Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Dec 2025HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision.NLAutoriteit PersoonsgegevensGDPR€100,000
26 Nov 2024NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests.NLAutoriteit PersoonsgegevensGDPR€4,750,000
01 Oct 2023ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company.NLAutoriteit PersoonsgegevensGDPR€2,700,000
08 May 2026MLU B.V.The Dutch data protection authority imposed a EUR 100 million fine on MLU B.V. for transferring personal data to Russia without adequate safeguards. It also ordered the company to stop transferring personal data of individuals in Norway and Finland to Russia via the Yango app.NLAutoriteit PersoonsgegevensGDPR€100,000,000
05 Feb 2026Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility.NLAutoriteit PersoonsgegevensGDPR€25,000
27 Nov 2025InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision.BEAutorité de protection des données (APD)GDPR€40,000
25 May 2022RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000.BEAutorité de protection des donnéesGDPR€50,000
31 Jan 2026SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
01 Dec 2024Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000
01 Aug 2025Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€1,000
01 Apr 2025BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal€10,000
01 Feb 2025Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€5,000
Lensa.roLensa.ro, operated by Tensa Art Design, was fined EUR 20,000 by Romania’s data protection authority, ANSPDCP. The case involved cookie-based tracking and behavioral advertising without clear user consent, as well as failure to respond to the authority’s official information requests.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
07 Jul 2025AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€25,000
01 Feb 2025Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000
01 May 2025SC Piramida Trade Invest SRLThe Romanian DPA ANSPDCP imposed a total fine of EUR 3,000 on SC Piramida Trade Invest SRL for unlawful audio-video monitoring of employees and inadequate staff information. It also found that the company failed to respond to access, erasure, and objection requests within the legal deadline; a separate email-forwarding issue resulted only in a warning.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€3,000
01 Jun 2025Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€10,000
27 Aug 2024YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine.BEAPDGDPR€8,000
09 Jul 2020YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners.BEAPDGDPR€5,000
14 May 2020Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements.BEAPDGDPR€50,000