BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Dec 2023 | Educational Development Informatikai Zrt.The company failed to implement adequate data security measures and did not report a data breach without undue delay. The authority found breaches of GDPR Articles 32 and 33. | HU | NAIH | GDPR | €286,000 | ↗ |
| 20 Dec 2023 | Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR. | PL | UODO | GDPR | €23,035 | ↗ |
| 20 Dec 2023 | Dane anonimowe (Wójta Gminy P.)UODO imposed a PLN 50,000 administrative fine on the controller for failing to implement appropriate technical and organizational measures proportionate to the risk of processing. The authority found insufficient safeguards for confidentiality, integrity, availability, and resilience of systems, as well as inadequate recovery capability after an incident. | PL | UODO | GDPR | €11,518 | ↗ |
| 19 Dec 2023 | HIPERBAZAR YONGFA 2018 SLHIPERBAZAR YONGFA 2018 SL was fined by the AEPD 5,000 EUR for breaching data protection rules. The case involved the improper sharing of surveillance footage, which was later posted on Facebook, undermining confidentiality and data security requirements. | ES | AEPD | GDPR | €5,000 | ↗ |
| 19 Dec 2023 | Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals. | PL | UODO | GDPR | €2,306 | ↗ |
| 18 Dec 2023 | MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 18 Dec 2023 | Vác Város ÖnkormányzataVác City Municipality was fined by NAIH for GDPR violations related to online parking permit services. The authority found that the website did not provide adequate information and that the municipality failed to comply with data minimization principles. | HU | NAIH | GDPR | €1,295 | ↗ |
| 15 Dec 2023 | O nouă amendă - operator persoană fizicăA fine was imposed on an individual operator for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules. | RO | ANSPDCP | GDPR | €200 | ↗ |
| 15 Dec 2023 | TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined by the AEPD in the amount of 5,000 EUR for breaching data protection rules. The company failed to honor a request to delete personal data and later sent commercial information to the complainant. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Dec 2023 | TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined EUR 5,000 by the AEPD for sending commercial information by email after confirming the deletion of personal data. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 13 Dec 2023 | Dane anonimowe (M. Sp. z o.o. z siedzibą w D. przy ul.)The President of UODO imposed a PLN 23,580 administrative fine on M. Sp. z o.o. The penalty was issued for failing to comply with two administrative decisions issued by the data protection authority. | PL | UODO | GDPR | €5,451 | ↗ |
| 12 Dec 2023 | B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information. | AT | DSB | GDPR | €5,900 | ↗ |
| 12 Dec 2023 | COMMUNECNIL imposed a EUR 5,000 fine on COMMUNE and issued an injunction. The case concerns a regulatory breach requiring corrective action. | FR | CNIL | GDPR | €5,000 | ↗ |
| 11 Dec 2023 | PERSONNALITE POLITIQUE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on PERSONNALITE POLITIQUE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 11 Dec 2023 | Veranda Obor S.A.The National Supervisory Authority for Personal Data Processing imposed a fine on Veranda Obor S.A. for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 11 Dec 2023 | C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information. | AT | DSB | GDPR | €9,500 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 07 Dec 2023 | Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card. | IT | Garante | GDPR | €1,000 | ↗ |
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |