BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Aug 2018 | InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000. | NL | AP | GDPR | €48,000 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 04 Nov 2019 | Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data. | NL | AP | GDPR | €150,000 | ↗ |
| 17 Dec 2025 | Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach. | NL | AP | GDPR | €175,000 | ↗ |
| 13 Apr 2023 | Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32. | NL | AP | GDPR | €150,000 | ↗ |
| 18 Dec 2024 | Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements. | NL | AP | GDPR | €4,750,000 | ↗ |
| 17 Nov 2023 | Gemeente VoorschotenThe municipality of Voorschoten unlawfully processed personal data about residents’ waste disposal history without a sufficient legal basis. It also failed to properly inform the affected residents, breaching GDPR Articles 5, 6 and 14. | NL | AP | GDPR | €30,000 | ↗ |
| 31 Jan 2024 | Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements. | NL | AP | GDPR | €10,000,000 | ↗ |
| 05 Jun 2024 | Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12. | NL | AP | GDPR | €6,000 | ↗ |
| 24 Feb 2022 | DPG Media Magazines B.V.DPG Media Magazines B.V. was fined for obstructing data subjects’ access to and erasure of their personal data by imposing unnecessary barriers. The authority found this conduct breached Article 12(2) GDPR. | NL | AP | GDPR | €525,000 | ↗ |
| 11 May 2021 | Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident. | NL | AP | GDPR | €7,500 | ↗ |
| 21 Dec 2022 | Politie NederlandThe Dutch Data Protection Authority fined the police chief for failing to carry out a data protection impact assessment before using mobile camera cars in Rotterdam. The measure created a high risk to individuals' rights and freedoms. | NL | AP | GDPR | €50,000 | ↗ |
| 10 Jun 2021 | orthodontiepraktijkThe entity failed to implement appropriate technical and organizational measures to secure personal data, which constitutes a breach of Article 32 GDPR. Sensitive data on the website was not transmitted over encrypted connections, increasing the risk of disclosure. | NL | AP | GDPR | €12,000 | ↗ |
| 08 May 2026 | MLU B.V.MLU B.V. was fined €100,000,000 by AP for transferring personal data of users in Finland and Norway to Russia without adequate safeguards. The authority found breaches of GDPR Articles 44, 46, and 5. | NL | AP | GDPR | €100,000,000 | ↗ |
| 30 Apr 2020 | vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR. | NL | AP | GDPR | €725,000 | ↗ |
| 07 Jul 2021 | Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers. | NL | AP | GDPR | €450,000 | ↗ |
| 04 Nov 2019 | Coöperatie VGZ U.A.The Autoriteit Persoonsgegevens imposed a EUR 150,000 penalty on Coöperatie VGZ U.A. for failing to implement appropriate technical measures to protect personal data from unauthorized access. The authority found a breach of data protection law. | NL | AP | GDPR | €150,000 | ↗ |
| 16 Jul 2024 | A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 05 Mar 2020 | CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation. | NL | Autoriteit Persoonsgegevens | GDPR | €40,000 | ↗ |
| 03 Mar 2020 | Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle. | NL | AP | GDPR | €525,000 | ↗ |