Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Dec 2021Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws.NLAPGDPR€2,750,000
17 Oct 2025Experian Nederland B.V.Experian Nederland B.V. was fined by the AP €2,700,000 for failing to adequately inform data subjects and for processing personal data without a valid legal basis. The case concerns breaches of the GDPR principles of transparency and lawful processing.NLAPGDPR€2,700,000
01 Oct 2023ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company.NLAutoriteit PersoonsgegevensGDPR€2,700,000
22 Oct 2025SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states.ESAEPDGDPR€2,600,000
10 Jun 2021Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention.ITGaranteGDPR€2,600,000
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by NAIH 2,500,000 HUF for publishing personal data without a proper legal basis. The authority also found that the company failed to provide adequate information to the data subjects in connection with the Forbes publication.HUNAIHGDPR€7,200
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,500,000 HUF for failing to provide adequate information to data subjects about processing and their rights. The authority also found that the company did not demonstrate compelling legitimate grounds for continued processing after objections were raised.HUNAIHGDPR€7,200
06 Dec 2023ReykjanesbærReykjanesbær was fined by Persónuvernd 2,500,000 ISK for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited the failure to carry out timely data protection impact assessments and to define processing purposes clearly.ISPersónuverndGDPR€16,650
16 Mar 2023Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33.NODatatilsynetGDPR€218,000
10 Feb 2021Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act.SEIMYePrivacy€248,000
06 Aug 2025SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data.ESAEPDGDPR€2,500,000
02 Dec 2020Region ÖstergötlandRegion Östergötland was fined by IMY for failing to perform a needs and risk analysis before granting access rights in its journal system. The authority found that this breached several GDPR provisions.SEIMYGDPR€243,000
19 Mar 2026GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis.ISPersónuverndGDPR€17,425
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe NAIH imposed a 2,500,000 HUF fine on Mediarey Hungary Services Zrt. for unlawful data processing related to Forbes magazine publications. The authority found that data subjects were not adequately informed and that their rights to object and erasure were not respected.HUNAIHGDPR€7,200
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH for failing to report a data breach involving a patient's application form within 72 hours. The authority also found that the organization lacked an internal incident management policy.HUNAIHGDPR€7,600
24 Oct 2019Magyar Honvédség Egészségügyi KözpontThe Hungarian Defence Forces Health Centre did not report a data breach within 72 hours and lacked internal incident management procedures. NAIH found this to be a breach of GDPR obligations and imposed a fine of 2,500,000 HUF.HUNAIHGDPR€7,600
03 Jul 2023ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,500,000
02 Dec 2020Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€243,000
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register.HUNAIHGDPR€7,600
01 Jan 2025Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements.FITietosuojavaltuutettuGDPR€2,400,000