Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Mar 2026Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations.HUNAIHGDPR€1,275
06 Jan 2025Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560.LUCNPDGDPR€493,000
31 Mar 2021Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay.NLAPGDPR€475,000
14 Mar 2022Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected.IEDPCGDPR€463,000
16 Jul 2019Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures.NLAPGDPR€460,000
23 Feb 2023Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected.IEDPCGDPR€460,000
01 Oct 2024TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution.ESAEPDGDPR€450,000
07 Jul 2021Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers.NLAPGDPR€450,000
09 Dec 2020Twitter International CompanyThe Irish DPC imposed a fine of EUR 450,000 on Twitter International Company in inquiry IN-19-1-1. The fine was collected.IEDPCGDPR€450,000
11 Feb 2021Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR.NLAPGDPR€440,000
21 May 2025Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal.ITGarante per la protezione dei dati personaliGDPR€420,000
06 Dec 2011Tiscali Italia SpATiscali Italia SpA was fined €420,000 by the Garante for retaining customer traffic data beyond the legal retention period. The authority also found that Amdocs accessed the data without being properly designated as a data processor or obtaining customer consent.ITGaranteGDPR€420,000
14 Jan 2021Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles.NODatatilsynetGDPR€38,796
27 Nov 2024Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended.DKDatatilsynetGDPR€53,632
24 Jul 2018Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act.CZUOOUGDPR€15,528
13 Oct 2025BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data.ESAEPDGDPR€400,000
11 Jun 2021BRAbank ASABRAbank ASA was fined NOK 400,000 by Datatilsynet for failing to perform risk assessments and testing before launching a customer portal. The deficiency led to a data breach in which customers could view other customers’ loan information.NODatatilsynetGDPR€39,672
22 Jul 2021Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome.ITGaranteGDPR€400,000
10 Jan 2013Consodata S.p.A.Consodata S.p.A. was fined by the Garante 400,000 EUR for violations linked to unsolicited telemarketing. The authority also found that the company failed to provide individuals with proper data protection information.ITGaranteGDPR€400,000
09 Jul 2021Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls.DKDatatilsynetGDPR€53,788