Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Dec 2021Teaching CouncilThe Irish DPC fined Teaching Council EUR 60,000 in inquiry IN-20-4-1. The fine has been collected.IEDPCGDPR€60,000
25 Mar 2019Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000.DKDatatilsynetGDPR€33,493
27 Mar 2014Tarulli Francesca e Comune di ConversanoThe Garante imposed a EUR 4,000 fine on Tarulli Francesca and the Comune di Conversano for failing to designate data processors under the Italian Data Protection Code. The conduct breached Articles 30 and 33 and reflected a deficiency in data processing governance.ITGaranteGDPR€4,000
23 Feb 2023TársasházThe NAIH imposed a 200,000 HUF fine on Társasház for GDPR breaches linked to its electronic surveillance system. The authority found deficiencies in the processing purposes, legal basis, and information provided to data subjects.HUNAIHGDPR€524
02 Feb 2022TARIFER SERVICIOS, S.L.TARIFER SERVICIOS, S.L. was fined by the AEPD 2,000 EUR for using non-essential cookies without user consent. The authority also found that the website did not provide the required cookie information.ESAEPDePrivacy€2,000
29 May 2008Target informatica di Rebosio GiancarloThe sole proprietorship Target informatica di Rebosio Giancarlo was fined EUR 1,549 by the Garante. The sanction concerned sending unsolicited promotional emails without providing the required information notice to the data subjects, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€1,549
20 Dec 2022Tájékoztatás ügyfélszolgálati telefonhívások rögzítésérőlThe entity did not provide adequate prior information about the recording of customer service phone calls. The authority found this to be a breach of GDPR Articles 12 and 13.HUNAIHGDPR€12,400
22 Mar 2021Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine.HUNAIHGDPR€1,365
17 Jun 2025Szpital, za naruszenie przepisów art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,UODO imposed an administrative fine of PLN 66,500 on the hospital. The authority found that the hospital failed to implement appropriate technical and organizational measures to secure personal data and protect data subjects' rights. It also failed to regularly test, measure, and assess the effectiveness of those safeguards.PLUODOGDPR€15,546
30 Nov 2023SzkołęUODO imposed an administrative fine of PLN 35,000 on Szkołę. The authority found that the company had not implemented appropriate technical and organizational measures to secure personal data processed in the application. It also noted the absence of regular testing, measurement, and assessment of the effectiveness of those safeguards.PLUODOGDPR€8,048
23 May 2019Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects.HUNAIHGDPR€91,800
02 Mar 2022Személyes adatok nyilvánosságra hozatala online tudakozóbanThe entity did not delete personal data from an online directory after the data subject requested removal. It also failed to demonstrate a lawful basis or consent for publication, resulting in a breach of accountability and unlawful disclosure of personal data.HUNAIHGDPRFt 5,000,000
18 Aug 2023Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15.HUNAIHGDPR€13,050
07 Jul 2023Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles.HUNAIHGDPR€2,580
09 Mar 2020Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing.HUNAIHGDPR€891
09 Apr 2020Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF.HUNAIHGDPR€1,410
20 Feb 2026Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization.HUNAIHGDPR€5,260
21 Dec 2022Szálláshelyen kamerás megfigyelőrendszer üzemeltetéseThe authority found that the controller unlawfully processed personal data through a camera system, breaching several GDPR provisions. The decision highlighted improper data storage and a lack of transparent information provided to data subjects.HUNAIHGDPR€7,440
01 Jan 2016SYS N PROCS FR EXPS, S.L.SYS N PROCS FR EXPS, S.L. was fined 2,000 EUR by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
19 Jan 2015SYPNOSIS DISTRIBUCION INTEGRAL, S.A.USYPNOSIS DISTRIBUCION INTEGRAL, S.A.U was fined by the AEPD EUR 1,000 for sending unsolicited promotional emails without the recipient's consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€1,000