BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Jun 2021 | Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures. | SE | IMY | GDPR | €34,794 | ↗ |
| 26 Feb 2024 | Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP. | GB | ICO | GDPR | €409,000 | ↗ |
| 08 Dec 2022 | Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle. | DK | Datatilsynet | GDPR | €47,054 | ↗ |
| 16 Dec 2025 | Bank MillenniumThe Polish Supreme Administrative Court upheld a PLN 350,000 administrative fine imposed on Bank Millennium by the President of the Personal Data Protection Office. The sanction concerned failure to report a personal data breach and failure to notify affected individuals after a courier shipment containing customer data was lost. | PL | Urząd Ochrony Danych Osobowych | GDPR | €82,922 | ↗ |
| 11 Feb 2021 | Roma CapitaleRoma Capitale was fined EUR 350,000 by the Garante for breaches of GDPR principles, including data minimization and security. The violations resulted in unauthorized access to personal data over an extended period. | IT | Garante | GDPR | €350,000 | ↗ |
| 09 Oct 2024 | Pana AB, prowadzącego działalność gospodarczą pod firmą X, ul.The Polish DPA (UODO) imposed a fine of PLN 353,589 on Pana AB, operating under the name X, for breaches of the GDPR. The authority also ordered the company to bring its processing operations into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €82,273 | ↗ |
| 16 Dec 2020 | [...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group. | HU | NAIH | GDPR | €1,012 | ↗ |
| 14 Oct 2021 | Dane anonimowe (Bank Z. S.A.)The Polish DPA (UODO) imposed an administrative fine of PLN 363,832 on Bank Z. S.A. The authority found that the bank failed to notify the supervisory authority of a personal data breach and did not inform the affected individuals. | PL | UODO | GDPR | €79,625 | ↗ |
| 18 Jan 2017 | Anonymizováno (ÚOOÚ UOOU-01178/17-265)The company was fined for repeatedly sending unsolicited commercial communications without a legal basis. The case concerned a breach of the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €14,064 | ↗ |
| 11 May 2023 | SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRECNIL imposed a fine of 380,000 EUR on SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRE. The case concerns data processing breaches in connection with a health and wellness website. | FR | CNIL | GDPR | €380,000 | ↗ |
| 14 Jan 2021 | Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles. | NO | Datatilsynet | GDPR | €38,796 | ↗ |
| 27 Nov 2024 | Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended. | DK | Datatilsynet | GDPR | €53,632 | ↗ |
| 24 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act. | CZ | UOOU | GDPR | €15,528 | ↗ |
| 13 Oct 2025 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data. | ES | AEPD | GDPR | €400,000 | ↗ |
| 11 Jun 2021 | BRAbank ASABRAbank ASA was fined NOK 400,000 by Datatilsynet for failing to perform risk assessments and testing before launching a customer portal. The deficiency led to a data breach in which customers could view other customers’ loan information. | NO | Datatilsynet | GDPR | €39,672 | ↗ |
| 22 Jul 2021 | Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome. | IT | Garante | GDPR | €400,000 | ↗ |
| 10 Jan 2013 | Consodata S.p.A.Consodata S.p.A. was fined by the Garante 400,000 EUR for violations linked to unsolicited telemarketing. The authority also found that the company failed to provide individuals with proper data protection information. | IT | Garante | GDPR | €400,000 | ↗ |
| 09 Jul 2021 | Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls. | DK | Datatilsynet | GDPR | €53,788 | ↗ |
| 12 Nov 2021 | Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals. | NL | AP | GDPR | €400,000 | ↗ |
| 10 May 2024 | EUSKALTEL, S.A.EUSKALTEL, S.A. was fined 400,000 EUR by the AEPD for failing to comply with a resolution requiring access to geolocation data. The authority found a breach of Article 58.2 of the GDPR. | ES | AEPD | GDPR | €400,000 | ↗ |