BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Oct 2021 | AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards. | ES | AEPD | GDPR | €3,300,000 | ↗ |
| 12 May 2021 | E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use. | ES | AEPD | GDPR | €3,100,000 | ↗ |
| 26 Mar 2025 | Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services. | GB | Information Commissioner's Office | GDPR | €3,678,000 | ↗ |
| 26 Mar 2025 | Advanced Computer Software Group LimitedThe UK Information Commissioner’s Office (ICO) fined Advanced Computer Software Group Limited £3,070,000 for security failings. The issues put the personal information of 79,404 people at risk. The case highlights inadequate safeguards over processed personal data. | GB | ICO | GDPR | €3,671,000 | ↗ |
| 05 Mar 2020 | S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate. | IS | Persónuvernd | GDPR | €21,090 | ↗ |
| 22 Apr 2022 | Magyar Kétfarkú Kutya PártThe Hungarian party Magyar Kétfarkú Kutya Párt was fined by NAIH for failing to implement adequate security measures when storing supporter and activist data. The authority found breaches of GDPR Articles 32 and 5. | HU | NAIH | GDPR | €8,100 | ↗ |
| 20 Feb 2023 | Mindenki Magyarországa MozgalomNAIH imposed a HUF 3,000,000 fine on Mindenki Magyarországa Mozgalom and Márki-Zay Péter for GDPR violations. The authority found inadequate data processing information and failure to respect the right to object in Facebook Messenger communications. | HU | NAIH | GDPR | €7,830 | ↗ |
| 29 Dec 2022 | SOCIETE DE DEVELOPPEMENT DE JEUX MOBILESCNIL imposed a fine of 3,000,000 EUR on SOCIETE DE DEVELOPPEMENT DE JEUX MOBILES. The decision concerns a breach of rules examined by the supervisory authority. | FR | CNIL | GDPR | €3,000,000 | ↗ |
| 17 Jul 2019 | Bírák érdek-képviseleti egyesületi tagságra vonatkozó adatának jogellenes kezeléseBudapest Környéki Törvényszék unlawfully processed personal data by listing and sharing association membership information without a proper purpose or legal basis. The authority found a breach of the GDPR principles of purpose limitation and lawful processing. | HU | NAIH | GDPR | €9,180 | ↗ |
| 26 Jan 2024 | Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people. | EE | Andmekaitse Inspektsioon | GDPR | €3,000,000 | ↗ |
| 10 Apr 2025 | Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents. | IT | Garante | GDPR | €3,000,000 | ↗ |
| 19 Mar 2026 | KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes. | IS | Persónuvernd | GDPR | €20,910 | ↗ |
| 21 Dec 2022 | Szálláshelyen kamerás megfigyelőrendszer üzemeltetéseThe authority found that the controller unlawfully processed personal data through a camera system, breaching several GDPR provisions. The decision highlighted improper data storage and a lack of transparent information provided to data subjects. | HU | NAIH | GDPR | €7,440 | ↗ |
| 02 Mar 2022 | Közös Nevező 2018 párt és dr. Gődény György aláírásgyűjtéshez kapcsolódó adatkezelésének jogszerűségeThe NAIH imposed a HUF 3,000,000 fine on entities involved in a signature campaign against mandatory vaccinations. The authority found that personal data were collected without meeting GDPR requirements on lawfulness, purpose limitation, transparency, and information provision. | HU | NAIH | GDPR | €7,860 | ↗ |
| 25 Apr 2022 | Budapest Főváros XVIII. kerület Pestszentlőrinc - Pestszentimre ÖnkormányzataThe authority fined the municipality for failing to provide adequate information to data subjects about the collection and use of their personal data. It also found processing of personal and health data without a valid legal basis or proper consent. | HU | NAIH | GDPR | €8,010 | ↗ |
| 28 Feb 2024 | Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach. | GR | HDPA | GDPR | €2,995,000 | ↗ |
| 13 May 2021 | Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register. | IT | Garante | GDPR | €2,856,000 | ↗ |
| 10 Sept 2019 | Dane anonimowe (V. Sp. z o.o. z siedzibą w S. przy ul.)UODO found that V. Sp. z o.o. breached rules on the security and confidentiality of processed personal data. A fine of PLN 2,830,410 was imposed. | PL | UODO | GDPR | €653,000 | ↗ |
| 01 Jan 2019 | Morele.netMorele.net received an administrative fine from the President of the Personal Data Protection Office (UODO) for a GDPR violation. The 2,830,410 PLN penalty followed a phishing attack that led to unauthorized access to customer data affecting about 2.2 million people. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €658,000 | ↗ |
| 19 Mar 2026 | HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments. | IS | Persónuvernd | GDPR | €19,516 | ↗ |