BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Nov 2023 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data. | NO | Datatilsynet | GDPR | €1,707,000 | ↗ |
| 03 Sept 2020 | Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data. | HU | NAIH | GDPR | €55,800 | ↗ |
| 23 Jul 2025 | Dane anonimowe (K.)UODO imposed an administrative fine of PLN 18,416,400 for processing personal data without a lawful basis. The case concerned copying and scanning customers’ identity documents without properly verifying whether this was justified by AML obligations. | PL | UODO | GDPR | €4,328,000 | ↗ |
| 27 Aug 2025 | INGPoland’s data protection authority, UODO, fined ING more than PLN 18 million. The authority found that the bank scanned identity documents in situations not required by AML rules, including for non-customers and in cases unrelated to service provision. | PL | Urząd Ochrony Danych Osobowych | GDPR | €4,215,000 | ↗ |
| 15 Mar 2022 | Meta (Facebook)The Irish DPC fined Meta (Facebook) EUR 17,000,000 in case IN-18-11-5. The penalty has been collected. | IE | DPC | GDPR | €17,000,000 | ↗ |
| 23 Jun 2025 | McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures. | PL | President of the Personal Data Protection Office | GDPR | €3,960,000 | ↗ |
| 09 Jul 2020 | Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing. | IT | Garante | GDPR | €16,729,000 | ↗ |
| 21 Feb 2025 | Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches. | AT | Österreichische Datenschutzbehörde | GDPR | €16,000,000 | ↗ |
| 23 Jun 2023 | BKM Budapesti Közművek Nonprofit Zrt.NAIH imposed a 16,000,000 HUF fine on BKM Budapesti Közművek Nonprofit Zrt. for failing to implement adequate technical and organizational measures to protect data security. The authority also found deficiencies in the reporting of a personal data breach. | HU | NAIH | GDPR | €43,200 | ↗ |
| 21 Jun 2021 | Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization. | SE | IMY | GDPR | €1,566,000 | ↗ |
| 25 Jun 2024 | AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta. | SE | IMY | GDPR | €1,336,000 | ↗ |
| 20 Dec 2024 | OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs. | IT | Garante per la protezione dei dati personali | GDPR | €15,000,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE FIXECNIL imposed an administrative fine of EUR 15 million on a fixed-line telecom operator and issued an injunction. The case concerns a breach requiring corrective action and compliance with regulatory obligations. | FR | CNIL | GDPR | €15,000,000 | ↗ |
| 02 Dec 2020 | Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements. | SE | IMY | GDPR | €1,458,000 | ↗ |
| 24 Feb 2026 | Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice. | GB | Information Commissioner's Office | GDPR | €16,606,000 | ↗ |
| 23 Feb 2026 | Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment. | GB | ICO | GDPR | €16,571,000 | ↗ |
| 10 Oct 2025 | Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts. | GB | Information Commissioner's Office | GDPR | €16,074,000 | ↗ |
| 15 Oct 2025 | CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance. | GB | Information Commissioner's Office | GDPR | €16,083,000 | ↗ |
| 15 Oct 2025 | Capita plc and Capita Pension Solutions LtdThe UK Information Commissioner’s Office fined Capita plc and Capita Pension Solutions Ltd a combined £14m after a cyber attack in April 2023. Hackers gained access to the data of more than 6 million people. The case highlights serious weaknesses in data protection and incident response. | GB | ICO | GDPR | €16,083,000 | ↗ |
| 04 Feb 2025 | Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate. | SE | Integritetsskyddsmyndigheten | GDPR | €1,138,000 | ↗ |