BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Apr 2025 | Diskrimineringsombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form. | SE | IMY | GDPR | €9,141 | ↗ |
| 03 Oct 2023 | Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR. | SE | IMY | GDPR | €68,744 | ↗ |
| 02 Dec 2020 | Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements. | SE | IMY | GDPR | €1,458,000 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 15 Apr 2026 | Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose. | SI | Informacijski pooblaščenec | GDPR | €6,000 | ↗ |
| 25 Jul 2025 | Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract. | SI | IP-RS | GDPR | €5,610 | ↗ |
| 29 Jul 2025 | Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness. | SI | IP-RS | GDPR | €10,614 | ↗ |
| 01 Dec 2025 | Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop. | SI | IP-RS | GDPR | €1,000 | ↗ |
| 26 Nov 2025 | Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR. | SI | IP-RS | GDPR | €6,000 | ↗ |
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 13 Aug 2025 | Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR. | SI | IP-RS | GDPR | €500 | ↗ |
| 22 Jul 2025 | Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements. | SI | IP-RS | GDPR | €2,000 | ↗ |
| 08 Dec 2025 | Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR. | SI | IP-RS | GDPR | €4,800 | ↗ |