Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Jun 2019A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD.HUNAIHGDPR€1,550
14 Jul 2022SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident.DKDatatilsynetGDPR€67,180
11 Jul 2022Hírlevekkel kapcsolatos adatkezelésThe entity was fined by NAIH in the amount of HUF 500,000 for processing personal data for direct marketing purposes without a legal basis. The authority also found a lack of transparent information and delayed handling of data subject requests.HUNAIHGDPR€1,225
11 May 2021Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data.HUNAIHGDPR€1,395
24 Jan 2020Adatbiztonsági intézkedések és incidenskezelési gyakorlat hiányosságaiThe entity failed to implement appropriate technical and organizational measures to protect data, including storing access data in printed form. Its internal incident management policy also did not regulate the obligation to notify the supervisory authority.HUNAIHGDPR€1,490
01 Jan 2018LIGA NACIONAL DE FÚTBOL PROFESIONALThe Spanish Data Protection Agency (AEPD) fined LIGA NACIONAL DE FÚTBOL PROFESIONAL for using a mobile app to indiscriminately capture ambient sounds. This could have resulted in the processing of personal data without the consent of the individuals concerned.ESAEPDGDPR€500,000
16 Jul 2021Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen.DKDatatilsynetGDPR€67,220
16 Apr 2025CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 500,000 for failing to implement measures to ensure data integrity and confidentiality. The breach resulted in unauthorized access to personal data, indicating insufficient technical or organizational safeguards.ESAEPDGDPR€500,000
02 Dec 2025Bende IstvánBende István and Berencsi Béla Miklós were fined for processing personal data without a legal basis and for failing to provide required information. The authority found breaches of GDPR principles of fair processing, purpose limitation, and transparency.HUNAIHGDPR€1,315
20 Dec 2022Webáruház adatkezelése és törlési jog sérelmeThe authority found breaches of several GDPR provisions concerning information to data subjects, obtaining consent for marketing, and handling deletion requests. A fine of HUF 500,000 was imposed.HUNAIHGDPR€1,240
26 Jun 2023Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR.HUNAIHGDPR€1,355
27 Nov 2025SOCIETE DE VENTE A DISTANCECNIL imposed an administrative fine of EUR 500,000 on SOCIETE DE VENTE A DISTANCE and issued an injunction. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€500,000
17 Dec 2020Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users.ITGaranteGDPR€500,000
18 Dec 2023Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles.HUNAIHGDPR€1,295
09 Aug 2022Nemzeti Egészségbiztosítási AlapkezelőNemzeti Egészségbiztosítási Alapkezelő was fined by NAIH 500,000 HUF. The authority found that the organization failed to provide transparent information to data subjects and did not cooperate during the inspection, breaching GDPR transparency and accountability principles.HUNAIHGDPR€1,260
07 Jun 2021Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations.SEIMYGDPR€49,725
11 Dec 2019Volt munkavállaló e-mail-fiókjai archivált tartalmának tárolása és azokban történő dokumentumkeresésThe controller stored the complainant’s private correspondence without a lawful basis and searched archived email accounts for documents. The authority found a breach of data minimization and fairness principles.HUNAIHGDPR€1,510
14 Nov 2022Megismételt eljárásban bírság kiszabásaThe authority imposed a fine for violations related to the processing of personal data and special categories of data, including health data, without proper notification and consent. The case also concerned actions linked to the termination of an employment relationship.HUNAIHGDPR€1,230
22 Dec 2021SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights.HUNAIHGDPR€1,355
09 Apr 2020Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF.HUNAIHGDPR€1,410