Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jan 2024Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements.NLAPGDPR€10,000,000
05 Jun 2024Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12.NLAPGDPR€6,000
24 Feb 2022DPG Media Magazines B.V.DPG Media Magazines B.V. was fined for obstructing data subjects’ access to and erasure of their personal data by imposing unnecessary barriers. The authority found this conduct breached Article 12(2) GDPR.NLAPGDPR€525,000
11 May 2021Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident.NLAPGDPR€7,500
21 Dec 2022Politie NederlandThe Dutch Data Protection Authority fined the police chief for failing to carry out a data protection impact assessment before using mobile camera cars in Rotterdam. The measure created a high risk to individuals' rights and freedoms.NLAPGDPR€50,000
10 Jun 2021orthodontiepraktijkThe entity failed to implement appropriate technical and organizational measures to secure personal data, which constitutes a breach of Article 32 GDPR. Sensitive data on the website was not transmitted over encrypted connections, increasing the risk of disclosure.NLAPGDPR€12,000
08 May 2026MLU B.V.MLU B.V. was fined €100,000,000 by AP for transferring personal data of users in Finland and Norway to Russia without adequate safeguards. The authority found breaches of GDPR Articles 44, 46, and 5.NLAPGDPR€100,000,000
30 Apr 2020vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR.NLAPGDPR€725,000
07 Jul 2021Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers.NLAPGDPR€450,000
04 Nov 2019Coöperatie VGZ U.A.The Autoriteit Persoonsgegevens imposed a EUR 150,000 penalty on Coöperatie VGZ U.A. for failing to implement appropriate technical measures to protect personal data from unauthorized access. The authority found a breach of data protection law.NLAPGDPR€150,000
16 Jul 2024A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6.NLAPGDPR€600,000
05 Mar 2020CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation.NLAutoriteit PersoonsgegevensGDPR€40,000
03 Mar 2020Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle.NLAPGDPR€525,000
04 Nov 2019Coöperatie Menzis U.A.Menzis was fined by the AP for failing to implement appropriate technical measures to protect personal data. The authority found a breach of Article 32 GDPR.NLAPGDPR€50,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
03 Sept 2024Clearview AI Inc.Clearview AI Inc. was fined by the Dutch data protection authority AP for processing personal data without a legal basis, including biometric data. The authority also cited inadequate notice to data subjects, failure to respond to access requests, and failure to appoint an EU representative.NLAPGDPR€30,500,000
01 Jan 2019KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis.NLAutoriteit PersoonsgegevensGDPR€525,000
06 Jul 2020Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access.NLAPGDPR€830,000
07 Dec 2021Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws.NLAPGDPR€2,750,000
17 Oct 2025Experian Nederland B.V.Experian Nederland B.V. was fined by the AP €2,700,000 for failing to adequately inform data subjects and for processing personal data without a valid legal basis. The case concerns breaches of the GDPR principles of transparency and lawful processing.NLAPGDPR€2,700,000