BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Nov 2022 | ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 16 Jul 2025 | Georgescu CălinThe operator Georgescu Călin was fined by ANSPDCP in the amount of EUR 4,000 for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 05 Feb 2024 | Asociație de proprietari din Miercurea CiucIn January 2024, ANSPDCP completed an investigation at a homeowners’ association in Miercurea Ciuc and found a breach of GDPR provisions. The operator was fined EUR 500. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 22 Apr 2024 | S.C. Tensa Art Design S.A.In April 2024, ANSPDCP completed an investigation into S.C. Tensa Art Design S.A., the operator of www.lensa.ro. The authority found GDPR violations and imposed a fine of EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 19 Sept 2022 | Vodafone România SAVodafone România SA was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 29 May 2026 | Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 11 May 2023 | Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 07 Jul 2025 | Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 20 Oct 2025 | S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 10 Mar 2022 | Briza Land S.R.L.The National Supervisory Authority completed an investigation on 24.02.2022 at Briza Land S.R.L. and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Nov 2022 | SC Prestige Media PHG SRLSC Prestige Media PHG SRL was fined by ANSPDCP in the amount of 5,000 EUR for breaching the data processing principles under Article 5 of the GDPR. The case concerned unlawful processing of personal data. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 30 Apr 2025 | BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 30 Jun 2022 | Continental Automotive Romania SRLThe company was fined for failing to implement adequate technical and organizational measures and for not periodically assessing those measures in relation to employee video processing. The breach concerned the security of video processing and the prevention of unauthorized processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 18 Dec 2024 | Electrica Furnizare S.A.The National Supervisory Authority for Personal Data Processing completed an investigation in November 2024 at Electrica Furnizare S.A. and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 06 Mar 2023 | Finopro IFN SAFinopro IFN SA was fined by ANSPDCP EUR 2,250 for a data security breach caused by a ransomware attack. The incident led to unauthorized access and loss of integrity and availability of personal data. | RO | ANSPDCP | GDPR | €2,250 | ↗ |
| 02 Dec 2020 | Sahlgrenska UniversitetssjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €340,000 | ↗ |
| 11 May 2020 | Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32. | SE | IMY | GDPR | €11,321 | ↗ |
| 07 Jun 2021 | Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000. | SE | IMY | GDPR | €64,643 | ↗ |
| 28 Mar 2022 | Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making. | SE | IMY | GDPR | €719,000 | ↗ |
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |