BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 May 2024 | Fiziska personaA fine of EUR 100 was imposed by DVI. The decision became effective on 2024-05-16. | LV | DVI | GDPR | €100 | ↗ |
| 03 Nov 2025 | Fiziskas personaA fine of EUR 250 was imposed by DVI. The decision has entered into force. | LV | DVI | GDPR | €250 | ↗ |
| 10 Jun 2024 | SIA "Moshmans"A fine of EUR 500 was imposed by the DVI. The decision has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 29 Mar 2022 | SIA "8 LOUNGE"A fine of EUR 500 was imposed. The decision has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 12 Mar 2024 | Fiziska personaA monetary penalty of 150 EUR was imposed by DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €150 | ↗ |
| 18 Sept 2024 | Paula Stradiņa klīniskā universitātes slimnīcaA fine of EUR 2,000 was imposed. The decision has entered into force. | LV | DVI | GDPR | €2,000 | ↗ |
| 29 Sept 2022 | SIA "Deprus"DVI imposed a fine of 500 EUR on SIA "Deprus". The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 08 Sept 2025 | SIA "ZZ Dats"DVI imposed a fine of 300,000 EUR on SIA "ZZ Dats". The decision has been appealed. | LV | DVI | GDPR | €300,000 | ↗ |
| 18 Jan 2024 | Fiziska personaA fine of EUR 250 was imposed by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €250 | ↗ |
| 28 Oct 2025 | SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision. | LV | Datu valsts inspekcija | GDPR | €300,000 | ↗ |
| 01 Jul 2024 | Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000. | MT | IDPC | GDPR | €15,000 | ↗ |
| 01 May 2026 | Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed. | MT | IDPC | GDPR | €1,000 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability. | MT | IDPC | GDPR | €2,500 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation. | MT | IDPC | GDPR | €5,000 | ↗ |
| 01 Apr 2025 | Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer. | MT | IDPC | GDPR | €20,000 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 16 Jul 2019 | Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures. | NL | AP | GDPR | €460,000 | ↗ |
| 11 Feb 2021 | Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR. | NL | AP | GDPR | €440,000 | ↗ |
| 12 May 2021 | Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved. | NL | AP | GDPR | €525,000 | ↗ |
| 08 Jul 2025 | Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6. | NL | AP | GDPR | €500 | ↗ |