BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jun 2023 | Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €10,000 | ↗ |
| 16 Jun 2023 | Anonymisiert (DSB 2023-0.404.421)An individual processed personal data without a legal basis by storing contact details on a private phone for political advertising. The DSB imposed a EUR 1,000 fine for breaching GDPR lawfulness requirements. | AT | DSB | GDPR | €1,000 | ↗ |
| 23 Aug 2022 | Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed. | AT | DSB | GDPR | €25,000 | ↗ |
| 05 Aug 2021 | Anonymisiert (DSB 2021-0.518.795)An individual was fined for unlawfully processing and disclosing health-related personal data of a kindergarten teacher. The violation consisted of sending an email with sensitive information to her employer. | AT | DSB | GDPR | €600 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR. | AT | DSB | GDPR | €150 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis. | AT | DSB | GDPR | €600 | ↗ |
| 02 Mar 2021 | Anonymisert (Datatilsynet far-gebyr-for-ulovlig-videresending-av-e-post)The company was fined 250,000 NOK for forwarding an employee’s emails without a legal basis. The authority found that this breached the GDPR and the rules governing employer access to employee email accounts. | NO | Datatilsynet | GDPR | €24,378 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability. | MT | IDPC | GDPR | €2,500 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation. | MT | IDPC | GDPR | €5,000 | ↗ |
| 01 Jul 2024 | Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000. | MT | IDPC | GDPR | €15,000 | ↗ |
| 01 May 2026 | Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed. | MT | IDPC | GDPR | €1,000 | ↗ |
| 01 Apr 2025 | Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer. | MT | IDPC | GDPR | €20,000 | ↗ |
| 10 Aug 2015 | Anonymised (HDPA 95/2015)A fine was imposed on the residential complex “Lofos Edison” for installing additional surveillance cameras without authorization. The authority also noted that the installation was not properly notified to the competent authority. | GR | HDPA | GDPR | €1,000 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)The HDPA imposed a EUR 500 fine on the anonymised entity for sending unsolicited marketing emails. The conduct breached the requirement to obtain subscriber consent before sending such communications. | GR | HDPA | ePrivacy | €500 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 16 Feb 2024 | Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee. | GR | HDPA | GDPR | €2,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject. | GR | HDPA | GDPR | €3,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data. | GR | HDPA | GDPR | €15,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for unlawfully processing email addresses without prior consent. The authority found this to be a breach of data protection law. | GR | HDPA | GDPR | €2,000 | ↗ |