BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Jan 2023 | Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR. | SE | IMY | GDPR | kr 200,000 | ↗ |
| 07 Nov 2023 | FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information. | SE | IMY | GDPR | €42,845 | ↗ |
| 02 Dec 2020 | Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements. | SE | IMY | GDPR | €1,167,000 | ↗ |
| 18 Jun 2025 | Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9. | SE | IMY | GDPR | €6,802 | ↗ |
| 26 Jan 2022 | Region Uppsala, personuppgiftsincidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place. | SE | IMY | GDPR | €28,710 | ↗ |
| 02 Dec 2020 | Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €243,000 | ↗ |
| 14 Dec 2020 | Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f). | SE | IMY | GDPR | €29,433 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 26 Jun 2023 | Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes. | SE | IMY | GDPR | €1,112,000 | ↗ |
| 02 Dec 2020 | Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems. | SE | IMY | GDPR | €2,917,000 | ↗ |
| 11 Mar 2020 | Google, rätten att få sökresultat borttagnaGoogle LLC was fined by IMY for processing sensitive personal data without a valid legal basis and for handling data relating to criminal offenses without authorization. The authority also found that Google did not respond promptly to requests for data removal, in breach of several GDPR provisions. | SE | IMY | GDPR | €6,993,000 | ↗ |
| 23 Nov 2020 | Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data. | SE | IMY | GDPR | €391,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 29 Aug 2024 | Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR. | SE | IMY | GDPR | €705,000 | ↗ |
| 23 Apr 2025 | Diskrimineringsombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form. | SE | IMY | GDPR | €9,141 | ↗ |
| 03 Oct 2023 | Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR. | SE | IMY | GDPR | €68,744 | ↗ |
| 02 Dec 2020 | Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements. | SE | IMY | GDPR | €1,458,000 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 30 Oct 2024 | Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 22 Aug 2024 | Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |