BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Mar 2024 | Dane anonimowe (U.)An administrative fine was imposed for failing to notify the supervisory authority of a personal data breach within the required 72 hours after detection. The authority also found that the affected individuals were not informed without undue delay. | PL | UODO | GDPR | €336,000 | ↗ |
| 20 May 2024 | Dane anonimowe (A. Spółka Akcyjna z siedzibą w U., ul.)UODO imposed an administrative fine of PLN 1,440,549 on A. Spółka Akcyjna. The authority found breaches of the integrity and confidentiality principle and the obligation to implement appropriate data security measures. | PL | UODO | GDPR | €338,000 | ↗ |
| 10 Oct 2023 | American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 06 Sept 2023 | Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations. | IS | Persónuvernd | GDPR | €10,425 | ↗ |
| 16 Aug 2024 | D*** Handels Ges.m.b.H.D*** Handels Ges.m.b.H. was fined by the DSB for unlawfully processing personal data through a video surveillance system without a legal basis. The authority also found a breach of the data minimization principle. | AT | DSB | GDPR | €1,500,000 | ↗ |
| 05 Feb 2026 | Óbudai EgyetemÓbudai Egyetem was fined by the NAIH 1,500,000 HUF for breaching the principles of transparency and data minimization. The authority also found no lawful basis for processing and that the conditions for processing special categories of data were not met. | HU | NAIH | GDPR | €3,945 | ↗ |
| 02 Aug 2023 | Adatbázisban tárolt személyes adatok kezelésének jogszerűségeThe entity was fined by NAIH HUF 1,500,000 for processing personal data without a legal basis. The authority also found that the entity failed to demonstrate compliance with data processing requirements and did not provide adequate information to data subjects. | HU | NAIH | GDPR | €3,870 | ↗ |
| 01 Jan 2024 | ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €1,500,000 | ↗ |
| 15 Feb 2021 | KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF. | HU | NAIH | GDPR | €4,185 | ↗ |
| 11 Nov 2019 | Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség, adattakarékosság és átláthatóság elvének megsértéseThe supervisory authority found that the controller did not comply with requests to erase personal data and unlawfully processed phone numbers. It also identified breaches of purpose limitation, data minimization, and transparency principles. | HU | NAIH | GDPR | €4,485 | ↗ |
| 01 Feb 2024 | Capio A/SThe Danish Data Protection Authority reported Capio A/S to the police and recommended a fine of at least DKK 1,500,000. The case concerned insufficient supervision of data processors, breaching the GDPR accountability principle. | DK | Datatilsynet | GDPR | €201,000 | ↗ |
| 27 Nov 2025 | AMERICAN EXPRESS CARTE FRANCEOn 27 November 2025, CNIL fined AMERICAN EXPRESS CARTE FRANCE EUR 1.5 million for breaches of cookie and tracker rules. The authority found that trackers were placed without consent, despite refusal, and continued to be read after consent was withdrawn. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 30 Jan 2026 | Magyar Agrár- és Élettudományi EgyetemThe Hungarian University of Agriculture and Life Sciences was fined by the NAIH for negligent GDPR violations in its dormitory admissions data processing. The authority cited a lack of proper legal basis, insufficient prior information, and failure to apply data minimization. | HU | NAIH | GDPR | €3,945 | ↗ |
| 27 Nov 2025 | SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERECNIL imposed an administrative fine of 1 500 000 EUR on SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 15 Apr 2022 | SOCIETE D'EDITION DE LOGICIELS APPLICATIFSCNIL imposed a fine of 1,500,000 EUR on SOCIETE D'EDITION DE LOGICIELS APPLICATIFS. The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 20 Mar 2024 | Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights. | IS | Persónuvernd | GDPR | €10,095 | ↗ |
| 14 May 2020 | Anonymizováno (ÚOOÚ UOOU-1936/19-68)The entity was fined 1,500,000 CZK by the UOOU. The authority found that required corrective measures under the Czech Data Processing Act were not implemented. | CZ | UOOU | GDPR | €54,405 | ↗ |
| 02 May 2023 | InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords. | CZ | UOOU | GDPR | €63,600 | ↗ |
| 03 May 2022 | HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made. | IS | Persónuvernd | GDPR | €10,905 | ↗ |
| 11 Sept 2025 | ILVA A/SVestre Landsret upheld a DKK 1.5 million GDPR fine against ILVA A/S. The case concerned retention of data on about 385,000 customers without a deletion policy, and the fine was based on the group’s total turnover. | DK | Datatilsynet | GDPR | €200,000 | ↗ |