Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jul 2019Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent.ATDSBGDPR€10,000
16 Oct 2024D**** GmbHThe company appointed its managing director as the data protection officer, creating a conflict of interest. The DSB found this breached Article 38(6) GDPR and imposed a fine of EUR 5,000.ATDSBGDPR€5,000
11 Dec 2023C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information.ATDSBGDPR€9,500
29 Jun 2023Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€10,000
19 Oct 2020Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR.ATDSBGDPR€150
12 Dec 2024Anonymisiert (DSB 2024-0.796.258)The individual unlawfully processed intimate photos by transferring and storing them without the data subject’s consent. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€2,000
27 Sept 2018Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ATDSBGDPR€300
23 Aug 2022Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed.ATDSBGDPR€25,000
07 Dec 2023N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR.ATDSBGDPR€20,000
21 Aug 2025Anonymisiert (DSB 2025-0.625.944)Dr. Martha N. unlawfully accessed the electronic health records of a former assistant without a legitimate purpose. The authority found this to be a breach of GDPR principles governing personal data processing.ATDSBGDPR€1,000
19 Oct 2020Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis.ATDSBGDPR€600
07 Dec 2023H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR.ATDSBGDPR€10,000
07 Oct 2025Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation.ATDSBGDPR€2,500