BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Jun 2020 | Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors. | DK | Datatilsynet | GDPR | €6,709 | ↗ |
| 06 Oct 2023 | Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis. | DK | Datatilsynet | GDPR | €26,818 | ↗ |
| 23 Apr 2024 | Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach. | DK | Datatilsynet | GDPR | €13,404 | ↗ |
| 24 Jun 2021 | Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data. | NO | Datatilsynet | GDPR | €49,145 | ↗ |
| 24 Jan 2022 | Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff. | NO | Datatilsynet | GDPR | €196,000 | ↗ |
| 09 Jul 2021 | Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls. | DK | Datatilsynet | GDPR | €53,788 | ↗ |
| 11 Aug 2022 | Lolland KommuneLolland Kommune was fined 50,000 DKK for failing to implement basic security measures. Employees were able to disable passwords on mobile devices, exposing sensitive citizen data to unauthorized access. | DK | Datatilsynet | GDPR | €6,721 | ↗ |
| 04 Jun 2026 | ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing. | NO | Datatilsynet | GDPR | €1,844,000 | ↗ |
| 24 May 2022 | NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people. | NO | Datatilsynet | GDPR | €485,000 | ↗ |
| 28 Nov 2023 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data. | NO | Datatilsynet | GDPR | €1,707,000 | ↗ |
| 11 May 2021 | Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days. | NO | Datatilsynet | GDPR | €124,000 | ↗ |
| 12 May 2022 | CivilstyrelsenThe Danish DPA reported Civilstyrelsen to the police and recommended a fine for failing to implement appropriate security measures and for not reporting a data breach. The case ended with a fine notice of 100,000 DKK. | DK | Datatilsynet | GDPR | €13,439 | ↗ |
| 06 May 2021 | Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA. | NO | Datatilsynet | GDPR | €497,000 | ↗ |
| 14 Aug 2024 | Vejen KommuneVejen Kommune was fined by Datatilsynet for insufficient security measures after stolen computers containing children's data were found to be unencrypted. The case also revealed up to 300 other unencrypted computers in the municipality. | DK | Datatilsynet | GDPR | €26,802 | ↗ |
| 09 Jan 2024 | Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals. | DK | Datatilsynet | GDPR | €33,523 | ↗ |
| 29 Oct 2024 | Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security. | NO | Datatilsynet | GDPR | €21,113 | ↗ |
| 25 Mar 2019 | Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000. | DK | Datatilsynet | GDPR | €33,493 | ↗ |
| 16 Jun 2021 | Vejle KommuneVejle Kommune was fined by Datatilsynet for failing to implement appropriate security measures, which led to the unintended disclosure of personal data, including children's addresses. The authority also found no assessment of whether such disclosures were necessary. | DK | Datatilsynet | GDPR | €13,447 | ↗ |
| 24 Mar 2021 | Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards. | NO | Datatilsynet | GDPR | €4,923 | ↗ |
| 11 Sept 2024 | Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals. | NO | Datatilsynet | GDPR | €12,566 | ↗ |