BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Mar 2020 | Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle. | HU | NAIH | GDPR | €5,620 | ↗ |
| 15 Nov 2022 | Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000. | HU | NAIH | GDPR | €4,940 | ↗ |
| 02 Aug 2022 | Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability. | HU | NAIH | GDPR | €17,640 | ↗ |
| 20 Jan 2023 | Egészségi állapotra vonatkozó dokumentumok kiadásának megtagadásaThe controller did not comply with the data subject's access request and failed to provide adequate information about data processing. The conduct breached several GDPR provisions, and the authority imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,530 | ↗ |
| 18 Jun 2021 | Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights. | HU | NAIH | GDPR | €28,100 | ↗ |
| 23 Feb 2023 | Okmánymásolás és fényképek készítése és közzététele munkahelyenThe authority imposed a fine for copying applicants’ identity documents and for failing to provide adequate information to data subjects during the recruitment process. The case concerned breaches of information duties and personal data processing rules in the workplace. | HU | NAIH | GDPR | €524 | ↗ |
| 24 Mar 2021 | Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals. | HU | NAIH | GDPR | €27,400 | ↗ |
| 06 Feb 2023 | I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes. | HU | NAIH | GDPR | €76,800 | ↗ |
| 23 Jun 2021 | Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject. | HU | NAIH | GDPR | €2,860 | ↗ |
| 20 Mar 2026 | Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations. | HU | NAIH | GDPR | €1,275 | ↗ |
| 13 Jan 2023 | Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements. | HU | NAIH | GDPR | €2,520 | ↗ |
| 21 May 2019 | Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33. | HU | NAIH | GDPR | €306 | ↗ |
| 04 Oct 2019 | Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance. | HU | NAIH | GDPR | €15,050 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register. | HU | NAIH | GDPR | €7,600 | ↗ |
| 01 Jan 2024 | Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €130,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XThe school unlawfully forwarded personal data of 18 employees to the City of Y, breaching GDPR Articles 5 and 6. AZOP imposed a fine of EUR 2,000. | HR | AZOP | GDPR | €2,000 | ↗ |
| 14 Sept 2023 | društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach. | HR | AZOP | GDPR | €15,000 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |
| 20 Mar 2025 | FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR. | HR | AZOP | GDPR | €175,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |