Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 May 2019Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects.HUNAIHGDPR€91,800
24 Nov 2023Pitagorasz Oktatási Stúdió Kft.Pitagorasz Oktatási Stúdió Kft. was fined by NAIH for processing minors' personal data without a valid legal basis. The authority found breaches of GDPR principles, including accountability, purpose limitation, and transparency.HUNAIHGDPR€1,315
20 Dec 2019Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach.HUNAIHGDPR€1,515
26 Jun 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség és adattakarékosság elvének megsértéseThe controller did not comply with the data subject’s request to delete personal data, including phone numbers. The authority found unlawful processing and a breach of the principles of purpose limitation and data minimization.HUNAIHGDPR€3,090
18 Jun 2019A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD.HUNAIHGDPR€1,550
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe authority found that Mediarey Hungary Services Zrt. unlawfully processed personal data related to Forbes magazine publications. It also failed to adequately inform data subjects about their rights, resulting in breaches of several GDPR provisions.HUNAIHGDPR€5,760
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,500,000 HUF for failing to provide adequate information to data subjects about processing and their rights. The authority also found that the company did not demonstrate compelling legitimate grounds for continued processing after objections were raised.HUNAIHGDPR€7,200
02 Aug 2022BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR.HUNAIHGDPR€75,600
10 Dec 2020Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds.HUNAIHGDPR€22,480
20 Feb 2023Mindenki Magyarországa MozgalomNAIH imposed a HUF 3,000,000 fine on Mindenki Magyarországa Mozgalom and Márki-Zay Péter for GDPR violations. The authority found inadequate data processing information and failure to respect the right to object in Facebook Messenger communications.HUNAIHGDPR€7,830
09 Mar 2020Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing.HUNAIHGDPR€891
05 Feb 2026Óbudai EgyetemÓbudai Egyetem was fined by the NAIH 1,500,000 HUF for breaching the principles of transparency and data minimization. The authority also found no lawful basis for processing and that the conditions for processing special categories of data were not met.HUNAIHGDPR€3,945
09 Jul 2020Második ítélet a NAIH/2020/974 sz. ügyben (Fővárosi Törvényszék 105.K.701.565/2022/2)The controller collected personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The conduct breached multiple GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions.HUNAIHGDPR€2,820
22 Jan 2020Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000.HUNAIHGDPR€5,960
24 Aug 2023Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13.HUNAIHGDPR€2,600
18 Jun 2021Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed.HUNAIHGDPR€14,050
23 May 2019Telenor Magyarország Zrt.Telenor Magyarország Zrt. was fined by the Hungarian NAIH 300,000 HUF for failing to comply with a data subject access request under the GDPR. The authority also found that the company did not inform the data subject of the right to an effective legal remedy.HUNAIHGDPR€918
11 Jul 2022Hírlevekkel kapcsolatos adatkezelésThe entity was fined by NAIH in the amount of HUF 500,000 for processing personal data for direct marketing purposes without a legal basis. The authority also found a lack of transparent information and delayed handling of data subject requests.HUNAIHGDPR€1,225
31 May 2019Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach.HUNAIHGDPR€2,156