Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
24 Feb 2026Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice.GBInformation Commissioner's OfficeGDPR€16,606,000
10 Oct 2025Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts.GBInformation Commissioner's OfficeGDPR€16,074,000
15 Oct 2025CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance.GBInformation Commissioner's OfficeGDPR€16,083,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services.GBInformation Commissioner's OfficeGDPR€3,678,000
01 Apr 2023TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully.GBInformation Commissioner's OfficeGDPR€14,444,000
11 May 2026South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR.GBInformation Commissioner's OfficeGDPR€1,113,000
05 Oct 2023DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data.GBInformation Commissioner's OfficeGDPR€69,282
15 Apr 2026Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose.SIInformacijski pooblaščenecGDPR€6,000
02 Dec 2020Sahlgrenska Universitets­sjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€340,000
11 May 2020Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32.SEIMYGDPR€11,321
07 Jun 2021Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000.SEIMYGDPR€64,643
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
17 Oct 2023H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21.SEIMYGDPR€30,356
09 Jun 2021Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures.SEIMYGDPR€34,794
12 Jun 2023Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language.SEIMYGDPR€4,992,000
28 Aug 2023Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1).SEIMYGDPR€2,941,000
10 Feb 2021Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act.SEIMYePrivacy€248,000
25 Jun 2024AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta.SEIMYGDPR€1,336,000
21 Jun 2021Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization.SEIMYGDPR€1,566,000