Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jun 2020Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors.DKDatatilsynetGDPR€6,709
06 Oct 2023Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis.DKDatatilsynetGDPR€26,818
23 Apr 2024Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach.DKDatatilsynetGDPR€13,404
24 Jun 2021Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data.NODatatilsynetGDPR€49,145
24 Jan 2022Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff.NODatatilsynetGDPR€196,000
09 Jul 2021Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls.DKDatatilsynetGDPR€53,788
11 Aug 2022Lolland KommuneLolland Kommune was fined 50,000 DKK for failing to implement basic security measures. Employees were able to disable passwords on mobile devices, exposing sensitive citizen data to unauthorized access.DKDatatilsynetGDPR€6,721
04 Jun 2026ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing.NODatatilsynetGDPR€1,844,000
24 May 2022NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people.NODatatilsynetGDPR€485,000
28 Nov 2023Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data.NODatatilsynetGDPR€1,707,000
11 May 2021Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days.NODatatilsynetGDPR€124,000
12 May 2022CivilstyrelsenThe Danish DPA reported Civilstyrelsen to the police and recommended a fine for failing to implement appropriate security measures and for not reporting a data breach. The case ended with a fine notice of 100,000 DKK.DKDatatilsynetGDPR€13,439
06 May 2021Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA.NODatatilsynetGDPR€497,000
14 Aug 2024Vejen KommuneVejen Kommune was fined by Datatilsynet for insufficient security measures after stolen computers containing children's data were found to be unencrypted. The case also revealed up to 300 other unencrypted computers in the municipality.DKDatatilsynetGDPR€26,802
09 Jan 2024Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals.DKDatatilsynetGDPR€33,523
29 Oct 2024Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security.NODatatilsynetGDPR€21,113
25 Mar 2019Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000.DKDatatilsynetGDPR€33,493
16 Jun 2021Vejle KommuneVejle Kommune was fined by Datatilsynet for failing to implement appropriate security measures, which led to the unintended disclosure of personal data, including children's addresses. The authority also found no assessment of whether such disclosures were necessary.DKDatatilsynetGDPR€13,447
24 Mar 2021Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards.NODatatilsynetGDPR€4,923
11 Sept 2024Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals.NODatatilsynetGDPR€12,566