BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Feb 2021 | Политическа партия „Д.П.Б.“Political party “D.P.B.” was fined 1,000 BGN by CPDP for processing personal data without the consent of the data subjects. The breach occurred during the registration of election commission members and violated Article 6 GDPR. | BG | CPDP | GDPR | €511 | ↗ |
| 07 Apr 2022 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization. | BG | CPDP | GDPR | €1,534 | ↗ |
| 23 Jul 2019 | община К.The Municipality of K. unlawfully processed the complainant’s personal data by sharing it with third parties without consent. The authority found a GDPR breach and imposed a 500 BGN fine. | BG | CPDP | GDPR | €256 | ↗ |
| 03 Sept 2019 | А.Т.The CPDP imposed a fine of 23,000 BGN on A.T. for processing personal data without consent, in breach of Article 6 GDPR. The case concerned the creation of financial obligations for the complainant without a valid contract. | BG | CPDP | GDPR | €11,760 | ↗ |
| 17 Jan 2019 | Учебно заведениеThe school was fined 1,000 BGN by the CPDP for unlawfully processing students' personal data. It shared the data with a financial institution without proper consent, which breached GDPR requirements. | BG | CPDP | GDPR | €511 | ↗ |
| 13 Jan 2025 | OrangeCNIL imposed a EUR 50 million fine on Orange for displaying commercial ads in email inboxes without prior user consent. The authority also found that advertising and statistical cookies continued to be read after consent had been withdrawn, in breach of the GDPR. | FR | Commission Nationale de l'Informatique et des Libertés | GDPR | €50,000,000 | ↗ |
| 13 Jan 2026 | Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data. | FR | Commission nationale de l’informatique et des libertés | GDPR | €42,000,000 | ↗ |
| 18 Oct 2019 | National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach. | BG | Commission for Personal Data Protection | GDPR | €2,607,000 | ↗ |
| 01 Jan 2021 | Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR. | PT | Comissão Nacional de Proteção de Dados | GDPR | €1,250,000 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-23-fr-2022)The company failed to meet the transparency obligations under Article 12(1) GDPR by not providing the required information in a concise, transparent, and easily accessible manner. CNPD treated this as a breach of the information duties owed to data subjects. | LU | CNPD | GDPR | €1,300 | ↗ |
| 13 Oct 2021 | Anonymisé (CNPD decision-36-fr-2021)The company did not involve the Data Protection Officer in all matters related to personal data protection. CNPD found this breached GDPR Articles 38(1) and 39(1) and imposed a EUR 23,400 fine. | LU | CNPD | GDPR | €23,400 | ↗ |
| 04 Aug 2021 | Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39. | LU | CNPD | GDPR | €17,700 | ↗ |
| 22 Jun 2022 | Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles. | LU | CNPD | GDPR | €4,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-17-fr-2021)The CNPD found that the company breached GDPR principles by failing to comply with data minimization and retention limits in its video surveillance practices. A fine of EUR 1,900 was imposed. | LU | CNPD | GDPR | €1,900 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-18-fr-2022)The company unlawfully transmitted personal data to third parties without prior authorization. The authority also found breaches of GDPR data processing principles and data subject rights. | LU | CNPD | GDPR | €2,500 | ↗ |
| 02 Feb 2022 | Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000. | LU | CNPD | GDPR | €10,000 | ↗ |
| 15 Jul 2021 | Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects. | LU | CNPD | GDPR | €3,500 | ↗ |
| 15 Dec 2021 | Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR. | LU | CNPD | GDPR | €11,600 | ↗ |
| 07 Jul 2022 | Anonymisé (CNPD decision-15-fr-2022)The company was fined by the CNPD EUR 10,500 for breaching the data minimization principle and for failing to adequately inform individuals about video surveillance systems. The authority cited violations of GDPR Articles 5(1)(c) and 13. | LU | CNPD | GDPR | €10,500 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-06-fr-2025)The company failed to maintain a proper record of processing activities under Article 30 GDPR. The register contained inaccuracies and omissions, indicating a breach of documentation obligations. | LU | CNPD | GDPR | €1,277 | ↗ |