BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Sept 2022 | Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police. | GR | HDPA | GDPR | €3,000 | ↗ |
| 12 Jun 2015 | ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing. | GR | HDPA | GDPR | €30,000 | ↗ |
| 12 Jun 2015 | Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP. | GR | HDPA | GDPR | €30,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator. | GR | HDPA | GDPR | €40,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XThe school unlawfully forwarded personal data of 18 employees to the City of Y, breaching GDPR Articles 5 and 6. AZOP imposed a fine of EUR 2,000. | HR | AZOP | GDPR | €2,000 | ↗ |
| 14 Sept 2023 | društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach. | HR | AZOP | GDPR | €15,000 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |
| 20 Mar 2025 | FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR. | HR | AZOP | GDPR | €175,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |
| 01 Jul 2025 | Bolnica XBolnica X did not provide data subjects with the required information about data processing. The hospital also failed to implement adequate security measures and did not report the data breach to the supervisory authority and affected individuals within the required timeframe. | HR | AZOP | GDPR | €3,000 | ↗ |
| 25 Feb 2020 | Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation. | HR | AZOP | GDPR | €145,000 | ↗ |
| 27 Oct 2023 | Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents. | HR | AZOP | GDPR | €4,500,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 11 Jul 2024 | EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history. | HR | AZOP | GDPR | €5,470,000 | ↗ |
| 27 Feb 2025 | Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach. | HR | AZOP | GDPR | €25,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements. | HR | AZOP | GDPR | €2,000 | ↗ |
| 19 Feb 2026 | Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures. | HR | AZOP | GDPR | €100,000 | ↗ |
| 02 Jul 2025 | Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia. | HR | AZOP | GDPR | €101,000 | ↗ |
| 18 Aug 2023 | Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15. | HU | NAIH | GDPR | €13,050 | ↗ |
| 20 Jul 2023 | Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed. | HU | NAIH | GDPR | €5,280 | ↗ |