BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Nov 2025 | LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption. | GB | Information Commissioner's Office | GDPR | €1,361,000 | ↗ |
| 24 Feb 2026 | Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice. | GB | Information Commissioner's Office | GDPR | €16,606,000 | ↗ |
| 10 Oct 2025 | Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts. | GB | Information Commissioner's Office | GDPR | €16,074,000 | ↗ |
| 15 Oct 2025 | CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance. | GB | Information Commissioner's Office | GDPR | €16,083,000 | ↗ |
| 26 Mar 2025 | Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services. | GB | Information Commissioner's Office | GDPR | €3,678,000 | ↗ |
| 01 Apr 2023 | TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully. | GB | Information Commissioner's Office | GDPR | €14,444,000 | ↗ |
| 11 May 2026 | South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR. | GB | Information Commissioner's Office | GDPR | €1,113,000 | ↗ |
| 05 Oct 2023 | DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data. | GB | Information Commissioner's Office | GDPR | €69,282 | ↗ |
| 15 Apr 2026 | Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose. | SI | Informacijski pooblaščenec | GDPR | €6,000 | ↗ |
| 02 Dec 2020 | Sahlgrenska UniversitetssjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €340,000 | ↗ |
| 11 May 2020 | Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32. | SE | IMY | GDPR | €11,321 | ↗ |
| 07 Jun 2021 | Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000. | SE | IMY | GDPR | €64,643 | ↗ |
| 28 Mar 2022 | Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making. | SE | IMY | GDPR | €719,000 | ↗ |
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |
| 09 Jun 2021 | Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures. | SE | IMY | GDPR | €34,794 | ↗ |
| 12 Jun 2023 | Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language. | SE | IMY | GDPR | €4,992,000 | ↗ |
| 28 Aug 2023 | Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1). | SE | IMY | GDPR | €2,941,000 | ↗ |
| 10 Feb 2021 | Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act. | SE | IMY | ePrivacy | €248,000 | ↗ |
| 25 Jun 2024 | AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta. | SE | IMY | GDPR | €1,336,000 | ↗ |
| 21 Jun 2021 | Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization. | SE | IMY | GDPR | €1,566,000 | ↗ |