BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €228,000 | ↗ |
| 27 Sept 2018 | Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €3,111 | ↗ |
| 20 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €54,460 | ↗ |
| 24 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified. | CZ | UOOU | ePrivacy | €391 | ↗ |
| 13 Mar 2019 | Anonymizováno (ÚOOÚ UOOU-12081/17-63)The entity was fined CZK 23,000 by the UOOU for repeatedly sending unsolicited commercial communications without recipients’ consent. The authority found this conduct breached Section 7 of the Czech Act on Certain Information Society Services. | CZ | UOOU | ePrivacy | €896 | ↗ |
| 20 Dec 2019 | Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €4,716 | ↗ |
| 30 Jun 2020 | AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient. | DE | Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg | GDPR | €1,240,000 | ↗ |
| 03 Jun 2025 | VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles. | DE | Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) | GDPR | €45,000,000 | ↗ |
| 01 Jan 2026 | Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €300,000 | ↗ |
| 12 Sept 2025 | A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €35,000 | ↗ |
| 27 Nov 2024 | Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended. | DK | Datatilsynet | GDPR | €53,632 | ↗ |
| 17 Aug 2021 | UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers. | DK | Datatilsynet | GDPR | €20,171 | ↗ |
| 08 Sept 2021 | Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center. | DK | Datatilsynet | GDPR | €40,344 | ↗ |
| 14 Jul 2022 | SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident. | DK | Datatilsynet | GDPR | €67,180 | ↗ |
| 26 Apr 2024 | Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began. | DK | Datatilsynet | GDPR | €6,705 | ↗ |
| 07 Jul 2021 | Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis. | DK | Datatilsynet | GDPR | €13,448 | ↗ |
| 22 Jan 2024 | Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents. | DK | Datatilsynet | GDPR | €26,816 | ↗ |
| 16 Jul 2021 | Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen. | DK | Datatilsynet | GDPR | €67,220 | ↗ |
| 08 Dec 2022 | Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle. | DK | Datatilsynet | GDPR | €47,054 | ↗ |
| 15 May 2020 | JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights. | DK | Datatilsynet | GDPR | €6,705 | ↗ |