Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 May 2013HU YonghuHU Yonghu was fined EUR 6,000 by the Garante for failing to provide the required privacy notice for the restaurant surveillance system. The case concerned non-compliance with the Italian Data Protection Code.ITGaranteGDPR€6,000
12 May 2022Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
16 Jan 2014Hu ShaozengHu Shaozeng was fined EUR 2,400 by the Garante. The breach concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system in a commercial establishment.ITGaranteGDPR€2,400
15 Jun 2021Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance.ISPersónuverndGDPR€33,950
03 Feb 2011HUNTER & GATTI, S.L.HUNTER & GATTI, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
27 Apr 2020Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34.HUNAIHGDPR€21,150
08 Aug 2014Hummingbird EPEHummingbird EPE was fined by the HDPA for processing publicly available personal data without the consent of the data subjects. The authority found a breach of the principles of data relevance and proportionality.GRHDPAGDPR€7,500
12 Oct 2017Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period.ITGaranteGDPR€14,400
30 Jan 2024HUELLAS AVENTURA, S.L.The company was fined by the AEPD for tying consent for a school trip service to acceptance of data protection policies and commercial communications. The authority also found that users were not given an option to object to the processing of minors' images.ESAEPDGDPR€10,000
05 Aug 2021HUBSIDE IBÉRICA S.L.HUBSIDE IBÉRICA S.L. was fined by the AEPD for charging a customer for services that were not contracted. Personal and bank account data were collected during a purchase, and the penalty was reduced due to early payment.ESAEPDGDPR€5,000
05 Sept 2013Huawei Technologies Italia S.r.lHuawei Technologies Italia S.r.l was fined EUR 30,000 by the Garante for breaching data protection rules. The company retained surveillance footage for 18 days, exceeding the permitted retention period.ITGaranteGDPR€30,000
17 Jul 2023HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD EUR 4,000 for failing to provide information about personal data processing when a customer brought in a TV for repair. The authority also found that the company’s website lacked the required data protection information.ESAEPDGDPR€4,000
28 Oct 2024HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD for failing to comply with data protection rules. The authority cited non-compliance with measures required under Article 58(2) GDPR.ESAEPDGDPR€15,000
18 Aug 2020HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected.IEDPCGDPR€65,000
02 Jul 2025Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia.HRAZOPGDPR€101,000
19 Feb 2026Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures.HRAZOPGDPR€100,000
26 Jun 2023Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR.HUNAIHGDPR€1,355
21 Jul 2023Hozzáférési kérelem nemteljesítéseThe controller did not respond to the access request within the one-month deadline. It also failed to provide substantive information about the processing of personal data, in breach of GDPR Articles 12 and 15.HUNAIHGDPR€26,300
20 Jul 2023Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed.HUNAIHGDPR€5,280
20 Dec 2019Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach.HUNAIHGDPR€1,515