BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 May 2026 | KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service. | GB | ICO | ePrivacy | €346,000 | ↗ |
| 29 Aug 2024 | EDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTSEDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTS was fined EUR 300,000 by the CNIL. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €300,000 | ↗ |
| 08 Aug 2022 | Hangfelvétel készítése szerelési munkák soránThe authority found that the entity breached the GDPR by recording audio during installation work without a proper legal basis. It also failed to meet transparency and data protection principle requirements. | HU | NAIH | GDPR | €762 | ↗ |
| 01 Jan 2021 | PAGE GROUP EUROPEPAGE GROUP EUROPE was fined by the AEPD 300,000 EUR for breaches of GDPR principles on data minimization and transparency. The case concerned the improper handling of a data subject access request submitted through its Dutch website. | ES | AEPD | GDPR | €300,000 | ↗ |
| 23 May 2019 | Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR. | HU | NAIH | GDPR | €918 | ↗ |
| 21 Mar 2024 | Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.). | HU | NAIH | GDPR | €762 | ↗ |
| 01 Jan 2024 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for issuing a duplicate SIM card without proper consent or identity verification. The failure enabled identity theft and fraudulent transactions. | ES | AEPD | GDPR | €300,000 | ↗ |
| 08 Sept 2021 | Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center. | DK | Datatilsynet | GDPR | €40,344 | ↗ |
| 09 Mar 2020 | Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing. | HU | NAIH | GDPR | €891 | ↗ |
| 23 May 2019 | Telenor Magyarország Zrt.Telenor Magyarország Zrt. was fined by the Hungarian NAIH 300,000 HUF for failing to comply with a data subject access request under the GDPR. The authority also found that the company did not inform the data subject of the right to an effective legal remedy. | HU | NAIH | GDPR | €918 | ↗ |
| 15 Dec 2021 | Anonymizováno (ÚOOÚ UOOU-01071/21-30)The entity was fined by the UOOU for repeatedly sending unsolicited commercial communications to electronic contacts without prior consent. The messages also failed to clearly identify the sender or label the content as commercial. | CZ | UOOU | ePrivacy | €11,871 | ↗ |
| 28 Aug 2025 | Home Improvement Marketing LtdHome Improvement Marketing Ltd was investigated by the ICO as part of a wider review of complaint trends in the energy and home improvements sector. After a search warrant and extensive investigation, the ICO found that between 31 May 2023 and 31 August 2023 the company initiated 2,449,380 automated marketing calls to subscribers without prior consent, contrary to PECR. The conduct generated 274 complaints to the TPS and ICO reporting tools. | GB | ICO | ePrivacy | €347,000 | ↗ |
| 01 Oct 2024 | IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine. | ES | AEPD | GDPR | €300,000 | ↗ |
| 28 Nov 2023 | Barn- och utbildningsnämnden, Östersunds kommunBarn- och utbildningsnämnden in Östersunds kommun was fined by IMY for failing to conduct a data protection impact assessment before deploying Google Workspace for Education in 24 schools. The authority found this to be a breach of Article 35 GDPR. | SE | IMY | GDPR | €26,241 | ↗ |
| 08 May 2014 | Telextra s.r.l.Telextra s.r.l. was fined by the Garante for processing personal data from electronic communication operators' databases without consent. The authority also found non-compliance with previous orders and data protection requirements. | IT | Garante | GDPR | €300,000 | ↗ |
| 09 Jun 2022 | Webáruház adatkezelési tájékoztatójaThe authority found a GDPR breach because the website and online store did not provide clear and transparent information about personal data processing. A fine of 300,000 HUF was imposed. | HU | NAIH | GDPR | Ft 300,000 | ↗ |
| 01 Jan 2026 | Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €300,000 | ↗ |
| 22 Apr 2022 | DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules. | ES | AEPD | GDPR | €300,000 | ↗ |
| 14 Mar 2022 | Tullverket, tjänstemobilerThe Swedish Customs Agency (Tullverket) was fined by IMY 300,000 SEK for failing to implement adequate technical and organizational measures. This led to unauthorized storage of personal data in a cloud service. | SE | IMY | ePrivacy | €28,473 | ↗ |
| 03 Dec 2021 | Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR. | HU | NAIH | GDPR | €825 | ↗ |