Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Dec 2024OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs.ITGarante per la protezione dei dati personaliGDPR€15,000,000
08 Jan 2026OPÉRATEUR DE TÉLÉPHONIE FIXECNIL imposed an administrative fine of EUR 15 million on a fixed-line telecom operator and issued an injunction. The case concerns a breach requiring corrective action and compliance with regulatory obligations.FRCNILGDPR€15,000,000
02 Dec 2020Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements.SEIMYGDPR€1,458,000
21 Feb 2025Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches.ATÖsterreichische DatenschutzbehördeGDPR€16,000,000
23 Jun 2023BKM Budapesti Közművek Nonprofit Zrt.NAIH imposed a 16,000,000 HUF fine on BKM Budapesti Közművek Nonprofit Zrt. for failing to implement adequate technical and organizational measures to protect data security. The authority also found deficiencies in the reporting of a personal data breach.HUNAIHGDPR€43,200
21 Jun 2021Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization.SEIMYGDPR€1,566,000
09 Jul 2020Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing.ITGaranteGDPR€16,729,000
23 Jun 2025McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures.PLPresident of the Personal Data Protection OfficeGDPR€3,960,000
15 Mar 2022Meta (Facebook)The Irish DPC fined Meta (Facebook) EUR 17,000,000 in case IN-18-11-5. The penalty has been collected.IEDPCGDPR€17,000,000
27 Aug 2025INGPoland’s data protection authority, UODO, fined ING more than PLN 18 million. The authority found that the bank scanned identity documents in situations not required by AML rules, including for non-customers and in cases unrelated to service provision.PLUrząd Ochrony Danych OsobowychGDPR€4,215,000
23 Jul 2025Dane anonimowe (K.)UODO imposed an administrative fine of PLN 18,416,400 for processing personal data without a lawful basis. The case concerned copying and scanning customers’ identity documents without properly verifying whether this was justified by AML obligations.PLUODOGDPR€4,328,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified.NODatatilsynetGDPR€1,730,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data.NODatatilsynetGDPR€1,730,000
17 Oct 2022SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a EUR 20 million fine on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE and issued an injunction subject to a penalty. The case concerned identified data protection breaches.FRCNILGDPR€20,000,000
09 Dec 2020ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident.HUNAIHGDPR€56,000
04 Jun 2026ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing.NODatatilsynetGDPR€1,844,000
28 Nov 2023Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data.NODatatilsynetGDPR€1,707,000
03 Sept 2020Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data.HUNAIHGDPR€55,800
05 May 2021Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data.NODatatilsynetGDPR€2,503,000
29 May 2026IndaNext Hungary Korlátolt Felelősségű TársaságNAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12.HUNAIHGDPR€70,750