Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Nov 2024Dane anonimowe (A. z siedzibą w W. przy ul.)The Polish DPA (UODO) imposed administrative fines on the controller and the processor for breaches of GDPR obligations. The case concerned, among others, integrity and confidentiality, accountability, data protection by design, processor arrangements, and security measures.PLUODOGDPR€351,000
02 Feb 2017Yume s.r.l.Yume s.r.l. was fined by the Garante in the amount of 1,590,000 EUR for improper processing of personal data during money transfer operations. The authority found that techniques were used to obscure the true identity of the initiators of financial transactions.ITGaranteGDPR€1,590,000
11 Jan 2023BBVABBVA was fined by the AEPD EUR 1,640,000 for multiple data protection violations. The case involved unauthorized payment operations and improper handling of personal data in credit information systems.ESAEPDGDPR€1,640,000
22 Dec 2025NEXPUBLICA FRANCECNIL imposed a fine of 1,700,000 EUR on NEXPUBLICA FRANCE on 2025-12-22. The decision concerns serious security failures under Article 32 GDPR in the PCRM software used by public social action bodies, which processed sensitive personal data.FRCNILGDPR€1,700,000
22 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUESCNIL imposed an administrative fine of 1,700,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES. The decision concerns a breach of rules supervised by the French data protection authority.FRCNILGDPR€1,700,000
10 Sept 2025S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach.FIOffice of the Data Protection OmbudsmanGDPR€1,800,000
03 Dec 2020Dane anonimowe (W. Polska Sp. z o.o. z siedzibą w G.)UODO imposed a fine of PLN 1,968,524 on W. Polska Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing subscribers’ personal data in IT systems.PLUODOGDPR€440,000
20 Jul 2023Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed.HUNAIHGDPR€5,280
01 Oct 2023Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data.GBInformation Commissioner's OfficeGDPR€2,313,000
23 Jul 2020Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe authority found that Mediarey Hungary Services Zrt. unlawfully processed personal data related to Forbes magazine publications. It also failed to adequately inform data subjects about their rights, resulting in breaches of several GDPR provisions.HUNAIHGDPR€5,760
22 Jan 2020Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000.HUNAIHGDPR€5,960
07 Mar 2024CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent.ESAEPDGDPR€2,000,000
06 Aug 2020Hozzáférési jog, adatpontosság és átláthatóság elvének megsértéseThe decision concerned unlawful processing of personal data during debt collection and breaches of access rights and information obligations under the GDPR. Both entities involved in the case were fined for their actions.HUNAIHGDPR€5,780
08 Apr 2025Adatbiztonsági problémák ügyféladatbázis adatfeldolgozó általi költöztetése soránThe authority found that Ügyfél1 failed to implement appropriate security measures when processing data during the database migration. This breach of GDPR Article 32 resulted in a fine of 2,000,000 HUF.HUNAIHGDPR€4,920
20 Feb 2026Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization.HUNAIHGDPR€5,260
22 Oct 2020Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access.HUNAIHGDPR€5,480
12 Feb 2026Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls.ITGaranteGDPR€2,000,000
23 Dec 2024HYUNDAI MOTOR ESPAÑA S.L.U.HYUNDAI MOTOR ESPAÑA S.L.U. was fined EUR 2,000,000 by the AEPD for a data security incident. Unauthorized access to customer data occurred, breaching data protection principles.ESAEPDGDPR€2,000,000
23 Jul 2020Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,000,000 HUF for insufficient data protection measures in its Forbes publications. The authority also found that data subjects were not adequately informed and that several GDPR provisions were breached.HUNAIHGDPR€5,760
24 Jan 2022Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff.NODatatilsynetGDPR€196,000