022 | Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements. | BE | APD | ePrivacy | €50,000 | ↗ |
| 24 May 2022 | Geanonimiseerd (APD 84/2022)The case concerns a complaint by the Ordre des Barreaux Francophones de Belgique against sos-services.be and sos-avocats.be. The authority found that lawyers were listed without a legal basis and with incorrect information, in breach of GDPR and ePrivacy rules. | BE | APD | ePrivacy | €10,000 | ↗ |
| 29 Sept 2020 | Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation. | BE | APD | GDPR | €5,000 | ↗ |
| 06 May 2021 | YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions. | BE | APD | GDPR | €50,000 | ↗ |
| 15 Mar 2021 | Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached. | BE | APD | GDPR | €2,000 | ↗ |
| 27 Jan 2021 | De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations. | BE | APD | GDPR | €50,000 | ↗ |
| 08 Jun 2020 | de heer YThe APD Litigation Chamber fined de heer Y 5,000 EUR. It found that personal data from the municipal staff list was processed for election propaganda, breaching the GDPR principles of purpose limitation and lawfulness. | BE | APD | GDPR | €5,000 | ↗ |
| 23 Aug 2022 | Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents. | BE | APD | GDPR | €2,500 | ↗ |
| 27 Nov 2025 | Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24. | BE | APD | GDPR | €5,000 | ↗ |
| 31 Jan 2026 | SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €20,000 | ↗ |
| 01 Dec 2024 | Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 01 Aug 2025 | Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €1,000 | ↗ |
| 01 Apr 2025 | BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | — | €10,000 | ↗ |