BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221. | NL | Autoriteit Persoonsgegevens | GDPR | €6,000 | ↗ |
| 05 Feb 2026 | Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles. | NL | AP | GDPR | €25,000 | ↗ |
| 12 Apr 2022 | Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles. | NL | AP | GDPR | €3,700,000 | ↗ |
| 12 Nov 2021 | Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals. | NL | AP | GDPR | €400,000 | ↗ |
| 10 Oct 2023 | Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data. | NL | Autoriteit Persoonsgegevens | GDPR | €175,000 | ↗ |
| 16 Jul 2024 | AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules. | NL | Autoriteit Persoonsgegevens | GDPR | €600,000 | ↗ |
| 31 Mar 2021 | Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay. | NL | AP | GDPR | €475,000 | ↗ |
| 17 Dec 2025 | HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision. | NL | Autoriteit Persoonsgegevens | GDPR | €100,000 | ↗ |
| 26 Nov 2024 | NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests. | NL | Autoriteit Persoonsgegevens | GDPR | €4,750,000 | ↗ |
| 16 Jan 2024 | International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR. | NL | AP | GDPR | €150,000 | ↗ |
| 01 Oct 2023 | ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company. | NL | Autoriteit Persoonsgegevens | GDPR | €2,700,000 | ↗ |
| 06 Apr 2022 | Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications. | NL | AP | GDPR | €565,000 | ↗ |
| 08 May 2026 | MLU B.V.The Dutch data protection authority imposed a EUR 100 million fine on MLU B.V. for transferring personal data to Russia without adequate safeguards. It also ordered the company to stop transferring personal data of individuals in Norway and Finland to Russia via the Yango app. | NL | Autoriteit Persoonsgegevens | GDPR | €100,000,000 | ↗ |
| 29 Apr 2021 | Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 22 Jul 2021 | TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form. | NL | AP | GDPR | €750,000 | ↗ |
| 01 Nov 2018 | UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures. | NL | AP | GDPR | €150,000 | ↗ |
| 05 Feb 2026 | Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility. | NL | Autoriteit Persoonsgegevens | GDPR | €25,000 | ↗ |
| 26 Aug 2024 | Uber Technologies Inc.Uber Technologies Inc. was fined by the Dutch data protection authority AP in the amount of EUR 290,000,000. The authority found that the company transferred personal data to the United States without appropriate safeguards, in breach of Article 44 GDPR. | NL | AP | GDPR | €290,000,000 | ↗ |
| 01 Jul 2024 | Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000. | MT | IDPC | GDPR | €15,000 | ↗ |
| 01 May 2026 | Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed. | MT | IDPC | GDPR | €1,000 | ↗ |