Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Dec 2022SOCIETES EXPLOITANT UNE GAMME DE PLATEFORMES DE DISTRIBUTION DE CONTENUSCNIL imposed a fine of 5,000,000 EUR on SOCIETES EXPLOITANT UNE GAMME DE PLATEFORMES DE DISTRIBUTION DE CONTENUS. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€5,000,000
11 Feb 2025Primary Health Care of the Capital AreaThe Icelandic Supervisory Authority imposed an administrative fine on Primary Health Care of the Capital Area for unlawful processing related to the integration of medical record systems. The decision was finalized on 11 February 2025, and the fine amounted to 5,000,000 ISK.ISIcelandic Data Protection AuthorityGDPR€34,100
25 Jun 2019Budapesti Rendőr-főkapitányságBudapesti Rendőr-főkapitányság was fined by NAIH 5,000,000 HUF for failing to report a personal data breach within the 72-hour deadline. The incident involved the loss of a pendrive containing personal data, in breach of GDPR Article 33.HUNAIHGDPR€15,400
01 Jan 2020GOOGLE LLCGoogle LLC was fined by the AEPD EUR 5,000,000 for the unauthorized communication of personal data to the “Lumen Project”. The authority found breaches of the right to erasure and the GDPR requirement for lawful processing.ESAEPDGDPR€5,000,000
22 Mar 2021Engedményezés utáni követeléskezeléssel kapcsolatos adatkezelés jogalapja, érintetti kérelem teljesítéseThe supervisory authority found a GDPR breach in the processing of personal data for debt collection after assignment of a claim. The controller did not establish a proper legal basis, failed to provide clear information about that basis, and did not properly handle data subject requests.HUNAIHGDPR€13,650
20 Dec 2022Tájékoztatás ügyfélszolgálati telefonhívások rögzítésérőlThe entity did not provide adequate prior information about the recording of customer service phone calls. The authority found this to be a breach of GDPR Articles 12 and 13.HUNAIHGDPR€12,400
10 Apr 2025Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR.ITGarante per la protezione dei dati personaliGDPR€5,000,000
22 Jan 2026ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL.FRCNILGDPR€5,000,000
03 May 2022ReykjavíkurborgReykjavíkurborg was fined ISK 5,000,000 by Persónuvernd for using the Seesaw student system in schools without adequate data protection measures. The case concerned children’s personal data and transfers of data to the United States.ISPersónuverndGDPR€36,350
24 May 2022NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people.NODatatilsynetGDPR€485,000
15 Jun 2021Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance.ISPersónuverndGDPR€33,950
02 Mar 2022Személyes adatok nyilvánosságra hozatala online tudakozóbanThe entity did not delete personal data from an online directory after the data subject requested removal. It also failed to demonstrate a lawful basis or consent for publication, resulting in a breach of accountability and unlawful disclosure of personal data.HUNAIHGDPRFt 5,000,000
29 Apr 2024Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13.HUNAIHGDPR€12,750
17 Feb 2025Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing.ISPersónuverndGDPR€34,050
17 Jul 2024Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures.ITGaranteGDPR€5,000,000
06 May 2021Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA.NODatatilsynetGDPR€497,000
04 Oct 2019Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance.HUNAIHGDPR€15,050
22 Jan 2022Dane anonimowe (C. S.A. z siedzibą w M. przy ul.)UODO imposed an administrative fine on the controller and the processor for failing to implement appropriate technical and organizational measures to protect personal data. The breach resulted in a loss of confidentiality, and the controller also failed to properly verify the processor.PLUODOGDPR€1,083,000
15 Dec 2022Edison Energia S.p.A.Edison Energia S.p.A. was fined for running promotional campaigns to non-customers without adequate checks on data lists supplied by third parties. The authority found breaches of GDPR requirements on data processing and consent.ITGaranteGDPR€4,900,000
18 Dec 2024Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements.NLAPGDPR€4,750,000