BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Jul 2023 | Hozzáférési kérelem nemteljesítéseThe controller did not respond to the access request within the one-month deadline. It also failed to provide substantive information about the processing of personal data, in breach of GDPR Articles 12 and 15. | HU | NAIH | GDPR | €26,300 | ↗ |
| 18 Jun 2021 | Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights. | HU | NAIH | GDPR | €28,100 | ↗ |
| 24 Mar 2021 | Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals. | HU | NAIH | GDPR | €27,400 | ↗ |
| 01 Jan 2025 | AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data. | ES | AEPD | GDPR | €9,000,000 | ↗ |
| 11 Dec 2019 | Eni Gas e Luce S.p.A.Eni Gas e Luce S.p.A. was fined EUR 8,500,000 by the Garante for making unsolicited telemarketing calls without consent. The conduct also affected individuals who had opted out or were listed in the public opposition register. | IT | Garante | GDPR | €8,500,000 | ↗ |
| 15 Jan 2021 | VODAFONE ESPAÑA, S.A.U.The Spanish data protection authority imposed a total fine of EUR 8,150,000 on VODAFONE ESPAÑA, S.A.U. The sanction covers breaches of GDPR Articles 28 and 44, as well as additional violations of LSSICE and tax-related rules. | ES | Agencia Española de Protección de Datos | GDPR | €8,150,000 | ↗ |
| 10 Dec 2020 | Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing. | HU | NAIH | GDPR | €22,480 | ↗ |
| 10 Dec 2020 | Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds. | HU | NAIH | GDPR | €22,480 | ↗ |
| 13 Nov 2023 | Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv. | HU | NAIH | GDPR | €21,200 | ↗ |
| 29 Dec 2022 | SOCIETE CREANT ET COMMERCIALISANT DES PRODUITS ELECTRONIQUES GRAND PUBLIC, DES ORDINATEURS PERSONNELS ET DES LOGICIELSCNIL imposed a fine of 8,000,000 EUR on SOCIETE CREANT ET COMMERCIALISANT DES PRODUITS ELECTRONIQUES GRAND PUBLIC, DES ORDINATEURS PERSONNELS ET DES LOGICIELS. The case concerned breaches of personal data protection rules. | FR | CNIL | GDPR | €8,000,000 | ↗ |
| 29 Aug 2024 | Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR. | SE | IMY | GDPR | €705,000 | ↗ |
| 28 Mar 2022 | Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making. | SE | IMY | GDPR | €719,000 | ↗ |
| 27 Apr 2020 | Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34. | HU | NAIH | GDPR | €21,150 | ↗ |
| 23 Nov 2021 | atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance. | IS | Persónuvernd | GDPR | €50,850 | ↗ |
| 27 Jun 2023 | eCommerce 2020 ApSeCommerce 2020 ApS was fined by Persónuvernd in the amount of 7,500,000 ISK for registering loan defaults with Creditinfo Lánstrausti hf. without meeting the required conditions. The authority noted, among other issues, that claims below the minimum threshold were registered. The case concerns improper handling of debt-related personal data. | IS | Persónuvernd | GDPR | €50,400 | ↗ |
| 15 May 2026 | Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €19,460 | ↗ |
| 02 Aug 2022 | Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability. | HU | NAIH | GDPR | €17,640 | ↗ |
| 17 Apr 2026 | Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles. | IT | Garante | GDPR | €6,624,000 | ↗ |
| 01 Jan 2023 | PHONE HOUSEPHONE HOUSE was fined by the AEPD for failing to ensure data integrity and confidentiality. The breach resulted in a data incident caused by a cyberattack. | ES | AEPD | GDPR | €6,500,000 | ↗ |
| 01 Feb 2019 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis. | ES | AEPD | GDPR | €6,500,000 | ↗ |