Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Aug 2024Apoteket AB, gällande Meta-pixelApoteket AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€3,261,000
27 Jun 2023Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data.ISPersónuverndGDPR€254,000
15 Jun 2023SOCIÉTÉ SPÉCIALISÉE DANS L'AFFICHAGE DE PUBLICITÉS CIBLÉES SUR LE WEBThe CNIL imposed a fine of 40 million euros on the company. The decision concerns identified breaches of rules under the authority's supervision.FRCNILGDPR€40,000,000
13 Jan 2026Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data.FRCommission nationale de l’informatique et des libertésGDPR€42,000,000
03 Jun 2025VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles.DEBundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)GDPR€45,000,000
14 Nov 2024OPERATEUR DE TELECOMMUNICATIONSOPERATEUR DE TELECOMMUNICATIONS was issued an administrative fine of EUR 50 million and an injunction. The case concerns a CNIL decision dated 2024-11-14.FRCNILGDPR€50,000,000
19 Dec 2025MÁV Személyszállítási Zártkörűen Működő RészvénytársaságThe NAIH imposed a 50,000,000 HUF fine on MÁV Személyszállítási Zrt. for breaching GDPR principles. The authority found deficiencies in transparency and data minimization in the company's camera surveillance and audio recording practices at HÉV stations.HUNAIHGDPR€129,000
26 May 2026Mediaworks Hungary Zrt.Mediaworks Hungary Zrt. was fined by NAIH 50,000,000 HUF for publishing links to a map containing personal data and special category data, including political opinions. The authority found that the processing lacked a lawful basis.HUNAIHGDPR€140,000
13 Jan 2025OrangeCNIL imposed a EUR 50 million fine on Orange for displaying commercial ads in email inboxes without prior user consent. The authority also found that advertising and statistical cookies continued to be read after consent had been withdrawn, in breach of the GDPR.FRCommission Nationale de l'Informatique et des LibertésGDPR€50,000,000
01 Jan 2024Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€130,000
12 Jun 2023Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language.SEIMYGDPR€4,992,000
03 Jun 2025Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten.SEIntegritetsskyddsmyndigheten (IMY)GDPR€5,309,000
19 Dec 2022SOCIETE DE VENTE DE SYSTEMES D’EXPLOITATION, DE LOGICIELS APPLICATIFS, DE MATERIELS ET DE SERVICES DERIVESThe CNIL imposed a EUR 60 million fine on SOCIETE DE VENTE DE SYSTEMES D’EXPLOITATION, DE LOGICIELS APPLICATIFS, DE MATERIELS ET DE SERVICES DERIVES and issued an injunction subject to a penalty payment. The case concerned identified compliance breaches requiring corrective action and enforcement measures.FRCNILGDPR€60,000,000
02 Feb 2024[...] Zrt.The controller did not provide adequate information about data processing through camera systems in bank branches. This constituted a breach of GDPR Articles 12 and 13.HUNAIHGDPR€156,000
29 Sept 2020Vodafone Magyarország Távközlési Zártkörűen Működő RészvénytársaságThe NAIH imposed a 60,000,000 HUF fine on Vodafone Magyarország for unlawful voice recording practices at customer service offices. The authority found GDPR breaches relating to legal basis, transparency, purpose limitation, and data minimization.HUNAIHGDPR€163,000
01 Dec 2021GrindrThe Norwegian DPA, Datatilsynet, fined Grindr NOK 65 million for sharing user data with third parties for marketing purposes without a legal basis. The authority found a breach of GDPR consent requirements.NODatatilsynetGDPR€6,360,000
15 Dec 2021GrindrNorway's Datatilsynet imposed an administrative fine of NOK 65 million on Grindr on 15.12.2021. The case concerned violations of the GDPR consent requirements.NODatatilsynetGDPR€6,355,000
06 Oct 2023Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures.HUNAIHGDPR€194,000
16 Apr 2026An unnamed energy companyHungary’s data protection authority, NAIH, imposed a HUF 75 million GDPR fine in case NAIH-19-18/2024 on an unnamed energy company. The case concerned data processing for a nationwide LED replacement program and identified serious privacy compliance failures.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€205,000
10 Sept 2024Okmánymásolat feltöltését is előíró regisztrációs folyamattal és regisztrációs adatbázissal kapcsolatos jogellenes adatkezelésThe authority imposed a fine for negligent GDPR violations between December 2021 and November 2023. The breaches concerned transparency and data processing principles in connection with the registration process and the registration database.HUNAIHGDPR€189,000