BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Dec 2022 | Webáruház adatkezelése és törlési jog sérelmeThe authority found breaches of several GDPR provisions concerning information to data subjects, obtaining consent for marketing, and handling deletion requests. A fine of HUF 500,000 was imposed. | HU | NAIH | GDPR | €1,240 | ↗ |
| 26 Jun 2023 | Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR. | HU | NAIH | GDPR | €1,355 | ↗ |
| 27 Nov 2025 | SOCIETE DE VENTE A DISTANCECNIL imposed an administrative fine of EUR 500,000 on SOCIETE DE VENTE A DISTANCE and issued an injunction. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €500,000 | ↗ |
| 17 Dec 2020 | Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users. | IT | Garante | GDPR | €500,000 | ↗ |
| 18 Dec 2023 | Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles. | HU | NAIH | GDPR | €1,295 | ↗ |
| 09 Aug 2022 | Nemzeti Egészségbiztosítási AlapkezelőNemzeti Egészségbiztosítási Alapkezelő was fined by NAIH 500,000 HUF. The authority found that the organization failed to provide transparent information to data subjects and did not cooperate during the inspection, breaching GDPR transparency and accountability principles. | HU | NAIH | GDPR | €1,260 | ↗ |
| 07 Jun 2021 | Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations. | SE | IMY | GDPR | €49,725 | ↗ |
| 11 Dec 2019 | Volt munkavállaló e-mail-fiókjai archivált tartalmának tárolása és azokban történő dokumentumkeresésThe controller stored the complainant’s private correspondence without a lawful basis and searched archived email accounts for documents. The authority found a breach of data minimization and fairness principles. | HU | NAIH | GDPR | €1,510 | ↗ |
| 14 Nov 2022 | Megismételt eljárásban bírság kiszabásaThe authority imposed a fine for violations related to the processing of personal data and special categories of data, including health data, without proper notification and consent. The case also concerned actions linked to the termination of an employment relationship. | HU | NAIH | GDPR | €1,230 | ↗ |
| 22 Dec 2021 | SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights. | HU | NAIH | GDPR | €1,355 | ↗ |
| 09 Apr 2020 | Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF. | HU | NAIH | GDPR | €1,410 | ↗ |
| 24 Jun 2021 | Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data. | NO | Datatilsynet | GDPR | €49,145 | ↗ |
| 17 Jul 2020 | Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness. | HU | NAIH | GDPR | €1,415 | ↗ |
| 10 Nov 2022 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 20 Feb 2019 | Érintetti joggyakorlásra vonatkozó kérelem elbírálásaThe supervisory authority fined the controller for failing to facilitate the exercise of data subject rights and for not meeting transparency requirements when handling a deletion request. The case concerned an improperly handled request for erasure and insufficient information provided to the requester. | HU | NAIH | GDPR | €1,575 | ↗ |
| 07 Nov 2023 | FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information. | SE | IMY | GDPR | €42,845 | ↗ |
| 09 May 2024 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent. | IT | Garante | GDPR | €500,000 | ↗ |
| 29 Mar 2022 | Munkahelyi kamerás megfigyelés jogalapjának és arról való tájékoztatásnak jogszerűségeThe entity was fined for configuring CCTV cameras to monitor employees more broadly than necessary. The authority also found that the data processing notice was inadequate and that the legal basis was incorrectly set on employee consent instead of legitimate interest. | HU | NAIH | GDPR | €1,350 | ↗ |
| 09 Oct 2025 | Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 16 Feb 2026 | KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €500,000 | ↗ |