Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Sept 2018Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ATDSBGDPR€300
23 Aug 2022Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed.ATDSBGDPR€25,000
07 Dec 2023N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR.ATDSBGDPR€20,000
21 Aug 2025Anonymisiert (DSB 2025-0.625.944)Dr. Martha N. unlawfully accessed the electronic health records of a former assistant without a legitimate purpose. The authority found this to be a breach of GDPR principles governing personal data processing.ATDSBGDPR€1,000
19 Oct 2020Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis.ATDSBGDPR€600
07 Dec 2023H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR.ATDSBGDPR€10,000
07 Oct 2025Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation.ATDSBGDPR€2,500
27 Aug 2024YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine.BEAPDGDPR€8,000
09 Jul 2020YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners.BEAPDGDPR€5,000
04 Sept 2025Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students.BEGegevensbeschermingsautoriteit (GBA)GDPR€9,700
14 May 2020Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements.BEAPDGDPR€50,000
12 May 2026SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles.BEAPDGDPR€50,000
27 Nov 2025InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision.BEAutorité de protection des données (APD)GDPR€40,000
28 Jul 2020Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
25 Nov 2019YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
01 Sept 2020Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures.BEAPDGDPR€2,000
17 Sept 2019vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17.BEAPDGDPR€2,000
13 Nov 2020Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency.BEAPDGDPR€528,000
28 May 2019Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
23 Aug 2024Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights.BEAPDGDPR€5,000