Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Nov 2022ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller.ROANSPDCPGDPR€20,000
16 Jul 2025Georgescu CălinThe operator Georgescu Călin was fined by ANSPDCP in the amount of EUR 4,000 for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€4,000
05 Feb 2024Asociație de proprietari din Miercurea CiucIn January 2024, ANSPDCP completed an investigation at a homeowners’ association in Miercurea Ciuc and found a breach of GDPR provisions. The operator was fined EUR 500.ROANSPDCPGDPR€500
22 Apr 2024S.C. Tensa Art Design S.A.In April 2024, ANSPDCP completed an investigation into S.C. Tensa Art Design S.A., the operator of www.lensa.ro. The authority found GDPR violations and imposed a fine of EUR 2,000.ROANSPDCPGDPR€2,000
19 Sept 2022Vodafone România SAVodafone România SA was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
29 May 2026Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments.ROANSPDCPGDPR€10,000
11 May 2023Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€10,000
07 Jul 2025Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party.ROANSPDCPGDPR€15,000
20 Oct 2025S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information.ROANSPDCPGDPR€5,000
10 Mar 2022Briza Land S.R.L.The National Supervisory Authority completed an investigation on 24.02.2022 at Briza Land S.R.L. and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
08 Nov 2022SC Prestige Media PHG SRLSC Prestige Media PHG SRL was fined by ANSPDCP in the amount of 5,000 EUR for breaching the data processing principles under Article 5 of the GDPR. The case concerned unlawful processing of personal data.ROANSPDCPGDPR€5,000
30 Apr 2025BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000.ROANSPDCPGDPR€10,000
30 Jun 2022Continental Automotive Romania SRLThe company was fined for failing to implement adequate technical and organizational measures and for not periodically assessing those measures in relation to employee video processing. The breach concerned the security of video processing and the prevention of unauthorized processing.ROANSPDCPGDPR€2,000
18 Dec 2024Electrica Furnizare S.A.The National Supervisory Authority for Personal Data Processing completed an investigation in November 2024 at Electrica Furnizare S.A. and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed.ROANSPDCPGDPR€3,000
06 Mar 2023Finopro IFN SAFinopro IFN SA was fined by ANSPDCP EUR 2,250 for a data security breach caused by a ransomware attack. The incident led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€2,250
02 Dec 2020Sahlgrenska Universitets­sjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€340,000
11 May 2020Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32.SEIMYGDPR€11,321
07 Jun 2021Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000.SEIMYGDPR€64,643
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
17 Oct 2023H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21.SEIMYGDPR€30,356