BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management. | LT | Valstybinė duomenų apsaugos inspekcija | GDPR | €2,385,000 | ↗ |
| 05 Jun 2025 | 23andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data. | GB | ICO | GDPR | €2,743,000 | ↗ |
| 24 Mar 2022 | Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy. | IT | Garante | GDPR | €2,120,000 | ↗ |
| 18 Jun 2020 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing. | ES | AEPD | GDPR | €2,100,000 | ↗ |
| 11 Apr 2019 | Vincall s.r.l.sVincall s.r.l.s was fined EUR 2,018,000 by the Garante for failing to provide required information to individuals contacted during telemarketing activities. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,018,000 | ↗ |
| 20 Jul 2023 | Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed. | HU | NAIH | GDPR | €5,280 | ↗ |
| 01 Oct 2023 | Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data. | GB | Information Commissioner's Office | GDPR | €2,313,000 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe authority found that Mediarey Hungary Services Zrt. unlawfully processed personal data related to Forbes magazine publications. It also failed to adequately inform data subjects about their rights, resulting in breaches of several GDPR provisions. | HU | NAIH | GDPR | €5,760 | ↗ |
| 22 Jan 2020 | Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000. | HU | NAIH | GDPR | €5,960 | ↗ |
| 07 Mar 2024 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 06 Aug 2020 | Hozzáférési jog, adatpontosság és átláthatóság elvének megsértéseThe decision concerned unlawful processing of personal data during debt collection and breaches of access rights and information obligations under the GDPR. Both entities involved in the case were fined for their actions. | HU | NAIH | GDPR | €5,780 | ↗ |
| 08 Apr 2025 | Adatbiztonsági problémák ügyféladatbázis adatfeldolgozó általi költöztetése soránThe authority found that Ügyfél1 failed to implement appropriate security measures when processing data during the database migration. This breach of GDPR Article 32 resulted in a fine of 2,000,000 HUF. | HU | NAIH | GDPR | €4,920 | ↗ |
| 20 Feb 2026 | Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization. | HU | NAIH | GDPR | €5,260 | ↗ |
| 22 Oct 2020 | Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access. | HU | NAIH | GDPR | €5,480 | ↗ |
| 12 Feb 2026 | Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 23 Dec 2024 | HYUNDAI MOTOR ESPAÑA S.L.U.HYUNDAI MOTOR ESPAÑA S.L.U. was fined EUR 2,000,000 by the AEPD for a data security incident. Unauthorized access to customer data occurred, breaching data protection principles. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,000,000 HUF for insufficient data protection measures in its Forbes publications. The authority also found that data subjects were not adequately informed and that several GDPR provisions were breached. | HU | NAIH | GDPR | €5,760 | ↗ |
| 24 Jan 2022 | Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff. | NO | Datatilsynet | GDPR | €196,000 | ↗ |
| 06 Oct 2022 | Alpha Exploration Co. Inc.Alpha Exploration Co. Inc. was fined by the Garante EUR 2,000,000 for violations related to data processing practices on its social media platform, Clubhouse. The case concerned irregularities in the way user data was processed. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 05 Jul 2022 | Üzleti titokra való hivatkozással hanganyag korlátozott felhasználhatósággal történő rendelkezésre bocsátásaThe authority fined the controller for failing to properly handle a data subject request. The case concerned a breach of the obligations under Article 12 GDPR. | HU | NAIH | GDPR | €4,900 | ↗ |