Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Aug 2020Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services.CZUOOUePrivacy€228,000
27 Sept 2018Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€3,111
20 Aug 2018Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services.CZUOOUePrivacy€54,460
24 Oct 2019Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified.CZUOOUePrivacy€391
13 Mar 2019Anonymizováno (ÚOOÚ UOOU-12081/17-63)The entity was fined CZK 23,000 by the UOOU for repeatedly sending unsolicited commercial communications without recipients’ consent. The authority found this conduct breached Section 7 of the Czech Act on Certain Information Society Services.CZUOOUePrivacy€896
20 Dec 2019Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€4,716
30 Jun 2020AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient.DELandesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-WürttembergGDPR€1,240,000
03 Jun 2025VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles.DEBundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)GDPR€45,000,000
01 Jan 2026Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€300,000
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
27 Nov 2024Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended.DKDatatilsynetGDPR€53,632
17 Aug 2021UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers.DKDatatilsynetGDPR€20,171
08 Sept 2021Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center.DKDatatilsynetGDPR€40,344
14 Jul 2022SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident.DKDatatilsynetGDPR€67,180
26 Apr 2024Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began.DKDatatilsynetGDPR€6,705
07 Jul 2021Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis.DKDatatilsynetGDPR€13,448
22 Jan 2024Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents.DKDatatilsynetGDPR€26,816
16 Jul 2021Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen.DKDatatilsynetGDPR€67,220
08 Dec 2022Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle.DKDatatilsynetGDPR€47,054
15 May 2020JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights.DKDatatilsynetGDPR€6,705