BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Mar 2021 | Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached. | BE | APD | GDPR | €2,000 | ↗ |
| 27 Jan 2021 | De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations. | BE | APD | GDPR | €50,000 | ↗ |
| 08 Jun 2020 | de heer YThe APD Litigation Chamber fined de heer Y 5,000 EUR. It found that personal data from the municipal staff list was processed for election propaganda, breaching the GDPR principles of purpose limitation and lawfulness. | BE | APD | GDPR | €5,000 | ↗ |
| 23 Aug 2022 | Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents. | BE | APD | GDPR | €2,500 | ↗ |
| 27 Nov 2025 | Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24. | BE | APD | GDPR | €5,000 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 16 Jul 2019 | Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures. | NL | AP | GDPR | €460,000 | ↗ |
| 11 Feb 2021 | Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR. | NL | AP | GDPR | €440,000 | ↗ |
| 12 May 2021 | Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved. | NL | AP | GDPR | €525,000 | ↗ |
| 08 Jul 2025 | Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6. | NL | AP | GDPR | €500 | ↗ |
| 09 Aug 2018 | InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000. | NL | AP | GDPR | €48,000 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 04 Nov 2019 | Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data. | NL | AP | GDPR | €150,000 | ↗ |
| 17 Dec 2025 | Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach. | NL | AP | GDPR | €175,000 | ↗ |
| 13 Apr 2023 | Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32. | NL | AP | GDPR | €150,000 | ↗ |
| 18 Dec 2024 | Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements. | NL | AP | GDPR | €4,750,000 | ↗ |
| 17 Nov 2023 | Gemeente VoorschotenThe municipality of Voorschoten unlawfully processed personal data about residents’ waste disposal history without a sufficient legal basis. It also failed to properly inform the affected residents, breaching GDPR Articles 5, 6 and 14. | NL | AP | GDPR | €30,000 | ↗ |
| 31 Jan 2024 | Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements. | NL | AP | GDPR | €10,000,000 | ↗ |
| 05 Jun 2024 | Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12. | NL | AP | GDPR | €6,000 | ↗ |
| 24 Feb 2022 | DPG Media Magazines B.V.DPG Media Magazines B.V. was fined for obstructing data subjects’ access to and erasure of their personal data by imposing unnecessary barriers. The authority found this conduct breached Article 12(2) GDPR. | NL | AP | GDPR | €525,000 | ↗ |