BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Jun 2019 | A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD. | HU | NAIH | GDPR | €1,550 | ↗ |
| 14 Jul 2022 | SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident. | DK | Datatilsynet | GDPR | €67,180 | ↗ |
| 11 Jul 2022 | Hírlevekkel kapcsolatos adatkezelésThe entity was fined by NAIH in the amount of HUF 500,000 for processing personal data for direct marketing purposes without a legal basis. The authority also found a lack of transparent information and delayed handling of data subject requests. | HU | NAIH | GDPR | €1,225 | ↗ |
| 11 May 2021 | Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data. | HU | NAIH | GDPR | €1,395 | ↗ |
| 24 Jan 2020 | Adatbiztonsági intézkedések és incidenskezelési gyakorlat hiányosságaiThe entity failed to implement appropriate technical and organizational measures to protect data, including storing access data in printed form. Its internal incident management policy also did not regulate the obligation to notify the supervisory authority. | HU | NAIH | GDPR | €1,490 | ↗ |
| 01 Jan 2018 | LIGA NACIONAL DE FÚTBOL PROFESIONALThe Spanish Data Protection Agency (AEPD) fined LIGA NACIONAL DE FÚTBOL PROFESIONAL for using a mobile app to indiscriminately capture ambient sounds. This could have resulted in the processing of personal data without the consent of the individuals concerned. | ES | AEPD | GDPR | €500,000 | ↗ |
| 16 Jul 2021 | Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen. | DK | Datatilsynet | GDPR | €67,220 | ↗ |
| 16 Apr 2025 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 500,000 for failing to implement measures to ensure data integrity and confidentiality. The breach resulted in unauthorized access to personal data, indicating insufficient technical or organizational safeguards. | ES | AEPD | GDPR | €500,000 | ↗ |
| 02 Dec 2025 | Bende IstvánBende István and Berencsi Béla Miklós were fined for processing personal data without a legal basis and for failing to provide required information. The authority found breaches of GDPR principles of fair processing, purpose limitation, and transparency. | HU | NAIH | GDPR | €1,315 | ↗ |
| 20 Dec 2022 | Webáruház adatkezelése és törlési jog sérelmeThe authority found breaches of several GDPR provisions concerning information to data subjects, obtaining consent for marketing, and handling deletion requests. A fine of HUF 500,000 was imposed. | HU | NAIH | GDPR | €1,240 | ↗ |
| 26 Jun 2023 | Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR. | HU | NAIH | GDPR | €1,355 | ↗ |
| 27 Nov 2025 | SOCIETE DE VENTE A DISTANCECNIL imposed an administrative fine of EUR 500,000 on SOCIETE DE VENTE A DISTANCE and issued an injunction. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €500,000 | ↗ |
| 17 Dec 2020 | Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users. | IT | Garante | GDPR | €500,000 | ↗ |
| 18 Dec 2023 | Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles. | HU | NAIH | GDPR | €1,295 | ↗ |
| 09 Aug 2022 | Nemzeti Egészségbiztosítási AlapkezelőNemzeti Egészségbiztosítási Alapkezelő was fined by NAIH 500,000 HUF. The authority found that the organization failed to provide transparent information to data subjects and did not cooperate during the inspection, breaching GDPR transparency and accountability principles. | HU | NAIH | GDPR | €1,260 | ↗ |
| 07 Jun 2021 | Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations. | SE | IMY | GDPR | €49,725 | ↗ |
| 11 Dec 2019 | Volt munkavállaló e-mail-fiókjai archivált tartalmának tárolása és azokban történő dokumentumkeresésThe controller stored the complainant’s private correspondence without a lawful basis and searched archived email accounts for documents. The authority found a breach of data minimization and fairness principles. | HU | NAIH | GDPR | €1,510 | ↗ |
| 14 Nov 2022 | Megismételt eljárásban bírság kiszabásaThe authority imposed a fine for violations related to the processing of personal data and special categories of data, including health data, without proper notification and consent. The case also concerned actions linked to the termination of an employment relationship. | HU | NAIH | GDPR | €1,230 | ↗ |
| 22 Dec 2021 | SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights. | HU | NAIH | GDPR | €1,355 | ↗ |
| 09 Apr 2020 | Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF. | HU | NAIH | GDPR | €1,410 | ↗ |