Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Jul 2023Hozzáférési kérelem nemteljesítéseThe controller did not respond to the access request within the one-month deadline. It also failed to provide substantive information about the processing of personal data, in breach of GDPR Articles 12 and 15.HUNAIHGDPR€26,300
18 Jun 2021Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights.HUNAIHGDPR€28,100
24 Mar 2021Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals.HUNAIHGDPR€27,400
01 Jan 2025AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data.ESAEPDGDPR€9,000,000
11 Dec 2019Eni Gas e Luce S.p.A.Eni Gas e Luce S.p.A. was fined EUR 8,500,000 by the Garante for making unsolicited telemarketing calls without consent. The conduct also affected individuals who had opted out or were listed in the public opposition register.ITGaranteGDPR€8,500,000
15 Jan 2021VODAFONE ESPAÑA, S.A.U.The Spanish data protection authority imposed a total fine of EUR 8,150,000 on VODAFONE ESPAÑA, S.A.U. The sanction covers breaches of GDPR Articles 28 and 44, as well as additional violations of LSSICE and tax-related rules.ESAgencia Española de Protección de DatosGDPR€8,150,000
10 Dec 2020Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing.HUNAIHGDPR€22,480
10 Dec 2020Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds.HUNAIHGDPR€22,480
13 Nov 2023Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv.HUNAIHGDPR€21,200
29 Dec 2022SOCIETE CREANT ET COMMERCIALISANT DES PRODUITS ELECTRONIQUES GRAND PUBLIC, DES ORDINATEURS PERSONNELS ET DES LOGICIELSCNIL imposed a fine of 8,000,000 EUR on SOCIETE CREANT ET COMMERCIALISANT DES PRODUITS ELECTRONIQUES GRAND PUBLIC, DES ORDINATEURS PERSONNELS ET DES LOGICIELS. The case concerned breaches of personal data protection rules.FRCNILGDPR€8,000,000
29 Aug 2024Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€705,000
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
27 Apr 2020Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34.HUNAIHGDPR€21,150
23 Nov 2021atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance.ISPersónuverndGDPR€50,850
27 Jun 2023eCommerce 2020 ApSeCommerce 2020 ApS was fined by Persónuvernd in the amount of 7,500,000 ISK for registering loan defaults with Creditinfo Lánstrausti hf. without meeting the required conditions. The authority noted, among other issues, that claims below the minimum threshold were registered. The case concerns improper handling of debt-related personal data.ISPersónuverndGDPR€50,400
15 May 2026Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€19,460
02 Aug 2022Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability.HUNAIHGDPR€17,640
17 Apr 2026Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles.ITGaranteGDPR€6,624,000
01 Jan 2023PHONE HOUSEPHONE HOUSE was fined by the AEPD for failing to ensure data integrity and confidentiality. The breach resulted in a data incident caused by a cyberattack.ESAEPDGDPR€6,500,000
01 Feb 2019CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis.ESAEPDGDPR€6,500,000