Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Apr 2025Diskriminerings­ombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form.SEIMYGDPR€9,141
03 Oct 2023Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR.SEIMYGDPR€68,744
02 Dec 2020Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements.SEIMYGDPR€1,458,000
26 Apr 2023Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures.SEIMYGDPR€17,566
15 Apr 2026Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose.SIInformacijski pooblaščenecGDPR€6,000
25 Jul 2025Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract.SIIP-RSGDPR€5,610
29 Jul 2025Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness.SIIP-RSGDPR€10,614
01 Dec 2025Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop.SIIP-RSGDPR€1,000
26 Nov 2025Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR.SIIP-RSGDPR€6,000
21 Nov 2025Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals.SIIP-RSGDPR€16,250
13 Aug 2025Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR.SIIP-RSGDPR€500
22 Jul 2025Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements.SIIP-RSGDPR€2,000
08 Dec 2025Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR.SIIP-RSGDPR€4,800