Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Dec 2020Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€389,000
10 Dec 2020Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements.SEIMYGDPR€53,713
11 Dec 2024Granit Bostad Beritsholm ABGranit Bostad Beritsholm AB was fined by IMY for conducting video surveillance without a lawful basis. The authority also found that required information was not provided to affected individuals, constituting a GDPR breach.SEIMYGDPR€17,366
20 Aug 2019Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data.SEIMYGDPR€18,578
07 Jun 2021MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing.SEIMYGDPR€1,193,000
07 Jun 2021Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements.SEIMYGDPR€24,863
17 Jan 2023Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR.SEIMYGDPRkr 200,000
07 Nov 2023FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information.SEIMYGDPR€42,845
02 Dec 2020Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements.SEIMYGDPR€1,167,000
18 Jun 2025Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9.SEIMYGDPR€6,802
26 Jan 2022Region Uppsala, personuppgifts­incidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place.SEIMYGDPR€28,710
02 Dec 2020Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€243,000
14 Dec 2020Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f).SEIMYGDPR€29,433
18 Apr 2024H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13.SEIMYGDPR€25,779
26 Jun 2023Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes.SEIMYGDPR€1,112,000
02 Dec 2020Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems.SEIMYGDPR€2,917,000
11 Mar 2020Google, rätten att få sökresultat borttagnaGoogle LLC was fined by IMY for processing sensitive personal data without a valid legal basis and for handling data relating to criminal offenses without authorization. The authority also found that Google did not respond promptly to requests for data removal, in breach of several GDPR provisions.SEIMYGDPR€6,993,000
23 Nov 2020Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data.SEIMYGDPR€391,000
26 Jan 2026SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach.SEIMYGDPR€564,000
29 Aug 2024Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€705,000