Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jun 2022NAVThe Norwegian DPA fined NAV 5,000,000 NOK for making CVs available on arbeidsplassen.no without a lawful basis under the GDPR. The case concerned unauthorized processing of personal data relating to job seekers and employees.NODatatilsynetGDPR€480,000
14 Jul 2022SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident.DKDatatilsynetGDPR€67,180
16 Mar 2023Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33.NODatatilsynetGDPR€218,000
26 Apr 2024Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began.DKDatatilsynetGDPR€6,705
09 Apr 2021Miljø- og Kvalitetsledelse ASMiljø- og Kvalitetsledelse AS was fined 35,000 NOK by Datatilsynet for unlawfully sending personal data from camera recordings to an employer without a legal basis. The authority cited breaches of GDPR Articles 6 and 5.NODatatilsynetGDPR€3,461
01 Dec 2021GrindrThe Norwegian DPA, Datatilsynet, fined Grindr NOK 65 million for sharing user data with third parties for marketing purposes without a legal basis. The authority found a breach of GDPR consent requirements.NODatatilsynetGDPR€6,360,000
05 May 2021Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data.NODatatilsynetGDPR€2,503,000
02 Mar 2021Anonymisert (Datatilsynet far-gebyr-for-ulovlig-videresending-av-e-post)The company was fined 250,000 NOK for forwarding an employee’s emails without a legal basis. The authority found that this breached the GDPR and the rules governing employer access to employee email accounts.NODatatilsynetGDPR€24,378
07 Jul 2021Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis.DKDatatilsynetGDPR€13,448
22 Jan 2024Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents.DKDatatilsynetGDPR€26,816
20 Jan 2026Timegrip ASTimegrip AS was fined 250,000 NOK for failing to provide employees access to their own timekeeping data after the bankruptcy of a retail chain. The authority treated the company as the data controller and found a breach of the GDPR right of access.NODatatilsynetGDPR€21,340
15 Dec 2021GrindrNorway's Datatilsynet imposed an administrative fine of NOK 65 million on Grindr on 15.12.2021. The case concerned violations of the GDPR consent requirements.NODatatilsynetGDPR€6,355,000
16 Jul 2021Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen.DKDatatilsynetGDPR€67,220
08 Dec 2022Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle.DKDatatilsynetGDPR€47,054
15 May 2020JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights.DKDatatilsynetGDPR€6,705
16 Dec 2021Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data.DKDatatilsynetGDPR€6,724
26 Jan 2021Grindr LLCThe Norwegian DPA intends to fine Grindr 100 million NOK for sharing user data with third parties without valid consent. The conduct was assessed as a breach of GDPR consent requirements.NODatatilsynetGDPR€9,627,000
01 Feb 2024Capio A/SThe Danish Data Protection Authority reported Capio A/S to the police and recommended a fine of at least DKK 1,500,000. The case concerned insufficient supervision of data processors, breaching the GDPR accountability principle.DKDatatilsynetGDPR€201,000
11 Feb 2022Etterforsker1 Gruppen ASEtterforsker1 Gruppen AS was fined NOK 50,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The assessment was carried out on behalf of a client who claimed to have a compensation claim against the complainant.NODatatilsynetGDPR€4,964
02 Mar 2026Nordic Cleaning ApSThe Danish DPA reported Klein2 ApS and Nordic Cleaning ApS to the police for failing to comply with orders to address access requests. Nordic Cleaning ApS accepted a fine notice of 60,000 DKK.DKDatatilsynetGDPR€8,031