Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Mar 2026Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€6,348,000
10 Jan 2025Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€215
DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych Osobowych€2,568,000
01 Jan 2025Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements.FITietosuojavaltuutettuGDPR€2,400,000
28 Oct 2025Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication.FITietosuojavaltuutetun toimistoGDPR€865,000
01 Jan 2025Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach.FITietosuojavaltuutetun toimistoGDPR€950,000
19 Dec 2025HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved.NOTilsynet for universell utforming av IKTEAA€4,197
05 Jul 2021Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose.FITSVGDPR€25,000
17 Dec 2024Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security.FITSVGDPR€950,000
29 Apr 2022TelemarkkinointiyritysA telemarketing company was fined for failing to comply with a Data Protection Ombudsman's order to provide a data subject access to a call recording. The case concerned a breach of GDPR Article 15 on the right of access.FITSVGDPR€8,300
23 Jul 2020Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed.FITSVGDPR€7,000
16 Dec 2021LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles.FITSVGDPR€52,000
21 Apr 2021ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights.FITSVGDPR€70,000
19 Jan 2023Sąd Rejonowy Szczecin-Centrum z siedzibą w Szczecinie przy ul.The UODO imposed an administrative fine of PLN 30,000 on the Szczecin-Centrum District Court. The authority found that appropriate technical and organizational measures were not implemented to match the risk of processing data using portable storage devices.PLUODOGDPR€6,374
02 Sept 2024Prokuraturę KrajowąUODO imposed an administrative fine of 85,000 PLN on the National Prosecutor's Office for breaches of Article 6(1), Article 9(1), Article 33(1), and Article 34(1) and (2) of the GDPR. The authority also ordered notification of the affected data subjects.PLUODOGDPR€19,883
29 Dec 2022Dane anonimowe (S. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 36,558 on the company. The sanction concerned failure to cooperate with the authority and failure to provide information necessary for the performance of its tasks.PLUODOGDPR€7,802
07 Apr 2026Dane anonimowe (Wspólnotę Mieszkaniową K.)The UODO imposed an administrative fine on K. Housing Community for failing to report a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to notify the President of the UODO within the statutory deadline.PLUODOGDPR€1,135
06 Jul 2022Uniwersyteckie CentrumThe Polish DPA (UODO) imposed an administrative fine of PLN 10,000 on Uniwersyteckie Centrum Kliniczne Uniwersytetu Medycznego. The authority found that the entity failed to report the personal data breach without undue delay and did not notify the affected individuals without undue delay.PLUODOGDPR€2,096
15 Nov 2025Państwowego Powiatowego Inspektora Sanitarnego w M., ul.UODO imposed a PLN 20,000 administrative fine on the State District Sanitary Inspector in M. The authority found that appropriate technical and organizational measures based on a risk assessment were not implemented, and that the effectiveness of safeguards for data processed on external media was not regularly tested. The case concerned a breach of the integrity and confidentiality principle.PLUODOGDPR€4,725
16 May 2023Dane anonimowe (Burmistrza Miasta Z.)UODO imposed an administrative fine of PLN 30,000 on the Mayor of City Z. and ordered the processing operations to be brought into compliance with the GDPR. The authority required appropriate technical and organizational measures, including regular testing, measuring, and evaluating their effectiveness to ensure processing security.PLUODOGDPR€6,687