Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221.NLAutoriteit PersoonsgegevensGDPR€6,000
05 Feb 2026Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles.NLAPGDPR€25,000
12 Apr 2022Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles.NLAPGDPR€3,700,000
12 Nov 2021Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals.NLAPGDPR€400,000
10 Oct 2023Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data.NLAutoriteit PersoonsgegevensGDPR€175,000
16 Jul 2024AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules.NLAutoriteit PersoonsgegevensGDPR€600,000
31 Mar 2021Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay.NLAPGDPR€475,000
17 Dec 2025HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision.NLAutoriteit PersoonsgegevensGDPR€100,000
26 Nov 2024NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests.NLAutoriteit PersoonsgegevensGDPR€4,750,000
16 Jan 2024International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR.NLAPGDPR€150,000
01 Oct 2023ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company.NLAutoriteit PersoonsgegevensGDPR€2,700,000
06 Apr 2022Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications.NLAPGDPR€565,000
08 May 2026MLU B.V.The Dutch data protection authority imposed a EUR 100 million fine on MLU B.V. for transferring personal data to Russia without adequate safeguards. It also ordered the company to stop transferring personal data of individuals in Norway and Finland to Russia via the Yango app.NLAutoriteit PersoonsgegevensGDPR€100,000,000
29 Apr 2021Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6.NLAPGDPR€600,000
22 Jul 2021TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form.NLAPGDPR€750,000
01 Nov 2018UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures.NLAPGDPR€150,000
05 Feb 2026Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility.NLAutoriteit PersoonsgegevensGDPR€25,000
26 Aug 2024Uber Technologies Inc.Uber Technologies Inc. was fined by the Dutch data protection authority AP in the amount of EUR 290,000,000. The authority found that the company transferred personal data to the United States without appropriate safeguards, in breach of Article 44 GDPR.NLAPGDPR€290,000,000
01 Jul 2024Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000.MTIDPCGDPR€15,000
01 May 2026Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed.MTIDPCGDPR€1,000