Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Apr 2021Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis.HUNAIHGDPR€2,750
16 Dec 2020Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles.HUNAIHGDPR€98,350
05 May 2021Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification.HUNAIHGDPR€5,560
23 May 2019Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing.HUNAIHGDPR€918
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine.HUNAIHGDPR€2,820
26 May 2026Mediaworks Hungary Zrt.Mediaworks Hungary Zrt. was fined by NAIH 50,000,000 HUF for publishing links to a map containing personal data and special category data, including political opinions. The authority found that the processing lacked a lawful basis.HUNAIHGDPR€140,000
24 Jul 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés és törlési kérelem nem teljesítéseThe authority imposed a fine for a negligent GDPR breach involving the processing of personal data without a legal basis in connection with debt collection. It also found that deletion requests from the data subject were not fulfilled.HUNAIHGDPR€25,100
20 Apr 2021Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites.HUNAIHGDPR€2,770
23 Feb 2023TársasházThe NAIH imposed a 200,000 HUF fine on Társasház for GDPR breaches linked to its electronic surveillance system. The authority found deficiencies in the processing purposes, legal basis, and information provided to data subjects.HUNAIHGDPR€524
29 Mar 2022Munkahelyi kamerás megfigyelés jogalapjának és arról való tájékoztatásnak jogszerűségeThe entity was fined for configuring CCTV cameras to monitor employees more broadly than necessary. The authority also found that the data processing notice was inadequate and that the legal basis was incorrectly set on employee consent instead of legitimate interest.HUNAIHGDPR€1,350
17 May 2024Nem közszereplő személyes és különleges adatainak online sajtótermékben történő nyilvánosságra hozatalaThe controller published personal data in an online news outlet without a valid legal basis. It also failed to delete unlawfully processed personal data, resulting in breaches of several GDPR provisions.HUNAIHGDPR€25,800
13 Aug 2020Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis.HUNAIHGDPR€5,800
10 Sept 2024Okmánymásolat feltöltését is előíró regisztrációs folyamattal és regisztrációs adatbázissal kapcsolatos jogellenes adatkezelésThe authority imposed a fine for negligent GDPR violations between December 2021 and November 2023. The breaches concerned transparency and data processing principles in connection with the registration process and the registration database.HUNAIHGDPR€189,000
27 Feb 2023Adatkezelési tájékoztatás átláthatóságaThe entity did not provide data subjects with transparent and accurate information about the purposes and legal bases of processing. This breached GDPR Articles 6, 12, and 13, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,630
29 Sept 2020Vodafone Magyarország Távközlési Zártkörűen Működő RészvénytársaságThe NAIH imposed a 60,000,000 HUF fine on Vodafone Magyarország for unlawful voice recording practices at customer service offices. The authority found GDPR breaches relating to legal basis, transparency, purpose limitation, and data minimization.HUNAIHGDPR€163,000
14 Oct 2020Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring.HUNAIHGDPR€1,925
21 Jul 2023Hozzáférési kérelem nemteljesítéseThe controller did not respond to the access request within the one-month deadline. It also failed to provide substantive information about the processing of personal data, in breach of GDPR Articles 12 and 15.HUNAIHGDPR€26,300
07 Apr 2022Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System.HUNAIHGDPR€2,640
03 Sept 2020Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data.HUNAIHGDPR€55,800
26 Mar 2020Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820