Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Mar 2020Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
17 Aug 2021UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers.DKDatatilsynetGDPR€20,171
16 Dec 2021Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties.ITGaranteGDPR€100,000
31 Jan 2024Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements.NLAPGDPR€10,000,000
26 Aug 2024Uber Technologies Inc.Uber Technologies Inc. was fined by the Dutch data protection authority AP in the amount of EUR 290,000,000. The authority found that the company transferred personal data to the United States without appropriate safeguards, in breach of Article 44 GDPR.NLAPGDPR€290,000,000
24 Mar 2022Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy.ITGaranteGDPR€2,120,000
25 Sept 2023UAT Comuna AlbeniANSPDCP imposed a 10,000 RON fine on UAT Comuna Albeni for failing to implement measures previously ordered by the authority. The entity also did not respond to the authority’s requests.ROANSPDCPGDPR€2,013
01 Jan 2024UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management.LTValstybinė duomenų apsaugos inspekcijaGDPR€2,385,000
10 Oct 2023UAB RamidonasThe supervisory authority imposed a €6,000 fine on UAB Ramidonas for personal data security violations. The case concerned deficiencies in data protection controls that could have exposed individuals’ information to risk.LTValstybinė duomenų apsaugos inspekcijaGDPR€6,000
27 Feb 2026T., za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,The Polish DPA (UODO) imposed an administrative fine of PLN 975 on T. for failing to implement appropriate technical and organizational measures and for lacking a proper, accountable data protection policy tailored to its processing activities. The authority also noted deficiencies in transparency notices, processor agreements, access authorizations, and the record of processing activities.PLUODOGDPR€231
01 Jan 2019TWITTER INTERNATIONAL COMPANY (TWITTER SPAIN, S.L.)Twitter International Company (Twitter Spain, S.L.) was fined EUR 30,000 by the AEPD. The authority found inadequate cookie information and the use of cookies without obtaining user consent, in breach of the LSSI.ESAEPDePrivacy€30,000
09 Dec 2020Twitter International CompanyThe Irish DPC imposed a fine of EUR 450,000 on Twitter International Company in inquiry IN-19-1-1. The fine was collected.IEDPCGDPR€450,000
26 Sept 2022TV2 Média Csoport Zrt.NAIH imposed a 10,000,000 HUF fine on TV2 Média Csoport Zrt. for insufficient user information and improper consent management on its websites. The authority found that these practices breached the principles of fair and transparent data processing.HUNAIHGDPR€24,500
12 Aug 2020TuslaThe Irish DPC fined Tusla EUR 85,000 in inquiry IN-18-11-4. The fine has been collected.IEDPCGDPR€85,000
21 May 2020TuslaThe Irish DPC imposed a fine of EUR 40,000 on Tusla in case IN-19-12-8. The fine was collected.IEDPCGDPR€40,000
14 Mar 2022Tullverket, tjänstemobilerThe Swedish Customs Agency (Tullverket) was fined by IMY 300,000 SEK for failing to implement adequate technical and organizational measures. This led to unauthorized storage of personal data in a cloud service.SEIMYePrivacy€28,473
27 Jan 2022T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights.ITGaranteGDPR€40,000
20 Jun 2024TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€10,000
28 Aug 2023Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1).SEIMYGDPR€2,941,000
01 Oct 2023TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated.ITItalian Competition Authority (AGCM)Omnibus€4,000,000