BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 May 2021 | Munkavállalói e-mail fiókok és munkaeszközök használatával és azok ellenőrzésével összefüggő adatkezelésThe controller did not provide the data subject with adequate prior information about the processing of work email and computer usage. The authority found this to breach the principles of fairness and accountability in data processing. | HU | NAIH | GDPR | €5,560 | ↗ |
| 05 May 2021 | Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification. | HU | NAIH | GDPR | €5,560 | ↗ |
| 13 Aug 2020 | Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis. | HU | NAIH | GDPR | €5,800 | ↗ |
| 19 Mar 2020 | Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle. | HU | NAIH | GDPR | €5,620 | ↗ |
| 15 Nov 2022 | Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000. | HU | NAIH | GDPR | €4,940 | ↗ |
| 19 Mar 2026 | ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards. | IS | Persónuvernd | GDPR | €13,940 | ↗ |
| 03 Dec 2020 | Dane anonimowe (W. Polska Sp. z o.o. z siedzibą w G.)UODO imposed a fine of PLN 1,968,524 on W. Polska Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing subscribers’ personal data in IT systems. | PL | UODO | GDPR | €440,000 | ↗ |
| 10 Sept 2025 | S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach. | FI | Office of the Data Protection Ombudsman | GDPR | €1,800,000 | ↗ |
| 22 Dec 2025 | NEXPUBLICA FRANCECNIL imposed a fine of 1,700,000 EUR on NEXPUBLICA FRANCE on 2025-12-22. The decision concerns serious security failures under Article 32 GDPR in the PCRM software used by public social action bodies, which processed sensitive personal data. | FR | CNIL | GDPR | €1,700,000 | ↗ |
| 22 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUESCNIL imposed an administrative fine of 1,700,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES. The decision concerns a breach of rules supervised by the French data protection authority. | FR | CNIL | GDPR | €1,700,000 | ↗ |
| 11 Jan 2023 | BBVABBVA was fined by the AEPD EUR 1,640,000 for multiple data protection violations. The case involved unauthorized payment operations and improper handling of personal data in credit information systems. | ES | AEPD | GDPR | €1,640,000 | ↗ |
| 02 Feb 2017 | Yume s.r.l.Yume s.r.l. was fined by the Garante in the amount of 1,590,000 EUR for improper processing of personal data during money transfer operations. The authority found that techniques were used to obscure the true identity of the initiators of financial transactions. | IT | Garante | GDPR | €1,590,000 | ↗ |
| 12 Nov 2024 | Dane anonimowe (A. z siedzibą w W. przy ul.)The Polish DPA (UODO) imposed administrative fines on the controller and the processor for breaches of GDPR obligations. The case concerned, among others, integrity and confidentiality, accountability, data protection by design, processor arrangements, and security measures. | PL | UODO | GDPR | €351,000 | ↗ |
| 10 Oct 2023 | American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 06 Sept 2023 | Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations. | IS | Persónuvernd | GDPR | €10,425 | ↗ |
| 16 Aug 2024 | D*** Handels Ges.m.b.H.D*** Handels Ges.m.b.H. was fined by the DSB for unlawfully processing personal data through a video surveillance system without a legal basis. The authority also found a breach of the data minimization principle. | AT | DSB | GDPR | €1,500,000 | ↗ |
| 05 Feb 2026 | Óbudai EgyetemÓbudai Egyetem was fined by the NAIH 1,500,000 HUF for breaching the principles of transparency and data minimization. The authority also found no lawful basis for processing and that the conditions for processing special categories of data were not met. | HU | NAIH | GDPR | €3,945 | ↗ |
| 02 Aug 2023 | Adatbázisban tárolt személyes adatok kezelésének jogszerűségeThe entity was fined by NAIH HUF 1,500,000 for processing personal data without a legal basis. The authority also found that the entity failed to demonstrate compliance with data processing requirements and did not provide adequate information to data subjects. | HU | NAIH | GDPR | €3,870 | ↗ |
| 01 Jan 2024 | ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €1,500,000 | ↗ |
| 15 Feb 2021 | KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF. | HU | NAIH | GDPR | €4,185 | ↗ |