BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 May 2019 | Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects. | HU | NAIH | GDPR | €91,800 | ↗ |
| 02 Aug 2022 | BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR. | HU | NAIH | GDPR | €75,600 | ↗ |
| 12 Sept 2022 | Magyar Éremkibocsátó Kft.The Hungarian data protection authority, NAIH, imposed a fine of 30,000,000 HUF on Magyar Éremkibocsátó Kft. The authority found that personal data were processed without a proper legal basis, specific purpose, or valid consent, and that GDPR transparency and information obligations were breached. | HU | NAIH | GDPR | €75,900 | ↗ |
| 02 Dec 2020 | Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems. | SE | IMY | GDPR | €2,917,000 | ↗ |
| 06 Feb 2023 | I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes. | HU | NAIH | GDPR | €76,800 | ↗ |
| 24 Jun 2025 | OLXUOKiK imposed a PLN 28.4 million fine on OLX for irregularities in its ratings system that could mislead consumers. The decision was not yet final, as OLX could appeal. | PL | Urząd Ochrony Konkurencji i Konsumentów | Omnibus | €6,676,000 | ↗ |
| 15 Jan 2020 | TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules. | IT | Garante | GDPR | €27,802,000 | ↗ |
| 27 Feb 2020 | Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 05 Mar 2026 | Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €6,348,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE MOBILECNIL imposed an administrative fine of EUR 27 million on OPÉRATEUR DE TÉLÉPHONIE MOBILE and issued an injunction. The case concerns a regulatory breach addressed by the authority’s decision. | FR | CNIL | GDPR | €27,000,000 | ↗ |
| 16 Dec 2021 | Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling. | IT | Garante | GDPR | €26,513,000 | ↗ |
| 05 May 2021 | Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data. | NO | Datatilsynet | GDPR | €2,503,000 | ↗ |
| 29 May 2026 | IndaNext Hungary Korlátolt Felelősségű TársaságNAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12. | HU | NAIH | GDPR | €70,750 | ↗ |
| 15 Nov 2019 | Raiffeisen Bank Zrt.Raiffeisen Bank Zrt. was fined by the NAIH 25,000,000 HUF for processing personal data of non-advisory service clients without a legal basis. The authority also found that the bank failed to provide adequate information about the processing of personal data collected through MiFID questionnaires. | HU | NAIH | GDPR | €74,750 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 17 Oct 2022 | SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a EUR 20 million fine on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE and issued an injunction subject to a penalty. The case concerned identified data protection breaches. | FR | CNIL | GDPR | €20,000,000 | ↗ |
| 09 Dec 2020 | ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident. | HU | NAIH | GDPR | €56,000 | ↗ |
| 04 Jun 2026 | ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing. | NO | Datatilsynet | GDPR | €1,844,000 | ↗ |