Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jul 2021Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose.FITSVGDPR€25,000
17 Dec 2024Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security.FITSVGDPR€950,000
29 Apr 2022TelemarkkinointiyritysA telemarketing company was fined for failing to comply with a Data Protection Ombudsman's order to provide a data subject access to a call recording. The case concerned a breach of GDPR Article 15 on the right of access.FITSVGDPR€8,300
23 Jul 2020Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed.FITSVGDPR€7,000
16 Dec 2021LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles.FITSVGDPR€52,000
21 Apr 2021ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights.FITSVGDPR€70,000
19 Dec 2025HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved.NOTilsynet for universell utforming av IKTEAA€4,197
28 Oct 2025Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication.FITietosuojavaltuutetun toimistoGDPR€865,000
01 Jan 2025Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach.FITietosuojavaltuutetun toimistoGDPR€950,000
01 Jan 2025Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements.FITietosuojavaltuutettuGDPR€2,400,000
05 Mar 2026Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€6,348,000
10 Jan 2025Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€215
DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych Osobowych€2,568,000
18 Dec 2024Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations.PLPresident of the Personal Data Protection Office (UODO)GDPR€132,000
01 Jan 2019Morele.netMorele.net received an administrative fine from the President of the Personal Data Protection Office (UODO) for a GDPR violation. The 2,830,410 PLN penalty followed a phishing attack that led to unauthorized access to customer data affecting about 2.2 million people.PLPresident of the Personal Data Protection Office (UODO)GDPR€658,000
01 Nov 2025Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late.PLPresident of the Personal Data Protection Office (UODO)GDPR€20,110
23 Jul 2025ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR.PLPresident of the Personal Data Protection OfficeGDPR€4,375,000
23 Jun 2025McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures.PLPresident of the Personal Data Protection OfficeGDPR€3,960,000
04 Apr 2025Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations.PLPolish Data Protection AuthorityGDPR€928,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000