Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Feb 2023Mindenki Magyarországa MozgalomNAIH imposed a HUF 3,000,000 fine on Mindenki Magyarországa Mozgalom and Márki-Zay Péter for GDPR violations. The authority found inadequate data processing information and failure to respect the right to object in Facebook Messenger communications.HUNAIHGDPR€7,830
29 Dec 2022SOCIETE DE DEVELOPPEMENT DE JEUX MOBILESCNIL imposed a fine of 3,000,000 EUR on SOCIETE DE DEVELOPPEMENT DE JEUX MOBILES. The decision concerns a breach of rules examined by the supervisory authority.FRCNILGDPR€3,000,000
17 Jul 2019Bírák érdek-képviseleti egyesületi tagságra vonatkozó adatának jogellenes kezeléseBudapest Környéki Törvényszék unlawfully processed personal data by listing and sharing association membership information without a proper purpose or legal basis. The authority found a breach of the GDPR principles of purpose limitation and lawful processing.HUNAIHGDPR€9,180
26 Jan 2024Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people.EEAndmekaitse InspektsioonGDPR€3,000,000
10 Apr 2025Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents.ITGaranteGDPR€3,000,000
19 Mar 2026KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes.ISPersónuverndGDPR€20,910
21 Dec 2022Szálláshelyen kamerás megfigyelőrendszer üzemeltetéseThe authority found that the controller unlawfully processed personal data through a camera system, breaching several GDPR provisions. The decision highlighted improper data storage and a lack of transparent information provided to data subjects.HUNAIHGDPR€7,440
02 Mar 2022Közös Nevező 2018 párt és dr. Gődény György aláírásgyűjtéshez kapcsolódó adatkezelésének jogszerűségeThe NAIH imposed a HUF 3,000,000 fine on entities involved in a signature campaign against mandatory vaccinations. The authority found that personal data were collected without meeting GDPR requirements on lawfulness, purpose limitation, transparency, and information provision.HUNAIHGDPR€7,860
25 Apr 2022Budapest Főváros XVIII. kerület Pestszentlőrinc - Pestszentimre ÖnkormányzataThe authority fined the municipality for failing to provide adequate information to data subjects about the collection and use of their personal data. It also found processing of personal and health data without a valid legal basis or proper consent.HUNAIHGDPR€8,010
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner’s Office (ICO) fined Advanced Computer Software Group Limited £3,070,000 for security failings. The issues put the personal information of 79,404 people at risk. The case highlights inadequate safeguards over processed personal data.GBICOGDPR€3,671,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services.GBInformation Commissioner's OfficeGDPR€3,678,000
12 May 2021E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use.ESAEPDGDPR€3,100,000
26 Oct 2021AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards.ESAEPDGDPR€3,300,000
02 Dec 2020Sahlgrenska Universitets­sjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€340,000
30 Dec 2025SOCIETE DU SECTEUR TERTIAIREThe CNIL imposed an administrative fine of EUR 3,500,000 on SOCIETE DU SECTEUR TERTIAIRE. The case concerns a breach of personal data protection rules.FRCNILGDPR€3,500,000
27 Jun 2023A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration.ISPersónuverndGDPR€23,520
17 Oct 2023Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children.ISPersónuverndGDPR€23,905
24 Feb 2025UNICAJA BANCO, S.A.U.UNICAJA BANCO, S.A.U. was fined by the AEPD EUR 3,500,000 for inadequate security measures in its video surveillance system. The authority found a breach of data protection requirements.ESAEPDGDPR€3,500,000
12 Apr 2022Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles.NLAPGDPR€3,700,000
17 Jan 2024Dane anonimowe (V. sp. z o. o. z siedzibą w S. za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 lit. b) i lit. d) i ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 3,819,960 on V. sp. z o.o. for breaches of GDPR rules on data security and confidentiality. The case concerned, among other things, data processing principles, data protection by design, and the implementation of appropriate technical and organizational measures.PLUODOGDPR€868,000