BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2020 | Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €389,000 | ↗ |
| 10 Dec 2020 | Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements. | SE | IMY | GDPR | €53,713 | ↗ |
| 11 Dec 2024 | Granit Bostad Beritsholm ABGranit Bostad Beritsholm AB was fined by IMY for conducting video surveillance without a lawful basis. The authority also found that required information was not provided to affected individuals, constituting a GDPR breach. | SE | IMY | GDPR | €17,366 | ↗ |
| 20 Aug 2019 | Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data. | SE | IMY | GDPR | €18,578 | ↗ |
| 07 Jun 2021 | MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing. | SE | IMY | GDPR | €1,193,000 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |
| 17 Jan 2023 | Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR. | SE | IMY | GDPR | kr 200,000 | ↗ |
| 07 Nov 2023 | FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information. | SE | IMY | GDPR | €42,845 | ↗ |
| 02 Dec 2020 | Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements. | SE | IMY | GDPR | €1,167,000 | ↗ |
| 18 Jun 2025 | Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9. | SE | IMY | GDPR | €6,802 | ↗ |
| 26 Jan 2022 | Region Uppsala, personuppgiftsincidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place. | SE | IMY | GDPR | €28,710 | ↗ |
| 02 Dec 2020 | Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €243,000 | ↗ |
| 14 Dec 2020 | Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f). | SE | IMY | GDPR | €29,433 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 26 Jun 2023 | Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes. | SE | IMY | GDPR | €1,112,000 | ↗ |
| 02 Dec 2020 | Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems. | SE | IMY | GDPR | €2,917,000 | ↗ |
| 11 Mar 2020 | Google, rätten att få sökresultat borttagnaGoogle LLC was fined by IMY for processing sensitive personal data without a valid legal basis and for handling data relating to criminal offenses without authorization. The authority also found that Google did not respond promptly to requests for data removal, in breach of several GDPR provisions. | SE | IMY | GDPR | €6,993,000 | ↗ |
| 23 Nov 2020 | Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data. | SE | IMY | GDPR | €391,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 29 Aug 2024 | Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR. | SE | IMY | GDPR | €705,000 | ↗ |