BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Jun 2024 | FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 07 Apr 2021 | Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects. | HU | NAIH | GDPR | €2,780 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles. | HU | NAIH | GDPR | €2,820 | ↗ |
| 08 Mar 2022 | Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IS | Persónuvernd | GDPR | €6,850 | ↗ |
| 29 Jul 2024 | IBERINFORMIBERINFORM was fined by the AEPD €1,000,000 for processing personal data of self-employed individuals without a proper legal basis. The authority also found that the data were used beyond professional relationships, including for marketing and online exposure. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 14 Jun 2019 | Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 24 Nov 2022 | Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 04 Sept 2025 | Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection. | HU | NAIH | GDPR | €2,540 | ↗ |
| 29 Apr 2026 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 03 Jun 2019 | Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed. | HU | NAIH | GDPR | €3,090 | ↗ |
| 26 Jun 2019 | Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations. | HU | NAIH | GDPR | €3,090 | ↗ |
| 11 Dec 2025 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETINGCNIL imposed an administrative fine of 1,000,000 EUR on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETING. The case concerns a confirmed breach of rules under CNIL supervision. | FR | CNIL | GDPR | €1,000,000 | ↗ |
| 22 Apr 2021 | Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis. | HU | NAIH | GDPR | €2,750 | ↗ |
| 24 Jul 2025 | CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine. | HU | NAIH | GDPR | €2,820 | ↗ |
| 20 Apr 2021 | Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites. | HU | NAIH | GDPR | €2,770 | ↗ |
| 27 Feb 2023 | Adatkezelési tájékoztatás átláthatóságaThe entity did not provide data subjects with transparent and accurate information about the purposes and legal bases of processing. This breached GDPR Articles 6, 12, and 13, and the authority imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,630 | ↗ |
| 07 Apr 2022 | Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System. | HU | NAIH | GDPR | €2,640 | ↗ |
| 26 Mar 2020 | Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,820 | ↗ |
| 20 Jan 2023 | Egészségi állapotra vonatkozó dokumentumok kiadásának megtagadásaThe controller did not comply with the data subject's access request and failed to provide adequate information about data processing. The conduct breached several GDPR provisions, and the authority imposed a fine of HUF 1,000,000. | HU | NAIH | GDPR | €2,530 | ↗ |