BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 17 Dec 2024 | Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security. | FI | TSV | GDPR | €950,000 | ↗ |
| 29 Apr 2022 | TelemarkkinointiyritysA telemarketing company was fined for failing to comply with a Data Protection Ombudsman's order to provide a data subject access to a call recording. The case concerned a breach of GDPR Article 15 on the right of access. | FI | TSV | GDPR | €8,300 | ↗ |
| 23 Jul 2020 | Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed. | FI | TSV | GDPR | €7,000 | ↗ |
| 16 Dec 2021 | LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles. | FI | TSV | GDPR | €52,000 | ↗ |
| 21 Apr 2021 | ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights. | FI | TSV | GDPR | €70,000 | ↗ |
| 19 Dec 2025 | HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved. | NO | Tilsynet for universell utforming av IKT | EAA | €4,197 | ↗ |
| 28 Oct 2025 | Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication. | FI | Tietosuojavaltuutetun toimisto | GDPR | €865,000 | ↗ |
| 01 Jan 2025 | Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach. | FI | Tietosuojavaltuutetun toimisto | GDPR | €950,000 | ↗ |
| 01 Jan 2025 | Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements. | FI | Tietosuojavaltuutettu | GDPR | €2,400,000 | ↗ |
| 05 Mar 2026 | Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €6,348,000 | ↗ |
| 10 Jan 2025 | Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €215 | ↗ |
| — | DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security. | PL | Prezes Urzędu Ochrony Danych Osobowych | — | €2,568,000 | ↗ |
| 18 Dec 2024 | Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €132,000 | ↗ |
| 01 Jan 2019 | Morele.netMorele.net received an administrative fine from the President of the Personal Data Protection Office (UODO) for a GDPR violation. The 2,830,410 PLN penalty followed a phishing attack that led to unauthorized access to customer data affecting about 2.2 million people. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €658,000 | ↗ |
| 01 Nov 2025 | Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €20,110 | ↗ |
| 23 Jul 2025 | ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR. | PL | President of the Personal Data Protection Office | GDPR | €4,375,000 | ↗ |
| 23 Jun 2025 | McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures. | PL | President of the Personal Data Protection Office | GDPR | €3,960,000 | ↗ |
| 04 Apr 2025 | Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations. | PL | Polish Data Protection Authority | GDPR | €928,000 | ↗ |
| 04 Nov 2025 | McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident. | PL | Polish Data Protection Authority | GDPR | €4,022,000 | ↗ |