Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Mar 2020Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle.HUNAIHGDPR€5,620
15 Nov 2022Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000.HUNAIHGDPR€4,940
02 Aug 2022Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability.HUNAIHGDPR€17,640
20 Jan 2023Egészségi állapotra vonatkozó dokumentumok kiadásának megtagadásaThe controller did not comply with the data subject's access request and failed to provide adequate information about data processing. The conduct breached several GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,530
18 Jun 2021Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights.HUNAIHGDPR€28,100
23 Feb 2023Okmánymásolás és fényképek készítése és közzététele munkahelyenThe authority imposed a fine for copying applicants’ identity documents and for failing to provide adequate information to data subjects during the recruitment process. The case concerned breaches of information duties and personal data processing rules in the workplace.HUNAIHGDPR€524
24 Mar 2021Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals.HUNAIHGDPR€27,400
06 Feb 2023I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes.HUNAIHGDPR€76,800
23 Jun 2021Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject.HUNAIHGDPR€2,860
20 Mar 2026Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations.HUNAIHGDPR€1,275
13 Jan 2023Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements.HUNAIHGDPR€2,520
21 May 2019Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33.HUNAIHGDPR€306
04 Oct 2019Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance.HUNAIHGDPR€15,050
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register.HUNAIHGDPR€7,600
01 Jan 2024Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€130,000
01 Sept 2025Osnovna škola XThe school unlawfully forwarded personal data of 18 employees to the City of Y, breaching GDPR Articles 5 and 6. AZOP imposed a fine of EUR 2,000.HRAZOPGDPR€2,000
14 Sept 2023društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach.HRAZOPGDPR€15,000
01 Aug 2025društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR.HRAZOPGDPR€17,500
20 Mar 2025FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR.HRAZOPGDPR€175,000
12 May 2021xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure.HRAZOPGDPR€30,553