Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Mar 2026ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards.ISPersónuverndGDPR€13,940
21 Feb 2025Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches.ATÖsterreichische DatenschutzbehördeGDPR€16,000,000
10 Sept 2025S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach.FIOffice of the Data Protection OmbudsmanGDPR€1,800,000
04 Jun 2025Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta.FIOffice of the Data Protection OmbudsmanGDPR€1,100,000
25 Sept 2025JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes.GGODPAGDPR€74,302
20 Oct 2025The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data.GGODPAGDPR€115,000
15 May 2026Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€19,460
16 Apr 2026An unnamed energy companyHungary’s data protection authority, NAIH, imposed a HUF 75 million GDPR fine in case NAIH-19-18/2024 on an unnamed energy company. The case concerned data processing for a nationwide LED replacement program and identified serious privacy compliance failures.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€205,000
11 Feb 2025A követeléskezelő társaságNAIH imposed a HUF 10 million fine on a debt collection company for continuing to process personal data after a court declared the debt time-barred. The company ignored the data subject’s deletion request and kept the case active in its system.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€24,800
01 Jan 2024Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€130,000
18 Aug 2023Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15.HUNAIHGDPR€13,050
20 Jul 2023Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed.HUNAIHGDPR€5,280
08 Jun 2020Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request.HUNAIHGDPR€582
22 Mar 2021Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine.HUNAIHGDPR€1,365
19 Apr 2021BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection.HUNAIHGDPR€13,900
25 Mar 2021Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing.HUNAIHGDPR€1,370
08 Aug 2022Hangfelvétel készítése szerelési munkák soránThe authority found that the entity breached the GDPR by recording audio during installation work without a proper legal basis. It also failed to meet transparency and data protection principle requirements.HUNAIHGDPR€762
10 Dec 2020Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing.HUNAIHGDPR€22,480
30 Sept 2020Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis.HUNAIHGDPR€2,740
27 Apr 2021Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles.HUNAIHGDPR€1,380