BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Nov 2019 | Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség, adattakarékosság és átláthatóság elvének megsértéseThe supervisory authority found that the controller did not comply with requests to erase personal data and unlawfully processed phone numbers. It also identified breaches of purpose limitation, data minimization, and transparency principles. | HU | NAIH | GDPR | €4,485 | ↗ |
| 01 Feb 2024 | Capio A/SThe Danish Data Protection Authority reported Capio A/S to the police and recommended a fine of at least DKK 1,500,000. The case concerned insufficient supervision of data processors, breaching the GDPR accountability principle. | DK | Datatilsynet | GDPR | €201,000 | ↗ |
| 27 Nov 2025 | AMERICAN EXPRESS CARTE FRANCEOn 27 November 2025, CNIL fined AMERICAN EXPRESS CARTE FRANCE EUR 1.5 million for breaches of cookie and tracker rules. The authority found that trackers were placed without consent, despite refusal, and continued to be read after consent was withdrawn. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 30 Jan 2026 | Magyar Agrár- és Élettudományi EgyetemThe Hungarian University of Agriculture and Life Sciences was fined by the NAIH for negligent GDPR violations in its dormitory admissions data processing. The authority cited a lack of proper legal basis, insufficient prior information, and failure to apply data minimization. | HU | NAIH | GDPR | €3,945 | ↗ |
| 27 Nov 2025 | SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERECNIL imposed an administrative fine of 1 500 000 EUR on SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 15 Apr 2022 | SOCIETE D'EDITION DE LOGICIELS APPLICATIFSCNIL imposed a fine of 1,500,000 EUR on SOCIETE D'EDITION DE LOGICIELS APPLICATIFS. The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 20 Mar 2024 | Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights. | IS | Persónuvernd | GDPR | €10,095 | ↗ |
| 14 May 2020 | Anonymizováno (ÚOOÚ UOOU-1936/19-68)The entity was fined 1,500,000 CZK by the UOOU. The authority found that required corrective measures under the Czech Data Processing Act were not implemented. | CZ | UOOU | GDPR | €54,405 | ↗ |
| 02 May 2023 | InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords. | CZ | UOOU | GDPR | €63,600 | ↗ |
| 03 May 2022 | HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made. | IS | Persónuvernd | GDPR | €10,905 | ↗ |
| 11 Sept 2025 | ILVA A/SVestre Landsret upheld a DKK 1.5 million GDPR fine against ILVA A/S. The case concerned retention of data on about 385,000 customers without a deletion policy, and the fine was based on the group’s total turnover. | DK | Datatilsynet | GDPR | €200,000 | ↗ |
| 12 Mar 2024 | Dane anonimowe (U.)An administrative fine was imposed for failing to notify the supervisory authority of a personal data breach within the required 72 hours after detection. The authority also found that the affected individuals were not informed without undue delay. | PL | UODO | GDPR | €336,000 | ↗ |
| 20 May 2024 | Dane anonimowe (A. Spółka Akcyjna z siedzibą w U., ul.)UODO imposed an administrative fine of PLN 1,440,549 on A. Spółka Akcyjna. The authority found breaches of the integrity and confidentiality principle and the obligation to implement appropriate data security measures. | PL | UODO | GDPR | €338,000 | ↗ |
| 01 Jan 2024 | Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations. | PL | Urząd Ochrony Danych Osobowych | GDPR | €331,000 | ↗ |
| 02 Feb 2017 | Sirama s.r.lSirama s.r.l was fined EUR 1,430,000 by the Garante for transferring money to China using techniques intended to evade anti-money laundering rules. The authority also found that personal data were processed without consent from the actual senders. | IT | Garante | GDPR | €1,430,000 | ↗ |
| 20 Oct 2022 | Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions. | IT | Garante | GDPR | €1,400,000 | ↗ |
| 20 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €54,460 | ↗ |
| 01 Jan 2024 | REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U.REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U. was fined by the AEPD for processing personal data without consent, which led to unauthorized access to a customer's data. The authority also found inadequate security measures. | ES | AEPD | GDPR | €1,380,000 | ↗ |
| 05 Mar 2020 | Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security. | IS | Persónuvernd | GDPR | €9,139 | ↗ |
| 02 Feb 2017 | Euro Comunication System s.r.l.Euro Comunication System s.r.l. was fined EUR 1,260,000 by the Garante. The authority found that funds were transferred without obtaining consent for data processing and that transactions were split to avoid detection, breaching AML rules. | IT | Garante | GDPR | €1,260,000 | ↗ |