BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jun 2021 | Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data. | NO | Datatilsynet | GDPR | €49,145 | ↗ |
| 17 Jul 2020 | Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness. | HU | NAIH | GDPR | €1,415 | ↗ |
| 10 Nov 2022 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 20 Feb 2019 | Érintetti joggyakorlásra vonatkozó kérelem elbírálásaThe supervisory authority fined the controller for failing to facilitate the exercise of data subject rights and for not meeting transparency requirements when handling a deletion request. The case concerned an improperly handled request for erasure and insufficient information provided to the requester. | HU | NAIH | GDPR | €1,575 | ↗ |
| 07 Nov 2023 | FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information. | SE | IMY | GDPR | €42,845 | ↗ |
| 09 May 2024 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent. | IT | Garante | GDPR | €500,000 | ↗ |
| 29 Mar 2022 | Munkahelyi kamerás megfigyelés jogalapjának és arról való tájékoztatásnak jogszerűségeThe entity was fined for configuring CCTV cameras to monitor employees more broadly than necessary. The authority also found that the data processing notice was inadequate and that the legal basis was incorrectly set on employee consent instead of legitimate interest. | HU | NAIH | GDPR | €1,350 | ↗ |
| 09 Oct 2025 | Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 16 Feb 2026 | KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €500,000 | ↗ |
| 20 Mar 2026 | Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations. | HU | NAIH | GDPR | €1,275 | ↗ |
| 04 Apr 2024 | COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATIONCNIL imposed an administrative fine of EUR 525,000 on COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €525,000 | ↗ |
| 12 May 2021 | Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved. | NL | AP | GDPR | €525,000 | ↗ |
| 24 Feb 2022 | DPG Media Magazines B.V.DPG Media Magazines B.V. was fined for obstructing data subjects’ access to and erasure of their personal data by imposing unnecessary barriers. The authority found this conduct breached Article 12(2) GDPR. | NL | AP | GDPR | €525,000 | ↗ |
| 03 Mar 2020 | Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle. | NL | AP | GDPR | €525,000 | ↗ |
| 01 Jan 2019 | KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis. | NL | Autoriteit Persoonsgegevens | GDPR | €525,000 | ↗ |
| 13 Nov 2020 | Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency. | BE | APD | GDPR | €528,000 | ↗ |
| 19 Jan 2022 | Dane anonimowe (U.)UODO imposed an administrative fine of 545,748 PLN on Dane anonimowe (U.) for failing to notify data subjects without undue delay about a personal data breach. The case concerns the obligation to promptly inform affected individuals under data protection rules. | PL | UODO | GDPR | €120,000 | ↗ |
| 09 Jun 2025 | Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC). | IE | DPC | GDPR | €550,000 | ↗ |
| 10 Dec 2020 | Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements. | SE | IMY | GDPR | €53,713 | ↗ |
| 01 Jan 2022 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security. | ES | AEPD | GDPR | €550,000 | ↗ |