Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Feb 2025SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed.SEIntegritetsskyddsmyndighetenGDPR€538,000
04 Feb 2025Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate.SEIntegritetsskyddsmyndighetenGDPR€1,138,000
09 Jun 2021Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures.SEIMYGDPR€34,794
12 Jun 2023Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language.SEIMYGDPR€4,992,000
03 Jun 2025Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten.SEIntegritetsskyddsmyndigheten (IMY)GDPR€5,309,000
28 Aug 2023Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1).SEIMYGDPR€2,941,000
10 Feb 2021Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act.SEIMYePrivacy€248,000
25 Jun 2024AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta.SEIMYGDPR€1,336,000
21 Jun 2021Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization.SEIMYGDPR€1,566,000
02 Dec 2020Region ÖstergötlandRegion Östergötland was fined by IMY for failing to perform a needs and risk analysis before granting access rights in its journal system. The authority found that this breached several GDPR provisions.SEIMYGDPR€243,000
28 Nov 2023Barn- och utbildningsnämnden, Östersunds kommunBarn- och utbildningsnämnden in Östersunds kommun was fined by IMY for failing to conduct a data protection impact assessment before deploying Google Workspace for Education in 24 schools. The authority found this to be a breach of Article 35 GDPR.SEIMYGDPR€26,241
07 Jun 2021Regionstyrelsen Region VärmlandRegionstyrelsen Region Värmland was fined by IMY 250,000 SEK for failing to inform patients calling the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found this to be a breach of GDPR transparency requirements.SEIMYGDPR€24,863
15 Jun 2020Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency.SEIMYGDPR€1,898
29 Aug 2024Apoteket AB, gällande Meta-pixelApoteket AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€3,261,000
03 Dec 2019Nusvar ABNusvar AB was fined SEK 35,000 by IMY. The authority found unauthorized processing of personal data relating to criminal offenses and a failure to comply with data minimization principles in credit reporting activities.SEIMYGDPR€3,313
14 Mar 2022Tullverket, tjänstemobilerThe Swedish Customs Agency (Tullverket) was fined by IMY 300,000 SEK for failing to implement adequate technical and organizational measures. This led to unauthorized storage of personal data in a cloud service.SEIMYePrivacy€28,473
07 Jun 2021Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations.SEIMYGDPR€49,725
01 Jan 2025Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor.SEIntegritetsskyddsmyndigheten (IMY)GDPR€8,727
18 Jun 2025Waxholms Ångfartygs AB (WÅAB)IMY fined Waxholms Ångfartygs AB SEK 75,000 for processing personal data without a lawful basis. The authority also found processing of sensitive personal data without an applicable exception, in breach of GDPR Articles 6 and 9.SEIMYGDPR€6,802
24 Nov 2020LSS-boendeGnosjö kommun - Socialutskottet was fined by IMY for unlawful video surveillance in an LSS residence. The authority found processing of personal and sensitive data without a legal basis and no data protection impact assessment.SEIMYGDPR€19,600