BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jul 2024 | Hangrögzítés telefonos ügyfélszolgálatonThe authority imposed a fine for breaching the GDPR principles of transparency and accountability. The entity did not adequately inform callers that customer service phone calls were being recorded. | HU | NAIH | GDPR | €2,530 | ↗ |
| 08 Aug 2022 | Hangfelvétel készítése szerelési munkák soránThe authority found that the entity breached the GDPR by recording audio during installation work without a proper legal basis. It also failed to meet transparency and data protection principle requirements. | HU | NAIH | GDPR | €762 | ↗ |
| 12 Mar 2026 | Hanako s.r.l.Hanako s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without ensuring GDPR compliance. The authority cited inadequate security measures and failure to provide sufficient information to employees. | IT | Garante | GDPR | €2,000 | ↗ |
| 01 Jul 2025 | HAMMERHOJ DESIGN, S.L.HAMMERHOJ DESIGN, S.L. was fined EUR 4,000 by the AEPD for publishing images of minors on Facebook without consent. The authority found this conduct to be in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 07 Jun 2021 | Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations. | SE | IMY | GDPR | €49,725 | ↗ |
| 11 May 2020 | Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32. | SE | IMY | GDPR | €11,321 | ↗ |
| 17 Jan 2023 | Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR. | SE | IMY | GDPR | kr 200,000 | ↗ |
| 19 Mar 2026 | HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments. | IS | Persónuvernd | GDPR | €19,516 | ↗ |
| 26 Oct 2011 | H3G S.p.A.H3G S.p.A. was fined EUR 120,000 by the Garante for sending unsolicited promotional communications to a fixed telephone line. The conduct breached data protection provisions. | IT | Garante | GDPR | €120,000 | ↗ |
| 12 Jun 2014 | H3g s.p.a.H3g s.p.a. was fined EUR 75,000 by the Garante for violations related to customer profiling without the required consent. The case concerned personal data processing that did not comply with data protection requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 20 Aug 2019 | Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data. | SE | IMY | GDPR | €18,578 | ↗ |
| 22 Jun 2022 | Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles. | DK | Datatilsynet | GDPR | €134,000 | ↗ |
| 29 Nov 2012 | G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Sept 2025 | G.Villa S.r.l.G.Villa S.r.l. was fined by the Garante EUR 22,500 for sending unsolicited promotional emails to an address not disclosed for marketing purposes. The company also failed to respond to the data subject's request for access to and deletion of personal data. | IT | Garante | GDPR | €22,500 | ↗ |
| 21 Sept 2022 | GUUDJOB WORLDWIDE S.L.GUUDJOB WORLDWIDE S.L. failed to delete personal data after a data subject request, breaching GDPR Articles 12 and 17. The AEPD imposed a fine of EUR 1,000, reduced to EUR 800 for early payment. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Apr 2013 | Gustavo CapizziGustavo Capizzi was fined €6,000 by the Garante for failing to provide the required data protection notice. The breach concerned a video surveillance system at the association “La Petit Nuit”. | IT | Garante | GDPR | €6,000 | ↗ |
| 30 Jan 2025 | Guru Nanak s.r.l.s.Guru Nanak s.r.l.s. was fined by the Garante EUR 1,000 for the non-compliant installation of a video surveillance system. The cameras captured areas beyond the company’s premises, creating a privacy and data protection breach. | IT | Garante | GDPR | €1,000 | ↗ |
| 09 Dec 2020 | Guldborgsund KommuneGuldborgsund Kommune was fined 50,000 DKK by Datatilsynet for a data breach. Sensitive information was mistakenly sent to an unauthorized recipient, causing significant consequences for the affected individuals. | DK | Datatilsynet | GDPR | €6,718 | ↗ |
| 02 Jul 2020 | GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 May 2008 | G. & T. Design Comunication s.r.l.G. & T. Design Comunication s.r.l. was fined €4,000 by the Garante for failing to provide the requested information on the acquisition and processing of an email address. The authority treated this as a breach of data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |