BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 May 2019 | Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33. | HU | NAIH | GDPR | €306 | ↗ |
| 04 Oct 2019 | Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance. | HU | NAIH | GDPR | €15,050 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register. | HU | NAIH | GDPR | €7,600 | ↗ |
| 15 May 2026 | Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €19,460 | ↗ |
| 16 Apr 2026 | An unnamed energy companyHungary’s data protection authority, NAIH, imposed a HUF 75 million GDPR fine in case NAIH-19-18/2024 on an unnamed energy company. The case concerned data processing for a nationwide LED replacement program and identified serious privacy compliance failures. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €205,000 | ↗ |
| 11 Feb 2025 | A követeléskezelő társaságNAIH imposed a HUF 10 million fine on a debt collection company for continuing to process personal data after a court declared the debt time-barred. The company ignored the data subject’s deletion request and kept the case active in its system. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €24,800 | ↗ |
| 01 Jan 2024 | Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €130,000 | ↗ |
| 25 Sept 2025 | JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes. | GG | ODPA | GDPR | €74,302 | ↗ |
| 20 Oct 2025 | The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data. | GG | ODPA | GDPR | €115,000 | ↗ |
| 10 Sept 2025 | S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach. | FI | Office of the Data Protection Ombudsman | GDPR | €1,800,000 | ↗ |
| 04 Jun 2025 | Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta. | FI | Office of the Data Protection Ombudsman | GDPR | €1,100,000 | ↗ |
| 21 Feb 2025 | Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches. | AT | Österreichische Datenschutzbehörde | GDPR | €16,000,000 | ↗ |
| 05 Mar 2020 | S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate. | IS | Persónuvernd | GDPR | €21,090 | ↗ |
| 02 May 2023 | KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards. | IS | Persónuvernd | GDPR | €26,720 | ↗ |
| 06 Sept 2023 | Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations. | IS | Persónuvernd | GDPR | €10,425 | ↗ |
| 06 Dec 2023 | ReykjanesbærReykjanesbær was fined by Persónuvernd 2,500,000 ISK for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited the failure to carry out timely data protection impact assessments and to define processing purposes clearly. | IS | Persónuvernd | GDPR | €16,650 | ↗ |
| 19 Mar 2026 | HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments. | IS | Persónuvernd | GDPR | €19,516 | ↗ |
| 19 Mar 2026 | GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis. | IS | Persónuvernd | GDPR | €17,425 | ↗ |
| 23 Nov 2021 | atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance. | IS | Persónuvernd | GDPR | €50,850 | ↗ |
| 05 Mar 2020 | Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security. | IS | Persónuvernd | GDPR | €9,139 | ↗ |