BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2020 | Region ÖstergötlandRegion Östergötland was fined by IMY for failing to perform a needs and risk analysis before granting access rights in its journal system. The authority found that this breached several GDPR provisions. | SE | IMY | GDPR | €243,000 | ↗ |
| 19 Mar 2026 | GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis. | IS | Persónuvernd | GDPR | €17,425 | ↗ |
| 23 Jul 2020 | Mediarey Hungary Services Zártkörűen Működő RészvénytársaságThe NAIH imposed a 2,500,000 HUF fine on Mediarey Hungary Services Zrt. for unlawful data processing related to Forbes magazine publications. The authority found that data subjects were not adequately informed and that their rights to object and erasure were not respected. | HU | NAIH | GDPR | €7,200 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH for failing to report a data breach involving a patient's application form within 72 hours. The authority also found that the organization lacked an internal incident management policy. | HU | NAIH | GDPR | €7,600 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontThe Hungarian Defence Forces Health Centre did not report a data breach within 72 hours and lacked internal incident management procedures. NAIH found this to be a breach of GDPR obligations and imposed a fine of 2,500,000 HUF. | HU | NAIH | GDPR | €7,600 | ↗ |
| 03 Jul 2023 | ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €2,500,000 | ↗ |
| 02 Dec 2020 | Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €243,000 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register. | HU | NAIH | GDPR | €7,600 | ↗ |
| 22 Oct 2025 | SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states. | ES | AEPD | GDPR | €2,600,000 | ↗ |
| 10 Jun 2021 | Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention. | IT | Garante | GDPR | €2,600,000 | ↗ |
| 17 Oct 2025 | Experian Nederland B.V.Experian Nederland B.V. was fined by the AP €2,700,000 for failing to adequately inform data subjects and for processing personal data without a valid legal basis. The case concerns breaches of the GDPR principles of transparency and lawful processing. | NL | AP | GDPR | €2,700,000 | ↗ |
| 01 Oct 2023 | ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company. | NL | Autoriteit Persoonsgegevens | GDPR | €2,700,000 | ↗ |
| 07 Dec 2021 | Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws. | NL | AP | GDPR | €2,750,000 | ↗ |
| 19 Mar 2026 | HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments. | IS | Persónuvernd | GDPR | €19,516 | ↗ |
| 10 Sept 2019 | Dane anonimowe (V. Sp. z o.o. z siedzibą w S. przy ul.)UODO found that V. Sp. z o.o. breached rules on the security and confidentiality of processed personal data. A fine of PLN 2,830,410 was imposed. | PL | UODO | GDPR | €653,000 | ↗ |
| 01 Jan 2019 | Morele.netMorele.net received an administrative fine from the President of the Personal Data Protection Office (UODO) for a GDPR violation. The 2,830,410 PLN penalty followed a phishing attack that led to unauthorized access to customer data affecting about 2.2 million people. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €658,000 | ↗ |
| 13 May 2021 | Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register. | IT | Garante | GDPR | €2,856,000 | ↗ |
| 28 Feb 2024 | Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach. | GR | HDPA | GDPR | €2,995,000 | ↗ |
| 05 Mar 2020 | S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate. | IS | Persónuvernd | GDPR | €21,090 | ↗ |
| 22 Apr 2022 | Magyar Kétfarkú Kutya PártThe Hungarian party Magyar Kétfarkú Kutya Párt was fined by NAIH for failing to implement adequate security measures when storing supporter and activist data. The authority found breaches of GDPR Articles 32 and 5. | HU | NAIH | GDPR | €8,100 | ↗ |