Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Jun 2021Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights.HUNAIHGDPR€28,100
24 Mar 2021Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals.HUNAIHGDPR€27,400
03 Sept 2025AENA, S.M.E., S.A.The AEPD imposed a fine of EUR 10,043,002 on AENA, S.M.E., S.A. for processing passenger personal data in a manner deemed unnecessary and disproportionate. The authority found that the company’s practices breached data protection rules.ESAEPDGDPR€10,043,000
21 Mar 2019Demokratikus KoalícióThe Democratic Coalition was fined by NAIH 11,000,000 HUF for failing to meet incident notification and data subject communication obligations. The case involved a data breach affecting high-risk special category data.HUNAIHGDPR€34,980
21 Mar 2019Demokratikus KoalícióDemocratic Coalition was fined HUF 11,000,000 by the NAIH for failing to report a personal data breach. The authority also found that affected individuals were not informed, contrary to GDPR Articles 33 and 34.HUNAIHGDPR€34,980
DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych Osobowych€2,568,000
07 Jun 2021MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing.SEIMYGDPR€1,193,000
02 Dec 2020Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements.SEIMYGDPR€1,167,000
27 Jun 2023embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards.ISPersónuverndGDPR€80,640
12 Nov 2020Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined by the Garante 12,251,601 EUR for making unauthorized promotional calls and sending messages. The authority also found that effective measures to ensure data processing security and GDPR compliance were not in place.ITGaranteGDPR€12,251,000
01 Apr 2023TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully.GBInformation Commissioner's OfficeGDPR€14,444,000
15 May 2023TikTok Information Technologies UK Limited and TikTok Inc (TikTok)The UK ICO imposed a fine of 12,700,000 GBP on TikTok Information Technologies UK Limited and TikTok Inc for multiple breaches of data protection law. The regulator specifically cited unlawful use of children’s personal data.GBICOGDPR€14,607,000
04 Feb 2025Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate.SEIntegritetsskyddsmyndighetenGDPR€1,138,000
26 Jun 2023Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes.SEIMYGDPR€1,112,000
10 Oct 2025Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts.GBInformation Commissioner's OfficeGDPR€16,074,000
15 Oct 2025CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance.GBInformation Commissioner's OfficeGDPR€16,083,000
15 Oct 2025Capita plc and Capita Pension Solutions LtdThe UK Information Commissioner’s Office fined Capita plc and Capita Pension Solutions Ltd a combined £14m after a cyber attack in April 2023. Hackers gained access to the data of more than 6 million people. The case highlights serious weaknesses in data protection and incident response.GBICOGDPR€16,083,000
23 Feb 2026Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment.GBICOGDPR€16,571,000
24 Feb 2026Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice.GBInformation Commissioner's OfficeGDPR€16,606,000
25 Jun 2024AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta.SEIMYGDPR€1,336,000