Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Jul 2018Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules.CZUOOUGDPR€386
23 Mar 2021Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules.CZUOOUePrivacy€382
07 Aug 2023Anonymizováno (ÚOOÚ UOOU-00414.23-30)The decision confirms a fine for a healthcare entity for failing to notify data subjects and document a personal data breach after a cyberattack. The authority found breaches of GDPR transparency and notification obligations.CZUOOUGDPR€12,756
22 Dec 2020Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR.CZUOOUGDPR€1,141
11 Dec 2018Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR.CZUOOUGDPR€3,869
25 Oct 2021Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services.CZUOOUePrivacy€1,166
08 Oct 2020Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations.CZUOOUGDPR€6,459
20 Dec 2019Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€4,716
24 Jul 2018Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act.CZUOOUGDPR€15,528
14 Jun 2018Anonymizováno (ÚOOÚ UOOU-00051/18-14)The entity was fined for processing the personal data of apartment building residents through a camera system without their consent. The authority found this to be a breach of Czech data protection law.CZUOOUGDPR€2,339
14 May 2020Anonymizováno (ÚOOÚ spr-563809-118)The entity was fined for operating a camera system without meeting the information obligations required under Czech data protection law. The case concerns a breach of transparency duties toward individuals subject to surveillance.CZUOOUGDPR€145
05 Jul 2021Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose.FITSVGDPR€25,000
23 Jul 2020Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed.FITSVGDPR€7,000
27 Sept 2018Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ATDSBGDPR€300
20 Dec 2018Anonymisiert (DSB DSB-D550.037/0003-DSB/2018)The DSB imposed a fine of EUR 2,200 for unlawful video surveillance covering common areas and neighboring properties without consent. The conduct breached GDPR principles of data minimization and purpose limitation.ATDSBGDPR€2,200
18 Nov 2025Anonymisiert (DSB 2025-0.902.556)The responsible party unlawfully published parts of a private complaint on a social media platform. This breached data minimization principles and there was no legal basis for processing personal data.ATDSBGDPR€1,200
27 Oct 2025Anonymisiert (DSB 2025-0.811.087)The controller unlawfully processed personal data through video surveillance, including public sidewalk areas, contrary to data minimization principles. Images were also published online without a legal basis.ATDSBGDPR€1,500
07 Oct 2025Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation.ATDSBGDPR€2,500
21 Aug 2025Anonymisiert (DSB 2025-0.625.944)Dr. Martha N. unlawfully accessed the electronic health records of a former assistant without a legitimate purpose. The authority found this to be a breach of GDPR principles governing personal data processing.ATDSBGDPR€1,000
12 Dec 2024Anonymisiert (DSB 2024-0.796.258)The individual unlawfully processed intimate photos by transferring and storing them without the data subject’s consent. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€2,000