Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 May 2021Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days.NODatatilsynetGDPR€124,000
01 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR€1,250,000
30 Jun 2020AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient.DELandesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-WürttembergGDPR€1,240,000
20 Nov 2025LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system.GBICOGDPR€1,393,000
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
09 Sept 2022SIA "TET"A fine of EUR 1,200,000 was imposed by the DVI. The case was appealed, and a court judgment was later recorded.LVDVIGDPR€1,200,000
03 Oct 2023MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€1,140,000
22 Apr 2021DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider.PLUODOGDPR€249,000
04 Jun 2025Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta.FIOffice of the Data Protection OmbudsmanGDPR€1,100,000
17 Dec 2020Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data.PLUODOGDPR€240,000
01 Jan 2024IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls.ESAEPDGDPR€1,040,000
20 Jun 2024Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante EUR 1,000,000 for carrying out telemarketing activities without obtaining proper consent from the contacted individuals. The authority found a breach of fairness and transparency principles in the processing of personal data.ITGaranteGDPR€1,000,000
12 Jan 2023ORANGEORANGE was fined EUR 1,000,000 by the AEPD for breaching data protection principles. The authority found failures to implement privacy by design and privacy by default in connection with SIM swapping incidents.ESAEPDGDPR€1,000,000
30 Sept 2020Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis.HUNAIHGDPR€2,740
23 Sept 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers.ESAEPDGDPR€1,000,000
26 Jun 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség és adattakarékosság elvének megsértéseThe controller did not comply with the data subject’s request to delete personal data, including phone numbers. The authority found unlawful processing and a breach of the principles of purpose limitation and data minimization.HUNAIHGDPR€3,090
09 Jul 2020Második ítélet a NAIH/2020/974 sz. ügyben (Fővárosi Törvényszék 105.K.701.565/2022/2)The controller collected personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The conduct breached multiple GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions.HUNAIHGDPR€2,820
24 Aug 2023Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13.HUNAIHGDPR€2,600
03 Feb 2025IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274IBERMUTUA was fined EUR 1,000,000 by the AEPD for a data breach. Due to a computer error, personal data, including health information, was mistakenly sent to various companies.ESAEPDGDPR€1,000,000