BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2021 | Teaching CouncilThe Irish DPC fined Teaching Council EUR 60,000 in inquiry IN-20-4-1. The fine has been collected. | IE | DPC | GDPR | €60,000 | ↗ |
| 25 Mar 2019 | Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000. | DK | Datatilsynet | GDPR | €33,493 | ↗ |
| 27 Mar 2014 | Tarulli Francesca e Comune di ConversanoThe Garante imposed a EUR 4,000 fine on Tarulli Francesca and the Comune di Conversano for failing to designate data processors under the Italian Data Protection Code. The conduct breached Articles 30 and 33 and reflected a deficiency in data processing governance. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Feb 2023 | TársasházThe NAIH imposed a 200,000 HUF fine on Társasház for GDPR breaches linked to its electronic surveillance system. The authority found deficiencies in the processing purposes, legal basis, and information provided to data subjects. | HU | NAIH | GDPR | €524 | ↗ |
| 02 Feb 2022 | TARIFER SERVICIOS, S.L.TARIFER SERVICIOS, S.L. was fined by the AEPD 2,000 EUR for using non-essential cookies without user consent. The authority also found that the website did not provide the required cookie information. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 29 May 2008 | Target informatica di Rebosio GiancarloThe sole proprietorship Target informatica di Rebosio Giancarlo was fined EUR 1,549 by the Garante. The sanction concerned sending unsolicited promotional emails without providing the required information notice to the data subjects, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €1,549 | ↗ |
| 20 Dec 2022 | Tájékoztatás ügyfélszolgálati telefonhívások rögzítésérőlThe entity did not provide adequate prior information about the recording of customer service phone calls. The authority found this to be a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €12,400 | ↗ |
| 22 Mar 2021 | Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine. | HU | NAIH | GDPR | €1,365 | ↗ |
| 17 Jun 2025 | Szpital, za naruszenie przepisów art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,UODO imposed an administrative fine of PLN 66,500 on the hospital. The authority found that the hospital failed to implement appropriate technical and organizational measures to secure personal data and protect data subjects' rights. It also failed to regularly test, measure, and assess the effectiveness of those safeguards. | PL | UODO | GDPR | €15,546 | ↗ |
| 30 Nov 2023 | SzkołęUODO imposed an administrative fine of PLN 35,000 on Szkołę. The authority found that the company had not implemented appropriate technical and organizational measures to secure personal data processed in the application. It also noted the absence of regular testing, measurement, and assessment of the effectiveness of those safeguards. | PL | UODO | GDPR | €8,048 | ↗ |
| 23 May 2019 | Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects. | HU | NAIH | GDPR | €91,800 | ↗ |
| 02 Mar 2022 | Személyes adatok nyilvánosságra hozatala online tudakozóbanThe entity did not delete personal data from an online directory after the data subject requested removal. It also failed to demonstrate a lawful basis or consent for publication, resulting in a breach of accountability and unlawful disclosure of personal data. | HU | NAIH | GDPR | Ft 5,000,000 | ↗ |
| 18 Aug 2023 | Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15. | HU | NAIH | GDPR | €13,050 | ↗ |
| 07 Jul 2023 | Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles. | HU | NAIH | GDPR | €2,580 | ↗ |
| 09 Mar 2020 | Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing. | HU | NAIH | GDPR | €891 | ↗ |
| 09 Apr 2020 | Szegedi Tudományegyetem (Szentgyörgyi Albert Klinikai Központ)Szegedi Tudományegyetem failed to comply with GDPR Articles 33 and 34 after a data breach incident. The NAIH imposed a fine of 500,000 HUF. | HU | NAIH | GDPR | €1,410 | ↗ |
| 20 Feb 2026 | Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization. | HU | NAIH | GDPR | €5,260 | ↗ |
| 21 Dec 2022 | Szálláshelyen kamerás megfigyelőrendszer üzemeltetéseThe authority found that the controller unlawfully processed personal data through a camera system, breaching several GDPR provisions. The decision highlighted improper data storage and a lack of transparent information provided to data subjects. | HU | NAIH | GDPR | €7,440 | ↗ |
| 01 Jan 2016 | SYS N PROCS FR EXPS, S.L.SYS N PROCS FR EXPS, S.L. was fined 2,000 EUR by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 19 Jan 2015 | SYPNOSIS DISTRIBUCION INTEGRAL, S.A.USYPNOSIS DISTRIBUCION INTEGRAL, S.A.U was fined by the AEPD EUR 1,000 for sending unsolicited promotional emails without the recipient's consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |