Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jun 2021Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject.HUNAIHGDPR€2,860
13 Jan 2023Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements.HUNAIHGDPR€2,520
01 Jan 2024IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls.ESAEPDGDPR€1,040,000
17 Dec 2020Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data.PLUODOGDPR€240,000
04 Jun 2025Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta.FIOffice of the Data Protection OmbudsmanGDPR€1,100,000
22 Apr 2021DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider.PLUODOGDPR€249,000
03 Oct 2023MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€1,140,000
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
09 Sept 2022SIA "TET"A fine of EUR 1,200,000 was imposed by the DVI. The case was appealed, and a court judgment was later recorded.LVDVIGDPR€1,200,000
20 Nov 2025LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system.GBICOGDPR€1,393,000
30 Jun 2020AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient.DELandesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-WürttembergGDPR€1,240,000
11 May 2021Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days.NODatatilsynetGDPR€124,000
01 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR€1,250,000
02 Feb 2017Euro Comunication System s.r.l.Euro Comunication System s.r.l. was fined EUR 1,260,000 by the Garante. The authority found that funds were transferred without obtaining consent for data processing and that transactions were split to avoid detection, breaching AML rules.ITGaranteGDPR€1,260,000
05 Mar 2020Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security.ISPersónuverndGDPR€9,139
01 Jan 2024REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U.REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U. was fined by the AEPD for processing personal data without consent, which led to unauthorized access to a customer's data. The authority also found inadequate security measures.ESAEPDGDPR€1,380,000
20 Oct 2022Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions.ITGaranteGDPR€1,400,000
20 Aug 2018Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services.CZUOOUePrivacy€54,460
02 Feb 2017Sirama s.r.lSirama s.r.l was fined EUR 1,430,000 by the Garante for transferring money to China using techniques intended to evade anti-money laundering rules. The authority also found that personal data were processed without consent from the actual senders.ITGaranteGDPR€1,430,000
01 Jan 2024Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations.PLUrząd Ochrony Danych OsobowychGDPR€331,000