Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jul 2025Bolnica XBolnica X did not provide data subjects with the required information about data processing. The hospital also failed to implement adequate security measures and did not report the data breach to the supervisory authority and affected individuals within the required timeframe.HRAZOPGDPR€3,000
25 Feb 2020Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation.HRAZOPGDPR€145,000
27 Oct 2023Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents.HRAZOPGDPR€4,500,000
13 Jun 2025HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information.HRAZOPGDPR€320,000
11 Jul 2024EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history.HRAZOPGDPR€5,470,000
27 Feb 2025Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach.HRAZOPGDPR€25,000
01 Sept 2025Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements.HRAZOPGDPR€2,000
19 Feb 2026Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures.HRAZOPGDPR€100,000
02 Jul 2025Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia.HRAZOPGDPR€101,000
28 Feb 2024Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach.GRHDPAGDPR€2,995,000
08 Aug 2014THE GOLDEN ATHENS SPAThe company processed personal data without consent, breaching the principles of lawfulness and data minimization under Greek law. HDPA imposed a fine of EUR 1,000.GRHDPAGDPR€1,000
25 Jul 2022MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing.GRHDPAGDPR€5,000
04 Aug 2017VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations.GRHDPAGDPR€5,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data.GRHDPAGDPR€8,000
24 Feb 2017Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information.GRHDPAGDPR€10,000
12 May 2021A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications.GRHDPAGDPR€5,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006.GRHDPAePrivacy€150,000
07 May 2015Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification.GRHDPAGDPR€3,000
27 Jun 2012OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules.GRHDPAGDPR€3,000
12 Jun 2015ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data.GRHDPAGDPR€100,000