Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Jun 2023Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes.SEIMYGDPR€1,112,000
01 Apr 2023TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully.GBInformation Commissioner's OfficeGDPR€14,444,000
15 May 2023TikTok Information Technologies UK Limited and TikTok Inc (TikTok)The UK ICO imposed a fine of 12,700,000 GBP on TikTok Information Technologies UK Limited and TikTok Inc for multiple breaches of data protection law. The regulator specifically cited unlawful use of children’s personal data.GBICOGDPR€14,607,000
12 Nov 2020Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined by the Garante 12,251,601 EUR for making unauthorized promotional calls and sending messages. The authority also found that effective measures to ensure data processing security and GDPR compliance were not in place.ITGaranteGDPR€12,251,000
07 Jun 2021MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing.SEIMYGDPR€1,193,000
02 Dec 2020Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements.SEIMYGDPR€1,167,000
27 Jun 2023embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards.ISPersónuverndGDPR€80,640
21 Mar 2019Demokratikus KoalícióThe Democratic Coalition was fined by NAIH 11,000,000 HUF for failing to meet incident notification and data subject communication obligations. The case involved a data breach affecting high-risk special category data.HUNAIHGDPR€34,980
21 Mar 2019Demokratikus KoalícióDemocratic Coalition was fined HUF 11,000,000 by the NAIH for failing to report a personal data breach. The authority also found that affected individuals were not informed, contrary to GDPR Articles 33 and 34.HUNAIHGDPR€34,980
DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych Osobowych€2,568,000
03 Sept 2025AENA, S.M.E., S.A.The AEPD imposed a fine of EUR 10,043,002 on AENA, S.M.E., S.A. for processing passenger personal data in a manner deemed unnecessary and disproportionate. The authority found that the company’s practices breached data protection rules.ESAEPDGDPR€10,043,000
08 Feb 2023SatsThe Norwegian DPA, Datatilsynet, fined Sats 10,000,000 NOK for breaches of GDPR requirements. The case concerned data subjects' rights to information, access, and erasure, as well as the lack of a legal basis for processing certain personal data.NODatatilsynetGDPR€906,000
31 Jan 2024Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements.NLAPGDPR€10,000,000
29 Dec 2023SOCIETE PROPOSANT DES SERVICES DE TELECOMUNICATIONCNIL imposed a fine of EUR 10,000,000 on SOCIETE PROPOSANT DES SERVICES DE TELECOMUNICATION. The case concerns breaches of personal data protection rules.FRCNILGDPR€10,000,000
26 Sept 2022TV2 Média Csoport Zrt.NAIH imposed a 10,000,000 HUF fine on TV2 Média Csoport Zrt. for insufficient user information and improper consent management on its websites. The authority found that these practices breached the principles of fair and transparent data processing.HUNAIHGDPR€24,500
11 Feb 2025A követeléskezelő társaságNAIH imposed a HUF 10 million fine on a debt collection company for continuing to process personal data after a court declared the debt time-barred. The company ignored the data subject’s deletion request and kept the case active in its system.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€24,800
10 Feb 2022Név2.The controller unlawfully processed and published personal data, including images, without consent, breaching multiple GDPR provisions. NAIH imposed a fine of 10,000,000 HUF.HUNAIHGDPR€28,200
28 Sept 2023Axpo Italia S.p.A.Axpo Italia S.p.A. was fined by the Garante 10,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the conclusion of unsolicited contracts for electricity and gas supply.ITGaranteGDPR€10,000,000
24 Jul 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés és törlési kérelem nem teljesítéseThe authority imposed a fine for a negligent GDPR breach involving the processing of personal data without a legal basis in connection with debt collection. It also found that deletion requests from the data subject were not fulfilled.HUNAIHGDPR€25,100
17 May 2024Nem közszereplő személyes és különleges adatainak online sajtótermékben történő nyilvánosságra hozatalaThe controller published personal data in an online news outlet without a valid legal basis. It also failed to delete unlawfully processed personal data, resulting in breaches of several GDPR provisions.HUNAIHGDPR€25,800