BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Jul 2019 | Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent. | AT | DSB | GDPR | €10,000 | ↗ |
| 16 Oct 2024 | D**** GmbHThe company appointed its managing director as the data protection officer, creating a conflict of interest. The DSB found this breached Article 38(6) GDPR and imposed a fine of EUR 5,000. | AT | DSB | GDPR | €5,000 | ↗ |
| 11 Dec 2023 | C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information. | AT | DSB | GDPR | €9,500 | ↗ |
| 29 Jun 2023 | Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €10,000 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR. | AT | DSB | GDPR | €150 | ↗ |
| 12 Dec 2024 | Anonymisiert (DSB 2024-0.796.258)The individual unlawfully processed intimate photos by transferring and storing them without the data subject’s consent. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €2,000 | ↗ |
| 27 Sept 2018 | Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | AT | DSB | GDPR | €300 | ↗ |
| 23 Aug 2022 | Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed. | AT | DSB | GDPR | €25,000 | ↗ |
| 07 Dec 2023 | N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR. | AT | DSB | GDPR | €20,000 | ↗ |
| 21 Aug 2025 | Anonymisiert (DSB 2025-0.625.944)Dr. Martha N. unlawfully accessed the electronic health records of a former assistant without a legitimate purpose. The authority found this to be a breach of GDPR principles governing personal data processing. | AT | DSB | GDPR | €1,000 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis. | AT | DSB | GDPR | €600 | ↗ |
| 07 Dec 2023 | H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR. | AT | DSB | GDPR | €10,000 | ↗ |
| 07 Oct 2025 | Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation. | AT | DSB | GDPR | €2,500 | ↗ |