Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Nov 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség, adattakarékosság és átláthatóság elvének megsértéseThe supervisory authority found that the controller did not comply with requests to erase personal data and unlawfully processed phone numbers. It also identified breaches of purpose limitation, data minimization, and transparency principles.HUNAIHGDPR€4,485
15 Nov 2019Raiffeisen Bank Zrt.Raiffeisen Bank Zrt. was fined by the NAIH 25,000,000 HUF for processing personal data of non-advisory service clients without a legal basis. The authority also found that the bank failed to provide adequate information about the processing of personal data collected through MiFID questionnaires.HUNAIHGDPR€74,750
07 Jul 2023Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles.HUNAIHGDPR€2,580
31 Jul 2024Hangrögzítés telefonos ügyfélszolgálatonThe authority imposed a fine for breaching the GDPR principles of transparency and accountability. The entity did not adequately inform callers that customer service phone calls were being recorded.HUNAIHGDPR€2,530
18 Dec 2023Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles.HUNAIHGDPR€1,295
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságNAIH imposed a HUF 95,000,000 fine on ALDI Magyarország for GDPR violations linked to data processing during alcohol purchases. The authority cited improper age verification and insufficient personal data protection measures.HUNAIHGDPR€240,000
09 Jun 2022Webáruház adatkezelési tájékoztatójaThe authority found a GDPR breach because the website and online store did not provide clear and transparent information about personal data processing. A fine of 300,000 HUF was imposed.HUNAIHGDPRFt 300,000
12 Sept 2022Magyar Éremkibocsátó Kft.The Hungarian data protection authority, NAIH, imposed a fine of 30,000,000 HUF on Magyar Éremkibocsátó Kft. The authority found that personal data were processed without a proper legal basis, specific purpose, or valid consent, and that GDPR transparency and information obligations were breached.HUNAIHGDPR€75,900
09 Jul 2020dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations.HUNAIHGDPR€2,820
20 Feb 2026Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization.HUNAIHGDPR€5,260
30 Jan 2026Magyar Agrár- és Élettudományi EgyetemThe Hungarian University of Agriculture and Life Sciences was fined by the NAIH for negligent GDPR violations in its dormitory admissions data processing. The authority cited a lack of proper legal basis, insufficient prior information, and failure to apply data minimization.HUNAIHGDPR€3,945
22 Oct 2020Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access.HUNAIHGDPR€5,480
15 May 2026Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€19,460
15 Oct 2019Munkavállaló munkaeszközeinek ellenőrzéseThe controller unlawfully processed the complainant's personal data by reviewing and monitoring their email account without prior notice. This breached the principle of fair processing.HUNAIHGDPR€3,010
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe NAIH imposed a 2,500,000 HUF fine on Mediarey Hungary Services Zrt. for unlawful data processing related to Forbes magazine publications. The authority found that data subjects were not adequately informed and that their rights to object and erasure were not respected.HUNAIHGDPR€7,200
28 Feb 2019Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF.HUNAIHGDPR€3,160
09 Aug 2022Nemzeti Egészségbiztosítási AlapkezelőNemzeti Egészségbiztosítási Alapkezelő was fined by NAIH 500,000 HUF. The authority found that the organization failed to provide transparent information to data subjects and did not cooperate during the inspection, breaching GDPR transparency and accountability principles.HUNAIHGDPR€1,260
06 Oct 2023Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures.HUNAIHGDPR€194,000
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH for failing to report a data breach involving a patient's application form within 72 hours. The authority also found that the organization lacked an internal incident management policy.HUNAIHGDPR€7,600
17 Dec 2021Kormánytisztviselő jogviszonyának megszűnésével összefüggésben egészségügyi adat kezelése, és erre irányuló hozzáférés megtagadásaThe authority found that the controller unlawfully denied access to personal data and failed to provide complete information about data processed in connection with the termination of employment. This breached GDPR Articles 12, 14, and 15.HUNAIHGDPR€1,632