BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Apr 2024 | Fiziska personaA fine of EUR 150 was imposed by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €150 | ↗ |
| 01 Apr 2024 | Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 28 Mar 2024 | SIA “JK Media group”The DVI imposed a fine of EUR 1,000 on SIA “JK Media group”. The decision is final and has entered into force. | LV | DVI | GDPR | €1,000 | ↗ |
| 25 Mar 2024 | KUR KLINIKUM, S.L.KUR KLINIKUM, S.L. was fined EUR 1,000 by the AEPD for failing to comply with a data protection authority resolution. The case concerned the right of access to personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Mar 2024 | NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 21 Mar 2024 | Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.). | HU | NAIH | GDPR | €762 | ↗ |
| 21 Mar 2024 | Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €120,000 | ↗ |
| 21 Mar 2024 | Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Mar 2024 | Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Mar 2024 | LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services. | IT | Garante | GDPR | €271,000 | ↗ |
| 20 Mar 2024 | Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights. | IS | Persónuvernd | GDPR | €10,095 | ↗ |
| 19 Mar 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 19 Mar 2024 | LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined by the AEPD 10,000 EUR for storing cookies without user consent and for failing to provide a legal notice on its website. The case concerns breaches of data protection rules and website transparency obligations. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 15 Mar 2024 | LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide information requested by the data protection authority during an investigation. The conduct breached Article 58(1) GDPR and hindered supervisory oversight. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Mar 2024 | SARARTE, S.L.SARARTE, S.L. was fined 6,000 EUR by the AEPD for disclosing personal data, including a private mobile number, to 18 people without consent. The case indicates a breach of data protection rules and unauthorized sharing of information. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Mar 2024 | DKN.5131.28.2023StatusprawomocnaTytuUODO imposed an administrative fine of PLN 78,575.4 for failing to report a personal data breach without undue delay. The incident was not notified to the supervisory authority within 72 hours of becoming aware of the breach. | PL | UODO | GDPR | €18,331 | ↗ |
| 12 Mar 2024 | Dane anonimowe (U.)An administrative fine was imposed for failing to notify the supervisory authority of a personal data breach within the required 72 hours after detection. The authority also found that the affected individuals were not informed without undue delay. | PL | UODO | GDPR | €336,000 | ↗ |