BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register. | HU | NAIH | GDPR | €7,600 | ↗ |
| 30 Jun 2020 | AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient. | DE | Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg | GDPR | €1,240,000 | ↗ |
| 01 Jan 2026 | Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €300,000 | ↗ |
| 12 Sept 2025 | A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €35,000 | ↗ |
| 18 Mar 2025 | JRSY Laser LimitedThe Jersey Data Protection Authority fined JRSY Laser Limited 500 GBP following an investigation opened on 27 March 2024. The case concerned a breach of data protection requirements by the data controller. | JE | JOIC | GDPR | €594 | ↗ |
| 25 Mar 2025 | Star Delta Electrical ServicesThe Jersey Data Protection Authority fined Jon Peacock t/a Star-Delta Electrical Services £4,000. The case arose from a client complaint concerning the handling of personal data by the sole trader. The penalty was issued under the Data Protection (Jersey) Law 2018. | JE | JOIC | GDPR | €4,787 | ↗ |
| 01 Oct 2023 | TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated. | IT | Italian Competition Authority (AGCM) | Omnibus | €4,000,000 | ↗ |
| 25 Jul 2025 | Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract. | SI | IP-RS | GDPR | €5,610 | ↗ |
| 29 Jul 2025 | Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness. | SI | IP-RS | GDPR | €10,614 | ↗ |
| 01 Dec 2025 | Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop. | SI | IP-RS | GDPR | €1,000 | ↗ |
| 26 Nov 2025 | Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR. | SI | IP-RS | GDPR | €6,000 | ↗ |
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 13 Aug 2025 | Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR. | SI | IP-RS | GDPR | €500 | ↗ |
| 22 Jul 2025 | Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements. | SI | IP-RS | GDPR | €2,000 | ↗ |
| 08 Dec 2025 | Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR. | SI | IP-RS | GDPR | €4,800 | ↗ |
| 03 Jun 2025 | Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €5,309,000 | ↗ |
| 01 Jan 2025 | Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €8,727 | ↗ |
| 26 Feb 2025 | SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed. | SE | Integritetsskyddsmyndigheten | GDPR | €538,000 | ↗ |
| 04 Feb 2025 | Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate. | SE | Integritetsskyddsmyndigheten | GDPR | €1,138,000 | ↗ |
| 01 Oct 2023 | Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data. | GB | Information Commissioner's Office | GDPR | €2,313,000 | ↗ |