Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jun 2023A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration.ISPersónuverndGDPR€23,520
08 Mar 2022Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ISPersónuverndGDPR€6,850
20 Mar 2024Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights.ISPersónuverndGDPR€10,095
19 Mar 2026KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes.ISPersónuverndGDPR€20,910
27 Jun 2023Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data.ISPersónuverndGDPR€254,000
03 May 2022ReykjavíkurborgReykjavíkurborg was fined ISK 5,000,000 by Persónuvernd for using the Seesaw student system in schools without adequate data protection measures. The case concerned children’s personal data and transfers of data to the United States.ISPersónuverndGDPR€36,350
15 Jun 2021Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance.ISPersónuverndGDPR€33,950
17 Feb 2025Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing.ISPersónuverndGDPR€34,050
17 Oct 2023Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children.ISPersónuverndGDPR€23,905
27 Jun 2023embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards.ISPersónuverndGDPR€80,640
27 Jun 2023eCommerce 2020 ApSeCommerce 2020 ApS was fined by Persónuvernd in the amount of 7,500,000 ISK for registering loan defaults with Creditinfo Lánstrausti hf. without meeting the required conditions. The authority noted, among other issues, that claims below the minimum threshold were registered. The case concerns improper handling of debt-related personal data.ISPersónuverndGDPR€50,400
03 May 2022HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made.ISPersónuverndGDPR€10,905
19 Mar 2026ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards.ISPersónuverndGDPR€13,940
04 Apr 2025Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations.PLPolish Data Protection AuthorityGDPR€928,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000
23 Jul 2025ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR.PLPresident of the Personal Data Protection OfficeGDPR€4,375,000
23 Jun 2025McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures.PLPresident of the Personal Data Protection OfficeGDPR€3,960,000
18 Dec 2024Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations.PLPresident of the Personal Data Protection Office (UODO)GDPR€132,000
01 Jan 2019Morele.netMorele.net received an administrative fine from the President of the Personal Data Protection Office (UODO) for a GDPR violation. The 2,830,410 PLN penalty followed a phishing attack that led to unauthorized access to customer data affecting about 2.2 million people.PLPresident of the Personal Data Protection Office (UODO)GDPR€658,000
01 Nov 2025Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late.PLPresident of the Personal Data Protection Office (UODO)GDPR€20,110