BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Jun 2019 | Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed. | HU | NAIH | GDPR | €3,090 | ↗ |
| 26 Jun 2019 | Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations. | HU | NAIH | GDPR | €3,090 | ↗ |
| 11 Dec 2025 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETINGCNIL imposed an administrative fine of 1,000,000 EUR on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETING. The case concerns a confirmed breach of rules under CNIL supervision. | FR | CNIL | GDPR | €1,000,000 | ↗ |
| 22 Apr 2021 | Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis. | HU | NAIH | GDPR | €2,750 | ↗ |
| 24 Jul 2025 | CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine. | HU | NAIH | GDPR | €2,820 | ↗ |
| 20 Apr 2021 | Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites. | HU | NAIH | GDPR | €2,770 | ↗ |
| 27 Feb 2023 | Adatkezelési tájékoztatás átláthatóságaThe entity did not provide data subjects with transparent and accurate information about the purposes and legal bases of processing. This breached GDPR Articles 6, 12, and 13, and the authority imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,630 | ↗ |
| 07 Apr 2022 | Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System. | HU | NAIH | GDPR | €2,640 | ↗ |
| 26 Mar 2020 | Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,820 | ↗ |
| 20 Jan 2023 | Egészségi állapotra vonatkozó dokumentumok kiadásának megtagadásaThe controller did not comply with the data subject's access request and failed to provide adequate information about data processing. The conduct breached several GDPR provisions, and the authority imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,530 | ↗ |
| 23 Jun 2021 | Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject. | HU | NAIH | GDPR | €2,860 | ↗ |
| 13 Jan 2023 | Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements. | HU | NAIH | GDPR | €2,520 | ↗ |
| 02 Jan 2026 | Dane anonimowe (Spółkę)UODO imposed an administrative fine of PLN 978,128 on the company. The authority found that the controller did not ensure the independence of the Data Protection Officer and failed to prevent a conflict of interest arising from the DPO’s other tasks and duties. | PL | UODO | GDPR | €232,000 | ↗ |
| 12 Apr 2023 | Česká republika – Ministerstvo vnitraThe Czech Ministry of Interior was fined CZK 975,000 by the UOOU for violations of personal data processing rules during COVID-19 measures. The authority found, among other issues, a failure to conduct data protection impact assessments and improper disclosure of processing purposes. | CZ | UOOU | GDPR | €41,633 | ↗ |
| 07 May 2026 | South Staffordshire Plc and South Staffordshire Water PlcThe Information Commissioner’s Office (ICO) imposed a fine of 963,900 GBP on South Staffordshire Plc and South Staffordshire Water Plc for breaches of Article 5(1)(f) and Article 32(1) of the UK GDPR. The case followed a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated. | GB | ICO | GDPR | €1,115,000 | ↗ |
| 11 May 2026 | South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR. | GB | Information Commissioner's Office | GDPR | €1,113,000 | ↗ |
| 17 Dec 2024 | Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security. | FI | TSV | GDPR | €950,000 | ↗ |
| 01 Jan 2025 | Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach. | FI | Tietosuojavaltuutetun toimisto | GDPR | €950,000 | ↗ |
| 15 Mar 2019 | Dane anonimowe (X. Sp. z o.o., za naruszenie stwierdzone w niniejszej decyzji,)UODO found that X. Sp. z o.o. failed to comply with its information obligation. The decision ordered remediation of the breach and imposed a fine of PLN 943,470. | PL | UODO | GDPR | €219,000 | ↗ |