BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Jun 2021 | Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights. | HU | NAIH | GDPR | €28,100 | ↗ |
| 24 Mar 2021 | Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals. | HU | NAIH | GDPR | €27,400 | ↗ |
| 03 Sept 2025 | AENA, S.M.E., S.A.The AEPD imposed a fine of EUR 10,043,002 on AENA, S.M.E., S.A. for processing passenger personal data in a manner deemed unnecessary and disproportionate. The authority found that the company’s practices breached data protection rules. | ES | AEPD | GDPR | €10,043,000 | ↗ |
| 21 Mar 2019 | Demokratikus KoalícióThe Democratic Coalition was fined by NAIH 11,000,000 HUF for failing to meet incident notification and data subject communication obligations. The case involved a data breach affecting high-risk special category data. | HU | NAIH | GDPR | €34,980 | ↗ |
| 21 Mar 2019 | Demokratikus KoalícióDemocratic Coalition was fined HUF 11,000,000 by the NAIH for failing to report a personal data breach. The authority also found that affected individuals were not informed, contrary to GDPR Articles 33 and 34. | HU | NAIH | GDPR | €34,980 | ↗ |
| — | DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security. | PL | Prezes Urzędu Ochrony Danych Osobowych | — | €2,568,000 | ↗ |
| 07 Jun 2021 | MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing. | SE | IMY | GDPR | €1,193,000 | ↗ |
| 02 Dec 2020 | Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements. | SE | IMY | GDPR | €1,167,000 | ↗ |
| 27 Jun 2023 | embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards. | IS | Persónuvernd | GDPR | €80,640 | ↗ |
| 12 Nov 2020 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined by the Garante 12,251,601 EUR for making unauthorized promotional calls and sending messages. The authority also found that effective measures to ensure data processing security and GDPR compliance were not in place. | IT | Garante | GDPR | €12,251,000 | ↗ |
| 01 Apr 2023 | TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully. | GB | Information Commissioner's Office | GDPR | €14,444,000 | ↗ |
| 15 May 2023 | TikTok Information Technologies UK Limited and TikTok Inc (TikTok)The UK ICO imposed a fine of 12,700,000 GBP on TikTok Information Technologies UK Limited and TikTok Inc for multiple breaches of data protection law. The regulator specifically cited unlawful use of children’s personal data. | GB | ICO | GDPR | €14,607,000 | ↗ |
| 04 Feb 2025 | Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate. | SE | Integritetsskyddsmyndigheten | GDPR | €1,138,000 | ↗ |
| 26 Jun 2023 | Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes. | SE | IMY | GDPR | €1,112,000 | ↗ |
| 10 Oct 2025 | Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts. | GB | Information Commissioner's Office | GDPR | €16,074,000 | ↗ |
| 15 Oct 2025 | CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance. | GB | Information Commissioner's Office | GDPR | €16,083,000 | ↗ |
| 15 Oct 2025 | Capita plc and Capita Pension Solutions LtdThe UK Information Commissioner’s Office fined Capita plc and Capita Pension Solutions Ltd a combined £14m after a cyber attack in April 2023. Hackers gained access to the data of more than 6 million people. The case highlights serious weaknesses in data protection and incident response. | GB | ICO | GDPR | €16,083,000 | ↗ |
| 23 Feb 2026 | Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment. | GB | ICO | GDPR | €16,571,000 | ↗ |
| 24 Feb 2026 | Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice. | GB | Information Commissioner's Office | GDPR | €16,606,000 | ↗ |
| 25 Jun 2024 | AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta. | SE | IMY | GDPR | €1,336,000 | ↗ |