BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 01 Dec 2025 | Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop. | SI | IP-RS | GDPR | €1,000 | ↗ |
| 29 Jul 2025 | Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness. | SI | IP-RS | GDPR | €10,614 | ↗ |
| 25 Jul 2025 | Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract. | SI | IP-RS | GDPR | €5,610 | ↗ |
| 13 Aug 2025 | Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR. | SI | IP-RS | GDPR | €500 | ↗ |
| 02 Feb 2022 | Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000. | LU | CNPD | GDPR | €10,000 | ↗ |
| 06 Jan 2025 | Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560. | LU | CNPD | GDPR | €493,000 | ↗ |
| 02 Feb 2022 | Anonymisé (CNPD decision-02-fr-2022)The company was fined by the CNPD 6,600 EUR for breaches of GDPR requirements. The authority found deficiencies in data minimization, retention, security of processing, and the information provided to data subjects in connection with video surveillance and geolocation systems. | LU | CNPD | GDPR | €6,600 | ↗ |
| 20 Nov 2024 | Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security. | LU | CNPD | GDPR | €14,288 | ↗ |
| 30 Apr 2025 | Anonymisé (CNPD decision-03-fr-2025)The company did not maintain a complete record of processing activities as required by Article 30 GDPR. CNPD imposed an administrative fine of €11,964. | LU | CNPD | GDPR | €11,964 | ↗ |
| 16 Feb 2022 | Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities. | LU | CNPD | GDPR | €3,100 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-04-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. CNPD treated this as a breach of documentation obligations and imposed an administrative fine. | LU | CNPD | GDPR | €2,784 | ↗ |
| 05 Jul 2023 | Anonymisé (CNPD decision-05-fr-2023)The company did not inform data subjects about the recipients of their personal data. It also failed to implement appropriate technical and organizational measures required under the GDPR, breaching Articles 13 and 24. | LU | CNPD | GDPR | €1,500 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-05-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. The record lacked or contained incomplete information on data categories and transfers to third countries. | LU | CNPD | GDPR | €7,341 | ↗ |
| 05 Jul 2023 | Anonymisé (CNPD decision-06-fr-2023)The company failed to implement appropriate technical and organizational measures to ensure data security. It also did not cooperate with the supervisory authority, breaching Articles 31 and 32 of the GDPR. | LU | CNPD | GDPR | €5,330 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-06-fr-2025)The company failed to maintain a proper record of processing activities under Article 30 GDPR. The register contained inaccuracies and omissions, indicating a breach of documentation obligations. | LU | CNPD | GDPR | €1,277 | ↗ |
| 10 Mar 2022 | Anonymisé (CNPD decision-07-fr-2022)The CNPD found that Société A breached the GDPR by failing to comply with data minimization, retention limitation, and information provision requirements. The case concerned improper personal data processing in relation to compliance obligations. | LU | CNPD | GDPR | €3,500 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-07-fr-2025)The entity did not maintain a complete and accurate record of processing activities, as required by Article 30 GDPR. CNPD imposed an administrative fine of EUR 12,010. | LU | CNPD | GDPR | €12,010 | ↗ |
| 20 Apr 2022 | Anonymisé (CNPD decision-09-fr-2022)The CNPD fined the company EUR 2,000 for failing to respond in time to a data subject access request and for not providing all required information under GDPR Articles 12 and 15. The company also failed to cooperate with the supervisory authority, contrary to Article 31 GDPR. | LU | CNPD | GDPR | €2,000 | ↗ |
| 22 Apr 2022 | Anonymisé (CNPD decision-10-fr-2022)The public transport organization breached GDPR requirements on storage limitation, data minimization, and providing adequate information to data subjects. CNPD imposed a fine of EUR 4,000. | LU | CNPD | GDPR | €4,000 | ↗ |