BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Aug 2021 | MOVE IrelandThe Irish DPC fined MOVE Ireland EUR 1,500 in case IN-20-7-1. The fine has been collected. | IE | DPC | GDPR | €1,500 | ↗ |
| 26 Jan 2022 | Slane Credit UnionThe Irish DPC imposed a fine of EUR 5,000 on Slane Credit Union in inquiry IN-19-7-5. The penalty has been collected. | IE | DPC | GDPR | €5,000 | ↗ |
| 23 Mar 2021 | Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected. | IE | DPC | GDPR | €90,000 | ↗ |
| 10 Dec 2025 | University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed. | IE | DPC | GDPR | €98,000 | ↗ |
| 09 Dec 2021 | Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected. | IE | DPC | GDPR | €110,000 | ↗ |
| 20 Dec 2022 | Virtue Integrated Elder Care LtdThe Irish DPC imposed a fine of EUR 100,000 on Virtue Integrated Elder Care Ltd in inquiry IN-21-2-5. The penalty has been collected. | IE | DPC | GDPR | €100,000 | ↗ |
| 28 Oct 2025 | SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision. | LV | Datu valsts inspekcija | GDPR | €300,000 | ↗ |
| 02 Jan 2023 | Dulnevnd fyritøka (Dátueftirlitið)DATFO referred a company to the police for suspected breaches of data protection law. The company collected and stored personal data without a valid legal basis and without providing adequate information to the data subjects. Its website contact mechanism also caused data intended for a specific provider to be collected and retained by the company. | FO | DATFO | GDPR | €13,446 | ↗ |
| 14 Jan 2021 | Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles. | NO | Datatilsynet | GDPR | €38,796 | ↗ |
| 27 Nov 2024 | Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended. | DK | Datatilsynet | GDPR | €53,632 | ↗ |
| — | Timegrip ASDatatilsynet imposed an administrative fine of NOK 250,000 on Timegrip AS for denying employees access to their personal data relating to time tracking. The authority found that Timegrip effectively acted as the controller and had no valid basis to refuse the access requests. | NO | Datatilsynet | — | €22,435 | ↗ |
| 08 Feb 2023 | SatsThe Norwegian DPA, Datatilsynet, fined Sats 10,000,000 NOK for breaches of GDPR requirements. The case concerned data subjects' rights to information, access, and erasure, as well as the lack of a legal basis for processing certain personal data. | NO | Datatilsynet | GDPR | €906,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 25 Mar 2021 | Dragefossen ASDragefossen AS was fined 150,000 NOK by Datatilsynet for unlawfully live streaming surveillance footage from a camera in Rognan sentrum on the internet. The authority found no legal basis for the processing, which breached GDPR Articles 6 and 5. | NO | Datatilsynet | GDPR | €14,756 | ↗ |
| 11 Jun 2021 | BRAbank ASABRAbank ASA was fined NOK 400,000 by Datatilsynet for failing to perform risk assessments and testing before launching a customer portal. The deficiency led to a data breach in which customers could view other customers’ loan information. | NO | Datatilsynet | GDPR | €39,672 | ↗ |
| 17 Aug 2021 | UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers. | DK | Datatilsynet | GDPR | €20,171 | ↗ |
| 03 Feb 2021 | Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion. | NO | Datatilsynet | GDPR | €19,316 | ↗ |
| 08 Sept 2021 | Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center. | DK | Datatilsynet | GDPR | €40,344 | ↗ |
| 07 Jan 2022 | Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check. | NO | Datatilsynet | GDPR | €19,942 | ↗ |