BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Oct 2024 | Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security. | NO | Datatilsynet | GDPR | €21,113 | ↗ |
| 25 Mar 2019 | Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000. | DK | Datatilsynet | GDPR | €33,493 | ↗ |
| 16 Jun 2021 | Vejle KommuneVejle Kommune was fined by Datatilsynet for failing to implement appropriate security measures, which led to the unintended disclosure of personal data, including children's addresses. The authority also found no assessment of whether such disclosures were necessary. | DK | Datatilsynet | GDPR | €13,447 | ↗ |
| 24 Mar 2021 | Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards. | NO | Datatilsynet | GDPR | €4,923 | ↗ |
| 11 Sept 2024 | Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals. | NO | Datatilsynet | GDPR | €12,566 | ↗ |
| 12 Nov 2024 | Uptime-IT ApSUptime-IT ApS was fined by Datatilsynet 40,000 DKK for failing to implement adequate security measures as a data processor. This led to a ransomware attack that encrypted sensitive personal data, including health information and CPR numbers, which could not be restored. | DK | Datatilsynet | GDPR | €5,362 | ↗ |
| 16 Sept 2021 | Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32. | DK | Datatilsynet | GDPR | €10,086 | ↗ |
| 22 Jun 2021 | VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections. | NO | Datatilsynet | GDPR | €14,678 | ↗ |
| 04 Aug 2020 | PrivatBo A.M.B.A. af 1993PrivatBo was reported to the police, and Datatilsynet recommended a fine of 150,000 DKK for inadequate data security measures. The incident led to the unintended disclosure of tenants' confidential information on USB drives. | DK | Datatilsynet | GDPR | €20,145 | ↗ |
| 11 Sept 2025 | ILVA A/SVestre Landsret upheld a DKK 1.5 million GDPR fine against ILVA A/S. The case concerned retention of data on about 385,000 customers without a deletion policy, and the fine was based on the group’s total turnover. | DK | Datatilsynet | GDPR | €200,000 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025. | IE | Data Protection Commission (Ireland) | GDPR | €125,000 | ↗ |
| 08 May 2026 | Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers. | IE | Data Protection Commission | GDPR | €277,000 | ↗ |
| 12 Sept 2019 | Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 10 Mar 2025 | Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 21 Sept 2022 | Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32. | CY | CyDPC | GDPR | €5,000 | ↗ |
| 31 Mar 2022 | Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 03 Feb 2022 | Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 03 Feb 2023 | Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls. | CY | CyDPC | GDPR | €3,250 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |