BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules. | CZ | UOOU | GDPR | €386 | ↗ |
| 23 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules. | CZ | UOOU | ePrivacy | €382 | ↗ |
| 07 Aug 2023 | Anonymizováno (ÚOOÚ UOOU-00414.23-30)The decision confirms a fine for a healthcare entity for failing to notify data subjects and document a personal data breach after a cyberattack. The authority found breaches of GDPR transparency and notification obligations. | CZ | UOOU | GDPR | €12,756 | ↗ |
| 22 Dec 2020 | Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR. | CZ | UOOU | GDPR | €1,141 | ↗ |
| 11 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR. | CZ | UOOU | GDPR | €3,869 | ↗ |
| 25 Oct 2021 | Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,166 | ↗ |
| 08 Oct 2020 | Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations. | CZ | UOOU | GDPR | €6,459 | ↗ |
| 20 Dec 2019 | Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €4,716 | ↗ |
| 24 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-00078/17-47)The entity was fined CZK 400,000 by the UOOU for processing customers' personal data without their consent. The authority found this conduct to be in breach of the Czech Data Protection Act. | CZ | UOOU | GDPR | €15,528 | ↗ |
| 14 Jun 2018 | Anonymizováno (ÚOOÚ UOOU-00051/18-14)The entity was fined for processing the personal data of apartment building residents through a camera system without their consent. The authority found this to be a breach of Czech data protection law. | CZ | UOOU | GDPR | €2,339 | ↗ |
| 14 May 2020 | Anonymizováno (ÚOOÚ spr-563809-118)The entity was fined for operating a camera system without meeting the information obligations required under Czech data protection law. The case concerns a breach of transparency duties toward individuals subject to surveillance. | CZ | UOOU | GDPR | €145 | ↗ |
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 23 Jul 2020 | Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed. | FI | TSV | GDPR | €7,000 | ↗ |
| 27 Sept 2018 | Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | AT | DSB | GDPR | €300 | ↗ |
| 20 Dec 2018 | Anonymisiert (DSB DSB-D550.037/0003-DSB/2018)The DSB imposed a fine of EUR 2,200 for unlawful video surveillance covering common areas and neighboring properties without consent. The conduct breached GDPR principles of data minimization and purpose limitation. | AT | DSB | GDPR | €2,200 | ↗ |
| 18 Nov 2025 | Anonymisiert (DSB 2025-0.902.556)The responsible party unlawfully published parts of a private complaint on a social media platform. This breached data minimization principles and there was no legal basis for processing personal data. | AT | DSB | GDPR | €1,200 | ↗ |
| 27 Oct 2025 | Anonymisiert (DSB 2025-0.811.087)The controller unlawfully processed personal data through video surveillance, including public sidewalk areas, contrary to data minimization principles. Images were also published online without a legal basis. | AT | DSB | GDPR | €1,500 | ↗ |
| 07 Oct 2025 | Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation. | AT | DSB | GDPR | €2,500 | ↗ |
| 21 Aug 2025 | Anonymisiert (DSB 2025-0.625.944)Dr. Martha N. unlawfully accessed the electronic health records of a former assistant without a legitimate purpose. The authority found this to be a breach of GDPR principles governing personal data processing. | AT | DSB | GDPR | €1,000 | ↗ |
| 12 Dec 2024 | Anonymisiert (DSB 2024-0.796.258)The individual unlawfully processed intimate photos by transferring and storing them without the data subject’s consent. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €2,000 | ↗ |