Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jun 2023Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€10,000
16 Jun 2023Anonymisiert (DSB 2023-0.404.421)An individual processed personal data without a legal basis by storing contact details on a private phone for political advertising. The DSB imposed a EUR 1,000 fine for breaching GDPR lawfulness requirements.ATDSBGDPR€1,000
23 Aug 2022Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed.ATDSBGDPR€25,000
05 Aug 2021Anonymisiert (DSB 2021-0.518.795)An individual was fined for unlawfully processing and disclosing health-related personal data of a kindergarten teacher. The violation consisted of sending an email with sensitive information to her employer.ATDSBGDPR€600
19 Oct 2020Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR.ATDSBGDPR€150
19 Oct 2020Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis.ATDSBGDPR€600
02 Mar 2021Anonymisert (Datatilsynet far-gebyr-for-ulovlig-videresending-av-e-post)The company was fined 250,000 NOK for forwarding an employee’s emails without a legal basis. The authority found that this breached the GDPR and the rules governing employer access to employee email accounts.NODatatilsynetGDPR€24,378
01 Oct 2023Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability.MTIDPCGDPR€2,500
01 Oct 2023Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation.MTIDPCGDPR€5,000
01 Jul 2024Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000.MTIDPCGDPR€15,000
01 May 2026Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed.MTIDPCGDPR€1,000
01 Apr 2025Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer.MTIDPCGDPR€20,000
10 Aug 2015Anonymised (HDPA 95/2015)A fine was imposed on the residential complex “Lofos Edison” for installing additional surveillance cameras without authorization. The authority also noted that the installation was not properly notified to the competent authority.GRHDPAGDPR€1,000
25 Jul 2013Anonymised (HDPA 90/2013)The HDPA imposed a EUR 500 fine on the anonymised entity for sending unsolicited marketing emails. The conduct breached the requirement to obtain subscriber consent before sending such communications.GRHDPAePrivacy€500
25 Jul 2013Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements.GRHDPAGDPR€1,000
16 Feb 2024Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee.GRHDPAGDPR€2,000
20 Nov 2006Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject.GRHDPAGDPR€3,000
20 Nov 2006Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data.GRHDPAGDPR€15,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications.GRHDPAePrivacy€2,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for unlawfully processing email addresses without prior consent. The authority found this to be a breach of data protection law.GRHDPAGDPR€2,000