BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Jun 2025 | VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles. | DE | Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) | GDPR | €45,000,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XThe school unlawfully forwarded personal data of 18 employees to the City of Y, breaching GDPR Articles 5 and 6. AZOP imposed a fine of EUR 2,000. | HR | AZOP | GDPR | €2,000 | ↗ |
| 14 Sept 2023 | društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach. | HR | AZOP | GDPR | €15,000 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |
| 20 Mar 2025 | FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR. | HR | AZOP | GDPR | €175,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |
| 01 Jul 2025 | Bolnica XBolnica X did not provide data subjects with the required information about data processing. The hospital also failed to implement adequate security measures and did not report the data breach to the supervisory authority and affected individuals within the required timeframe. | HR | AZOP | GDPR | €3,000 | ↗ |
| 25 Feb 2020 | Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation. | HR | AZOP | GDPR | €145,000 | ↗ |
| 27 Oct 2023 | Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents. | HR | AZOP | GDPR | €4,500,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 11 Jul 2024 | EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history. | HR | AZOP | GDPR | €5,470,000 | ↗ |
| 27 Feb 2025 | Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach. | HR | AZOP | GDPR | €25,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements. | HR | AZOP | GDPR | €2,000 | ↗ |
| 19 Feb 2026 | Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures. | HR | AZOP | GDPR | €100,000 | ↗ |
| 02 Jul 2025 | Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia. | HR | AZOP | GDPR | €101,000 | ↗ |
| 05 Mar 2020 | CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation. | NL | Autoriteit Persoonsgegevens | GDPR | €40,000 | ↗ |
| 01 Jan 2019 | KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis. | NL | Autoriteit Persoonsgegevens | GDPR | €525,000 | ↗ |
| 01 Jan 2024 | a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221. | NL | Autoriteit Persoonsgegevens | GDPR | €6,000 | ↗ |
| 10 Oct 2023 | Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data. | NL | Autoriteit Persoonsgegevens | GDPR | €175,000 | ↗ |
| 16 Jul 2024 | AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules. | NL | Autoriteit Persoonsgegevens | GDPR | €600,000 | ↗ |