BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Dec 2022 | SOCIETES EXPLOITANT UNE GAMME DE PLATEFORMES DE DISTRIBUTION DE CONTENUSCNIL imposed a fine of 5,000,000 EUR on SOCIETES EXPLOITANT UNE GAMME DE PLATEFORMES DE DISTRIBUTION DE CONTENUS. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €5,000,000 | ↗ |
| 11 Feb 2025 | Primary Health Care of the Capital AreaThe Icelandic Supervisory Authority imposed an administrative fine on Primary Health Care of the Capital Area for unlawful processing related to the integration of medical record systems. The decision was finalized on 11 February 2025, and the fine amounted to 5,000,000 ISK. | IS | Icelandic Data Protection Authority | GDPR | €34,100 | ↗ |
| 25 Jun 2019 | Budapesti Rendőr-főkapitányságBudapesti Rendőr-főkapitányság was fined by NAIH 5,000,000 HUF for failing to report a personal data breach within the 72-hour deadline. The incident involved the loss of a pendrive containing personal data, in breach of GDPR Article 33. | HU | NAIH | GDPR | €15,400 | ↗ |
| 01 Jan 2020 | GOOGLE LLCGoogle LLC was fined by the AEPD EUR 5,000,000 for the unauthorized communication of personal data to the “Lumen Project”. The authority found breaches of the right to erasure and the GDPR requirement for lawful processing. | ES | AEPD | GDPR | €5,000,000 | ↗ |
| 22 Mar 2021 | Engedményezés utáni követeléskezeléssel kapcsolatos adatkezelés jogalapja, érintetti kérelem teljesítéseThe supervisory authority found a GDPR breach in the processing of personal data for debt collection after assignment of a claim. The controller did not establish a proper legal basis, failed to provide clear information about that basis, and did not properly handle data subject requests. | HU | NAIH | GDPR | €13,650 | ↗ |
| 20 Dec 2022 | Tájékoztatás ügyfélszolgálati telefonhívások rögzítésérőlThe entity did not provide adequate prior information about the recording of customer service phone calls. The authority found this to be a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €12,400 | ↗ |
| 10 Apr 2025 | Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR. | IT | Garante per la protezione dei dati personali | GDPR | €5,000,000 | ↗ |
| 22 Jan 2026 | ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €5,000,000 | ↗ |
| 03 May 2022 | ReykjavíkurborgReykjavíkurborg was fined ISK 5,000,000 by Persónuvernd for using the Seesaw student system in schools without adequate data protection measures. The case concerned children’s personal data and transfers of data to the United States. | IS | Persónuvernd | GDPR | €36,350 | ↗ |
| 24 May 2022 | NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people. | NO | Datatilsynet | GDPR | €485,000 | ↗ |
| 15 Jun 2021 | Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance. | IS | Persónuvernd | GDPR | €33,950 | ↗ |
| 02 Mar 2022 | Személyes adatok nyilvánosságra hozatala online tudakozóbanThe entity did not delete personal data from an online directory after the data subject requested removal. It also failed to demonstrate a lawful basis or consent for publication, resulting in a breach of accountability and unlawful disclosure of personal data. | HU | NAIH | GDPR | Ft 5,000,000 | ↗ |
| 29 Apr 2024 | Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13. | HU | NAIH | GDPR | €12,750 | ↗ |
| 17 Feb 2025 | Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing. | IS | Persónuvernd | GDPR | €34,050 | ↗ |
| 17 Jul 2024 | Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures. | IT | Garante | GDPR | €5,000,000 | ↗ |
| 06 May 2021 | Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA. | NO | Datatilsynet | GDPR | €497,000 | ↗ |
| 04 Oct 2019 | Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance. | HU | NAIH | GDPR | €15,050 | ↗ |
| 22 Jan 2022 | Dane anonimowe (C. S.A. z siedzibą w M. przy ul.)UODO imposed an administrative fine on the controller and the processor for failing to implement appropriate technical and organizational measures to protect personal data. The breach resulted in a loss of confidentiality, and the controller also failed to properly verify the processor. | PL | UODO | GDPR | €1,083,000 | ↗ |
| 15 Dec 2022 | Edison Energia S.p.A.Edison Energia S.p.A. was fined for running promotional campaigns to non-customers without adequate checks on data lists supplied by third parties. The authority found breaches of GDPR requirements on data processing and consent. | IT | Garante | GDPR | €4,900,000 | ↗ |
| 18 Dec 2024 | Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements. | NL | AP | GDPR | €4,750,000 | ↗ |