Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 May 2022NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people.NODatatilsynetGDPR€485,000
28 Nov 2023Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data.NODatatilsynetGDPR€1,707,000
11 May 2021Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days.NODatatilsynetGDPR€124,000
06 May 2021Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA.NODatatilsynetGDPR€497,000
29 Oct 2024Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security.NODatatilsynetGDPR€21,113
24 Mar 2021Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards.NODatatilsynetGDPR€4,923
11 Sept 2024Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals.NODatatilsynetGDPR€12,566
22 Jun 2021VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections.NODatatilsynetGDPR€14,678
19 May 2021CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing.NLAPGDPR€15,000
16 Jul 2019Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures.NLAPGDPR€460,000
11 Feb 2021Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR.NLAPGDPR€440,000
12 May 2021Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved.NLAPGDPR€525,000
08 Jul 2025Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6.NLAPGDPR€500
09 Aug 2018InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000.NLAPGDPR€48,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
04 Nov 2019Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data.NLAPGDPR€150,000
17 Dec 2025Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach.NLAPGDPR€175,000
13 Apr 2023Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32.NLAPGDPR€150,000
18 Dec 2024Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements.NLAPGDPR€4,750,000
17 Nov 2023Gemeente VoorschotenThe municipality of Voorschoten unlawfully processed personal data about residents’ waste disposal history without a sufficient legal basis. It also failed to properly inform the affected residents, breaching GDPR Articles 5, 6 and 14.NLAPGDPR€30,000