BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Oct 2022 | Alpha Exploration Co. Inc.Alpha Exploration Co. Inc. was fined by the Garante EUR 2,000,000 for violations related to data processing practices on its social media platform, Clubhouse. The case concerned irregularities in the way user data was processed. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 05 Jul 2022 | Üzleti titokra való hivatkozással hanganyag korlátozott felhasználhatósággal történő rendelkezésre bocsátásaThe authority fined the controller for failing to properly handle a data subject request. The case concerned a breach of the obligations under Article 12 GDPR. | HU | NAIH | GDPR | €4,900 | ↗ |
| 05 May 2021 | Munkavállalói e-mail fiókok és munkaeszközök használatával és azok ellenőrzésével összefüggő adatkezelésThe controller did not provide the data subject with adequate prior information about the processing of work email and computer usage. The authority found this to breach the principles of fairness and accountability in data processing. | HU | NAIH | GDPR | €5,560 | ↗ |
| 05 May 2021 | Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification. | HU | NAIH | GDPR | €5,560 | ↗ |
| 13 Aug 2020 | Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis. | HU | NAIH | GDPR | €5,800 | ↗ |
| 19 Mar 2020 | Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle. | HU | NAIH | GDPR | €5,620 | ↗ |
| 15 Nov 2022 | Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000. | HU | NAIH | GDPR | €4,940 | ↗ |
| 19 Mar 2026 | ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards. | IS | Persónuvernd | GDPR | €13,940 | ↗ |
| 11 Apr 2019 | Vincall s.r.l.sVincall s.r.l.s was fined EUR 2,018,000 by the Garante for failing to provide required information to individuals contacted during telemarketing activities. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,018,000 | ↗ |
| 18 Jun 2020 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing. | ES | AEPD | GDPR | €2,100,000 | ↗ |
| 24 Mar 2022 | Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy. | IT | Garante | GDPR | €2,120,000 | ↗ |
| 05 Jun 2025 | 23andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data. | GB | ICO | GDPR | €2,743,000 | ↗ |
| 01 Jan 2024 | UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management. | LT | Valstybinė duomenų apsaugos inspekcija | GDPR | €2,385,000 | ↗ |
| 01 Jan 2025 | Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements. | FI | Tietosuojavaltuutettu | GDPR | €2,400,000 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by NAIH 2,500,000 HUF for publishing personal data without a proper legal basis. The authority also found that the company failed to provide adequate information to the data subjects in connection with the Forbes publication. | HU | NAIH | GDPR | €7,200 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zrt.Mediarey Hungary Services Zrt. was fined by the NAIH 2,500,000 HUF for failing to provide adequate information to data subjects about processing and their rights. The authority also found that the company did not demonstrate compelling legitimate grounds for continued processing after objections were raised. | HU | NAIH | GDPR | €7,200 | ↗ |
| 06 Dec 2023 | ReykjanesbærReykjanesbær was fined by Persónuvernd 2,500,000 ISK for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited the failure to carry out timely data protection impact assessments and to define processing purposes clearly. | IS | Persónuvernd | GDPR | €16,650 | ↗ |
| 16 Mar 2023 | Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33. | NO | Datatilsynet | GDPR | €218,000 | ↗ |
| 10 Feb 2021 | Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act. | SE | IMY | ePrivacy | €248,000 | ↗ |
| 06 Aug 2025 | SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data. | ES | AEPD | GDPR | €2,500,000 | ↗ |