BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Dec 2024 | OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs. | IT | Garante per la protezione dei dati personali | GDPR | €15,000,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE FIXECNIL imposed an administrative fine of EUR 15 million on a fixed-line telecom operator and issued an injunction. The case concerns a breach requiring corrective action and compliance with regulatory obligations. | FR | CNIL | GDPR | €15,000,000 | ↗ |
| 02 Dec 2020 | Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements. | SE | IMY | GDPR | €1,458,000 | ↗ |
| 21 Feb 2025 | Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches. | AT | Österreichische Datenschutzbehörde | GDPR | €16,000,000 | ↗ |
| 23 Jun 2023 | BKM Budapesti Közművek Nonprofit Zrt.NAIH imposed a 16,000,000 HUF fine on BKM Budapesti Közművek Nonprofit Zrt. for failing to implement adequate technical and organizational measures to protect data security. The authority also found deficiencies in the reporting of a personal data breach. | HU | NAIH | GDPR | €43,200 | ↗ |
| 21 Jun 2021 | Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization. | SE | IMY | GDPR | €1,566,000 | ↗ |
| 09 Jul 2020 | Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing. | IT | Garante | GDPR | €16,729,000 | ↗ |
| 23 Jun 2025 | McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures. | PL | President of the Personal Data Protection Office | GDPR | €3,960,000 | ↗ |
| 15 Mar 2022 | Meta (Facebook)The Irish DPC fined Meta (Facebook) EUR 17,000,000 in case IN-18-11-5. The penalty has been collected. | IE | DPC | GDPR | €17,000,000 | ↗ |
| 27 Aug 2025 | INGPoland’s data protection authority, UODO, fined ING more than PLN 18 million. The authority found that the bank scanned identity documents in situations not required by AML rules, including for non-customers and in cases unrelated to service provision. | PL | Urząd Ochrony Danych Osobowych | GDPR | €4,215,000 | ↗ |
| 23 Jul 2025 | Dane anonimowe (K.)UODO imposed an administrative fine of PLN 18,416,400 for processing personal data without a lawful basis. The case concerned copying and scanning customers’ identity documents without properly verifying whether this was justified by AML obligations. | PL | UODO | GDPR | €4,328,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 17 Oct 2022 | SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a EUR 20 million fine on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE and issued an injunction subject to a penalty. The case concerned identified data protection breaches. | FR | CNIL | GDPR | €20,000,000 | ↗ |
| 09 Dec 2020 | ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident. | HU | NAIH | GDPR | €56,000 | ↗ |
| 04 Jun 2026 | ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing. | NO | Datatilsynet | GDPR | €1,844,000 | ↗ |
| 28 Nov 2023 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data. | NO | Datatilsynet | GDPR | €1,707,000 | ↗ |
| 03 Sept 2020 | Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data. | HU | NAIH | GDPR | €55,800 | ↗ |
| 05 May 2021 | Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data. | NO | Datatilsynet | GDPR | €2,503,000 | ↗ |
| 29 May 2026 | IndaNext Hungary Korlátolt Felelősségű TársaságNAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12. | HU | NAIH | GDPR | €70,750 | ↗ |