BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jun 2024 | SIA "Moshmans"A fine of EUR 500 was imposed by the DVI. The decision has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 29 Mar 2022 | SIA "8 LOUNGE"A fine of EUR 500 was imposed. The decision has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 12 Mar 2024 | Fiziska personaA monetary penalty of 150 EUR was imposed by DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €150 | ↗ |
| 18 Sept 2024 | Paula Stradiņa klīniskā universitātes slimnīcaA fine of EUR 2,000 was imposed. The decision has entered into force. | LV | DVI | GDPR | €2,000 | ↗ |
| 29 Sept 2022 | SIA "Deprus"DVI imposed a fine of 500 EUR on SIA "Deprus". The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 08 Sept 2025 | SIA "ZZ Dats"DVI imposed a fine of 300,000 EUR on SIA "ZZ Dats". The decision has been appealed. | LV | DVI | GDPR | €300,000 | ↗ |
| 18 Jan 2024 | Fiziska personaA fine of EUR 250 was imposed by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €250 | ↗ |
| 28 Oct 2025 | SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision. | LV | Datu valsts inspekcija | GDPR | €300,000 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-23-fr-2022)The company failed to meet the transparency obligations under Article 12(1) GDPR by not providing the required information in a concise, transparent, and easily accessible manner. CNPD treated this as a breach of the information duties owed to data subjects. | LU | CNPD | GDPR | €1,300 | ↗ |
| 13 Oct 2021 | Anonymisé (CNPD decision-36-fr-2021)The company did not involve the Data Protection Officer in all matters related to personal data protection. CNPD found this breached GDPR Articles 38(1) and 39(1) and imposed a EUR 23,400 fine. | LU | CNPD | GDPR | €23,400 | ↗ |
| 04 Aug 2021 | Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39. | LU | CNPD | GDPR | €17,700 | ↗ |
| 22 Jun 2022 | Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles. | LU | CNPD | GDPR | €4,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-17-fr-2021)The CNPD found that the company breached GDPR principles by failing to comply with data minimization and retention limits in its video surveillance practices. A fine of EUR 1,900 was imposed. | LU | CNPD | GDPR | €1,900 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-18-fr-2022)The company unlawfully transmitted personal data to third parties without prior authorization. The authority also found breaches of GDPR data processing principles and data subject rights. | LU | CNPD | GDPR | €2,500 | ↗ |
| 02 Feb 2022 | Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000. | LU | CNPD | GDPR | €10,000 | ↗ |
| 15 Jul 2021 | Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects. | LU | CNPD | GDPR | €3,500 | ↗ |
| 15 Dec 2021 | Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR. | LU | CNPD | GDPR | €11,600 | ↗ |
| 07 Jul 2022 | Anonymisé (CNPD decision-15-fr-2022)The company was fined by the CNPD EUR 10,500 for breaching the data minimization principle and for failing to adequately inform individuals about video surveillance systems. The authority cited violations of GDPR Articles 5(1)(c) and 13. | LU | CNPD | GDPR | €10,500 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-06-fr-2025)The company failed to maintain a proper record of processing activities under Article 30 GDPR. The register contained inaccuracies and omissions, indicating a breach of documentation obligations. | LU | CNPD | GDPR | €1,277 | ↗ |
| 22 Apr 2022 | Anonymisé (CNPD decision-10-fr-2022)The public transport organization breached GDPR requirements on storage limitation, data minimization, and providing adequate information to data subjects. CNPD imposed a fine of EUR 4,000. | LU | CNPD | GDPR | €4,000 | ↗ |