Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jun 2021Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data.NODatatilsynetGDPR€49,145
17 Jul 2020Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness.HUNAIHGDPR€1,415
10 Nov 2022Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements.ITGaranteGDPR€500,000
20 Feb 2019Érintetti joggyakorlásra vonatkozó kérelem elbírálásaThe supervisory authority fined the controller for failing to facilitate the exercise of data subject rights and for not meeting transparency requirements when handling a deletion request. The case concerned an improperly handled request for erasure and insufficient information provided to the requester.HUNAIHGDPR€1,575
07 Nov 2023FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information.SEIMYGDPR€42,845
09 May 2024Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent.ITGaranteGDPR€500,000
29 Mar 2022Munkahelyi kamerás megfigyelés jogalapjának és arról való tájékoztatásnak jogszerűségeThe entity was fined for configuring CCTV cameras to monitor employees more broadly than necessary. The authority also found that the data processing notice was inadequate and that the legal basis was incorrectly set on employee consent instead of legitimate interest.HUNAIHGDPR€1,350
09 Oct 2025Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements.ITGaranteGDPR€500,000
16 Feb 2026KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR.ESAEPDGDPR€500,000
20 Mar 2026Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations.HUNAIHGDPR€1,275
04 Apr 2024COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATIONCNIL imposed an administrative fine of EUR 525,000 on COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION. The case concerns identified breaches of rules supervised by CNIL.FRCNILGDPR€525,000
12 May 2021Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved.NLAPGDPR€525,000
24 Feb 2022DPG Media Magazines B.V.DPG Media Magazines B.V. was fined for obstructing data subjects’ access to and erasure of their personal data by imposing unnecessary barriers. The authority found this conduct breached Article 12(2) GDPR.NLAPGDPR€525,000
03 Mar 2020Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle.NLAPGDPR€525,000
01 Jan 2019KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis.NLAutoriteit PersoonsgegevensGDPR€525,000
13 Nov 2020Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency.BEAPDGDPR€528,000
19 Jan 2022Dane anonimowe (U.)UODO imposed an administrative fine of 545,748 PLN on Dane anonimowe (U.) for failing to notify data subjects without undue delay about a personal data breach. The case concerns the obligation to promptly inform affected individuals under data protection rules.PLUODOGDPR€120,000
09 Jun 2025Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC).IEDPCGDPR€550,000
10 Dec 2020Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements.SEIMYGDPR€53,713
01 Jan 2022GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security.ESAEPDGDPR€550,000