BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 May 2021 | Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days. | NO | Datatilsynet | GDPR | €124,000 | ↗ |
| 01 Jan 2021 | Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR. | PT | Comissão Nacional de Proteção de Dados | GDPR | €1,250,000 | ↗ |
| 30 Jun 2020 | AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient. | DE | Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg | GDPR | €1,240,000 | ↗ |
| 20 Nov 2025 | LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system. | GB | ICO | GDPR | €1,393,000 | ↗ |
| 01 Nov 2025 | LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption. | GB | Information Commissioner's Office | GDPR | €1,361,000 | ↗ |
| 09 Sept 2022 | SIA "TET"A fine of EUR 1,200,000 was imposed by the DVI. The case was appealed, and a court judgment was later recorded. | LV | DVI | GDPR | €1,200,000 | ↗ |
| 03 Oct 2023 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €1,140,000 | ↗ |
| 22 Apr 2021 | DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider. | PL | UODO | GDPR | €249,000 | ↗ |
| 04 Jun 2025 | Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta. | FI | Office of the Data Protection Ombudsman | GDPR | €1,100,000 | ↗ |
| 17 Dec 2020 | Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data. | PL | UODO | GDPR | €240,000 | ↗ |
| 01 Jan 2024 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls. | ES | AEPD | GDPR | €1,040,000 | ↗ |
| 20 Jun 2024 | Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante EUR 1,000,000 for carrying out telemarketing activities without obtaining proper consent from the contacted individuals. The authority found a breach of fairness and transparency principles in the processing of personal data. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 12 Jan 2023 | ORANGEORANGE was fined EUR 1,000,000 by the AEPD for breaching data protection principles. The authority found failures to implement privacy by design and privacy by default in connection with SIM swapping incidents. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 30 Sept 2020 | Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis. | HU | NAIH | GDPR | €2,740 | ↗ |
| 23 Sept 2021 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 26 Jun 2019 | Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség és adattakarékosság elvének megsértéseThe controller did not comply with the data subject’s request to delete personal data, including phone numbers. The authority found unlawful processing and a breach of the principles of purpose limitation and data minimization. | HU | NAIH | GDPR | €3,090 | ↗ |
| 09 Jul 2020 | Második ítélet a NAIH/2020/974 sz. ügyben (Fővárosi Törvényszék 105.K.701.565/2022/2)The controller collected personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The conduct breached multiple GDPR provisions, and the authority imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,820 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions. | HU | NAIH | GDPR | €2,820 | ↗ |
| 24 Aug 2023 | Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €2,600 | ↗ |
| 03 Feb 2025 | IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274IBERMUTUA was fined EUR 1,000,000 by the AEPD for a data breach. Due to a computer error, personal data, including health information, was mistakenly sent to various companies. | ES | AEPD | GDPR | €1,000,000 | ↗ |