Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Oct 2019Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register.HUNAIHGDPR€7,600
30 Jun 2020AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient.DELandesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-WürttembergGDPR€1,240,000
01 Jan 2026Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€300,000
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
18 Mar 2025JRSY Laser LimitedThe Jersey Data Protection Authority fined JRSY Laser Limited 500 GBP following an investigation opened on 27 March 2024. The case concerned a breach of data protection requirements by the data controller.JEJOICGDPR€594
25 Mar 2025Star Delta Electrical ServicesThe Jersey Data Protection Authority fined Jon Peacock t/a Star-Delta Electrical Services £4,000. The case arose from a client complaint concerning the handling of personal data by the sole trader. The penalty was issued under the Data Protection (Jersey) Law 2018.JEJOICGDPR€4,787
01 Oct 2023TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated.ITItalian Competition Authority (AGCM)Omnibus€4,000,000
25 Jul 2025Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract.SIIP-RSGDPR€5,610
29 Jul 2025Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness.SIIP-RSGDPR€10,614
01 Dec 2025Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop.SIIP-RSGDPR€1,000
26 Nov 2025Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR.SIIP-RSGDPR€6,000
21 Nov 2025Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals.SIIP-RSGDPR€16,250
13 Aug 2025Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR.SIIP-RSGDPR€500
22 Jul 2025Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements.SIIP-RSGDPR€2,000
08 Dec 2025Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR.SIIP-RSGDPR€4,800
03 Jun 2025Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten.SEIntegritetsskyddsmyndigheten (IMY)GDPR€5,309,000
01 Jan 2025Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor.SEIntegritetsskyddsmyndigheten (IMY)GDPR€8,727
26 Feb 2025SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed.SEIntegritetsskyddsmyndighetenGDPR€538,000
04 Feb 2025Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate.SEIntegritetsskyddsmyndighetenGDPR€1,138,000
01 Oct 2023Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data.GBInformation Commissioner's OfficeGDPR€2,313,000