BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Mar 2021 | Engedményezés utáni követeléskezeléssel kapcsolatos adatkezelés jogalapja, érintetti kérelem teljesítéseThe supervisory authority found a GDPR breach in the processing of personal data for debt collection after assignment of a claim. The controller did not establish a proper legal basis, failed to provide clear information about that basis, and did not properly handle data subject requests. | HU | NAIH | GDPR | €13,650 | ↗ |
| 20 Dec 2022 | Tájékoztatás ügyfélszolgálati telefonhívások rögzítésérőlThe entity did not provide adequate prior information about the recording of customer service phone calls. The authority found this to be a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €12,400 | ↗ |
| 09 Dec 2020 | ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident. | HU | NAIH | GDPR | €56,000 | ↗ |
| 22 Dec 2021 | SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights. | HU | NAIH | GDPR | €1,355 | ↗ |
| 09 Apr 2020 | Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF. | HU | NAIH | GDPR | €1,410 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontThe Hungarian Defence Forces Health Centre did not report a data breach within 72 hours and lacked internal incident management procedures. NAIH found this to be a breach of GDPR obligations and imposed a fine of 2,500,000 HUF. | HU | NAIH | GDPR | €7,600 | ↗ |
| 26 Sept 2022 | TV2 Média Csoport Zrt.NAIH imposed a 10,000,000 HUF fine on TV2 Média Csoport Zrt. for insufficient user information and improper consent management on its websites. The authority found that these practices breached the principles of fair and transparent data processing. | HU | NAIH | GDPR | €24,500 | ↗ |
| 08 Aug 2019 | Zala Megyei Kormányhivatal Keszthelyi Járási FöldhivatalThe Zala Megyei Kormányhivatal Keszthelyi Járási Földhivatal was fined 600,000 HUF by NAIH for breaching the principles of data minimization and transparency. The authority found that personal data was made accessible to third parties without clear information about the processing. | HU | NAIH | GDPR | €1,848 | ↗ |
| 16 Dec 2020 | [...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group. | HU | NAIH | GDPR | €1,012 | ↗ |
| 04 Sept 2025 | Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection. | HU | NAIH | GDPR | €2,540 | ↗ |
| 21 Dec 2022 | Szálláshelyen kamerás megfigyelőrendszer üzemeltetéseThe authority found that the controller unlawfully processed personal data through a camera system, breaching several GDPR provisions. The decision highlighted improper data storage and a lack of transparent information provided to data subjects. | HU | NAIH | GDPR | €7,440 | ↗ |
| 10 Feb 2022 | Név2.The controller unlawfully processed and published personal data, including images, without consent, breaching multiple GDPR provisions. NAIH imposed a fine of 10,000,000 HUF. | HU | NAIH | GDPR | €28,200 | ↗ |
| 02 Feb 2024 | [...] Zrt.The controller did not provide adequate information about data processing through camera systems in bank branches. This constituted a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €156,000 | ↗ |
| 03 Jun 2019 | Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed. | HU | NAIH | GDPR | €3,090 | ↗ |
| 17 Jul 2020 | Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness. | HU | NAIH | GDPR | €1,415 | ↗ |
| 05 Jul 2022 | Üzleti titokra való hivatkozással hanganyag korlátozott felhasználhatósággal történő rendelkezésre bocsátásaThe authority fined the controller for failing to properly handle a data subject request. The case concerned a breach of the obligations under Article 12 GDPR. | HU | NAIH | GDPR | €4,900 | ↗ |
| 26 Jun 2019 | Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations. | HU | NAIH | GDPR | €3,090 | ↗ |
| 08 Jul 2022 | Egészségügyi dokumentáció másolatának kiadásaThe controller breached the GDPR by failing to provide adequate access to personal health data and by not ensuring transparency and information rights. As a result, the authority imposed a fine of HUF 600,000. | HU | NAIH | GDPR | €1,488 | ↗ |
| 02 Mar 2022 | Személyes adatok nyilvánosságra hozatala online tudakozóbanThe entity did not delete personal data from an online directory after the data subject requested removal. It also failed to demonstrate a lawful basis or consent for publication, resulting in a breach of accountability and unlawful disclosure of personal data. | HU | NAIH | GDPR | Ft 5,000,000 | ↗ |
| 29 Apr 2024 | Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13. | HU | NAIH | GDPR | €12,750 | ↗ |