BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Jun 2021 | Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject. | HU | NAIH | GDPR | €2,860 | ↗ |
| 13 Jan 2023 | Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements. | HU | NAIH | GDPR | €2,520 | ↗ |
| 01 Jan 2024 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls. | ES | AEPD | GDPR | €1,040,000 | ↗ |
| 17 Dec 2020 | Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data. | PL | UODO | GDPR | €240,000 | ↗ |
| 04 Jun 2025 | Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta. | FI | Office of the Data Protection Ombudsman | GDPR | €1,100,000 | ↗ |
| 22 Apr 2021 | DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider. | PL | UODO | GDPR | €249,000 | ↗ |
| 03 Oct 2023 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €1,140,000 | ↗ |
| 01 Nov 2025 | LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption. | GB | Information Commissioner's Office | GDPR | €1,361,000 | ↗ |
| 09 Sept 2022 | SIA "TET"A fine of EUR 1,200,000 was imposed by the DVI. The case was appealed, and a court judgment was later recorded. | LV | DVI | GDPR | €1,200,000 | ↗ |
| 20 Nov 2025 | LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system. | GB | ICO | GDPR | €1,393,000 | ↗ |
| 30 Jun 2020 | AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient. | DE | Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg | GDPR | €1,240,000 | ↗ |
| 11 May 2021 | Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days. | NO | Datatilsynet | GDPR | €124,000 | ↗ |
| 01 Jan 2021 | Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR. | PT | Comissão Nacional de Proteção de Dados | GDPR | €1,250,000 | ↗ |
| 02 Feb 2017 | Euro Comunication System s.r.l.Euro Comunication System s.r.l. was fined EUR 1,260,000 by the Garante. The authority found that funds were transferred without obtaining consent for data processing and that transactions were split to avoid detection, breaching AML rules. | IT | Garante | GDPR | €1,260,000 | ↗ |
| 05 Mar 2020 | Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security. | IS | Persónuvernd | GDPR | €9,139 | ↗ |
| 01 Jan 2024 | REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U.REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U. was fined by the AEPD for processing personal data without consent, which led to unauthorized access to a customer's data. The authority also found inadequate security measures. | ES | AEPD | GDPR | €1,380,000 | ↗ |
| 20 Oct 2022 | Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions. | IT | Garante | GDPR | €1,400,000 | ↗ |
| 20 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €54,460 | ↗ |
| 02 Feb 2017 | Sirama s.r.lSirama s.r.l was fined EUR 1,430,000 by the Garante for transferring money to China using techniques intended to evade anti-money laundering rules. The authority also found that personal data were processed without consent from the actual senders. | IT | Garante | GDPR | €1,430,000 | ↗ |
| 01 Jan 2024 | Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations. | PL | Urząd Ochrony Danych Osobowych | GDPR | €331,000 | ↗ |