BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Jan 2024 | Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis. | HU | NAIH | GDPR | €2,580 | ↗ |
| 11 Dec 2025 | Mobius Solutions LtdThe French CNIL imposed a 1 million EUR fine on Mobius Solutions Ltd for personal data processing violations. The case involved unlawful retention and reuse of data from more than 46 million users after the contract ended, as well as failure to maintain a processing activities register. | FR | CNIL | GDPR | €1,000,000 | ↗ |
| 18 Dec 2013 | Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 07 Jul 2023 | Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles. | HU | NAIH | GDPR | €2,580 | ↗ |
| 31 Jul 2024 | Hangrögzítés telefonos ügyfélszolgálatonThe authority imposed a fine for breaching the GDPR principles of transparency and accountability. The entity did not adequately inform callers that customer service phone calls were being recorded. | HU | NAIH | GDPR | €2,530 | ↗ |
| 22 Jun 2023 | Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante EUR 1,000,000 for violations linked to an application that processed users’ personal data. The app was used to handle refunds of highway ticket costs for delays caused by construction works. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 09 Jul 2020 | dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations. | HU | NAIH | GDPR | €2,820 | ↗ |
| 22 Jun 2022 | Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles. | DK | Datatilsynet | GDPR | €134,000 | ↗ |
| 04 Jan 2021 | Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing. | NO | Datatilsynet | GDPR | €95,750 | ↗ |
| 15 Oct 2019 | Munkavállaló munkaeszközeinek ellenőrzéseThe controller unlawfully processed the complainant's personal data by reviewing and monitoring their email account without prior notice. This breached the principle of fair processing. | HU | NAIH | GDPR | €3,010 | ↗ |
| 28 Feb 2019 | Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF. | HU | NAIH | GDPR | €3,160 | ↗ |
| 06 Jun 2024 | FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 07 Apr 2021 | Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects. | HU | NAIH | GDPR | €2,780 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles. | HU | NAIH | GDPR | €2,820 | ↗ |
| 08 Mar 2022 | Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IS | Persónuvernd | GDPR | €6,850 | ↗ |
| 29 Jul 2024 | IBERINFORMIBERINFORM was fined by the AEPD €1,000,000 for processing personal data of self-employed individuals without a proper legal basis. The authority also found that the data were used beyond professional relationships, including for marketing and online exposure. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 14 Jun 2019 | Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 24 Nov 2022 | Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 04 Sept 2025 | Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection. | HU | NAIH | GDPR | €2,540 | ↗ |
| 29 Apr 2026 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR. | ES | AEPD | GDPR | €1,000,000 | ↗ |