BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 May 2013 | HU YonghuHU Yonghu was fined EUR 6,000 by the Garante for failing to provide the required privacy notice for the restaurant surveillance system. The case concerned non-compliance with the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 May 2022 | Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Jan 2014 | Hu ShaozengHu Shaozeng was fined EUR 2,400 by the Garante. The breach concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system in a commercial establishment. | IT | Garante | GDPR | €2,400 | ↗ |
| 15 Jun 2021 | Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance. | IS | Persónuvernd | GDPR | €33,950 | ↗ |
| 03 Feb 2011 | HUNTER & GATTI, S.L.HUNTER & GATTI, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 27 Apr 2020 | Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34. | HU | NAIH | GDPR | €21,150 | ↗ |
| 08 Aug 2014 | Hummingbird EPEHummingbird EPE was fined by the HDPA for processing publicly available personal data without the consent of the data subjects. The authority found a breach of the principles of data relevance and proportionality. | GR | HDPA | GDPR | €7,500 | ↗ |
| 12 Oct 2017 | Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period. | IT | Garante | GDPR | €14,400 | ↗ |
| 30 Jan 2024 | HUELLAS AVENTURA, S.L.The company was fined by the AEPD for tying consent for a school trip service to acceptance of data protection policies and commercial communications. The authority also found that users were not given an option to object to the processing of minors' images. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Aug 2021 | HUBSIDE IBÉRICA S.L.HUBSIDE IBÉRICA S.L. was fined by the AEPD for charging a customer for services that were not contracted. Personal and bank account data were collected during a purchase, and the penalty was reduced due to early payment. | ES | AEPD | GDPR | €5,000 | ↗ |
| 05 Sept 2013 | Huawei Technologies Italia S.r.lHuawei Technologies Italia S.r.l was fined EUR 30,000 by the Garante for breaching data protection rules. The company retained surveillance footage for 18 days, exceeding the permitted retention period. | IT | Garante | GDPR | €30,000 | ↗ |
| 17 Jul 2023 | HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD EUR 4,000 for failing to provide information about personal data processing when a customer brought in a TV for repair. The authority also found that the company’s website lacked the required data protection information. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Oct 2024 | HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD for failing to comply with data protection rules. The authority cited non-compliance with measures required under Article 58(2) GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 18 Aug 2020 | HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected. | IE | DPC | GDPR | €65,000 | ↗ |
| 02 Jul 2025 | Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia. | HR | AZOP | GDPR | €101,000 | ↗ |
| 19 Feb 2026 | Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures. | HR | AZOP | GDPR | €100,000 | ↗ |
| 26 Jun 2023 | Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR. | HU | NAIH | GDPR | €1,355 | ↗ |
| 21 Jul 2023 | Hozzáférési kérelem nemteljesítéseThe controller did not respond to the access request within the one-month deadline. It also failed to provide substantive information about the processing of personal data, in breach of GDPR Articles 12 and 15. | HU | NAIH | GDPR | €26,300 | ↗ |
| 20 Jul 2023 | Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed. | HU | NAIH | GDPR | €5,280 | ↗ |
| 20 Dec 2019 | Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach. | HU | NAIH | GDPR | €1,515 | ↗ |