BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 May 2026 | Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights. | BE | APD | GDPR | €5,000 | ↗ |
| 21 Oct 2022 | IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury. | BE | APD | ePrivacy | €10,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance. | BE | APD | GDPR | €50,000 | ↗ |
| 14 May 2025 | IAB EuropeThe Gegevensbeschermingsautoriteit’s decision concerned IAB Europe and the Transparency and Consent Framework. A fine of EUR 250,000 was imposed for GDPR breaches related to the processing of personal data, and the Brussels Market Court confirmed the violations and sanctions while noting procedural grounds for annulling the original decision. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €250,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data. | BE | APD | GDPR | €250,000 | ↗ |
| 28 Apr 2026 | Fondation YThe APD Litigation Chamber fined Fondation Y EUR 1,000 for failing to respond to a data erasure request. The authority also found negligent cooperation with the data protection authority, constituting a breach of Article 31 GDPR. | BE | APD | GDPR | €1,000 | ↗ |
| 17 Dec 2024 | Geanonimiseerd (APD 166/2024)The hospital was fined by the APD for failing to carry out a data protection impact assessment and for lacking effective information security policies. These deficiencies contributed to a ransomware incident affecting up to 300,000 individuals. | BE | APD | GDPR | €50,000 | ↗ |
| 17 Sept 2019 | Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000. | BE | APD | GDPR | €10,000 | ↗ |
| 19 Jan 2023 | A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €8,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations. | BE | APD | GDPR | €250,000 | ↗ |
| 25 May 2022 | Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements. | BE | APD | ePrivacy | €50,000 | ↗ |
| 28 Apr 2026 | vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €1,000 | ↗ |
| 24 May 2022 | Geanonimiseerd (APD 84/2022)The case concerns a complaint by the Ordre des Barreaux Francophones de Belgique against sos-services.be and sos-avocats.be. The authority found that lawyers were listed without a legal basis and with incorrect information, in breach of GDPR and ePrivacy rules. | BE | APD | ePrivacy | €10,000 | ↗ |
| 29 Sept 2020 | Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation. | BE | APD | GDPR | €5,000 | ↗ |
| 06 May 2021 | YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions. | BE | APD | GDPR | €50,000 | ↗ |
| 15 Mar 2021 | Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached. | BE | APD | GDPR | €2,000 | ↗ |
| 27 Jan 2021 | De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations. | BE | APD | GDPR | €50,000 | ↗ |
| 08 Jun 2020 | de heer YThe APD Litigation Chamber fined de heer Y 5,000 EUR. It found that personal data from the municipal staff list was processed for election propaganda, breaching the GDPR principles of purpose limitation and lawfulness. | BE | APD | GDPR | €5,000 | ↗ |
| 25 May 2022 | RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000. | BE | Autorité de protection des données | GDPR | €50,000 | ↗ |
| 23 Aug 2022 | Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents. | BE | APD | GDPR | €2,500 | ↗ |