Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Feb 2022Név2.The controller unlawfully processed and published personal data, including images, without consent, breaching multiple GDPR provisions. NAIH imposed a fine of 10,000,000 HUF.HUNAIHGDPR€28,200
18 Dec 2024Netflix International B.V.Netflix International B.V. was fined EUR 4,750,000 by the Dutch data protection authority AP. The authority found that the company did not provide sufficient information to customers in its privacy statement and in responses to data access requests, breaching GDPR transparency and information requirements.NLAPGDPR€4,750,000
26 Nov 2024NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests.NLAutoriteit PersoonsgegevensGDPR€4,750,000
09 Aug 2022Nemzeti Egészségbiztosítási AlapkezelőNemzeti Egészségbiztosítási Alapkezelő was fined by NAIH 500,000 HUF. The authority found that the organization failed to provide transparent information to data subjects and did not cooperate during the inspection, breaching GDPR transparency and accountability principles.HUNAIHGDPR€1,260
17 May 2024Nem közszereplő személyes és különleges adatainak online sajtótermékben történő nyilvánosságra hozatalaThe controller published personal data in an online news outlet without a valid legal basis. It also failed to delete unlawfully processed personal data, resulting in breaches of several GDPR provisions.HUNAIHGDPR€25,800
11 Sept 2024NEGOCIOS R&R 2020 S.L.NEGOCIOS R&R 2020 S.L. was fined by the AEPD 12,000 EUR for failing to provide access under Article 58(1) of the GDPR. The authority treated this as a serious breach of data protection obligations.ESAEPDGDPR€12,000
01 Jan 2012NECESIDADES INFORMATICAS, S.L.NECESIDADES INFORMATICAS, S.L. was fined EUR 600 by the AEPD for sending a commercial email without the recipient’s prior consent. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€600
09 Mar 2021NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD €20,000 for processing personal data without a legal basis. The case was related to identity theft in a microcredit contract.ESAEPDGDPR€20,000
03 Feb 2021NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident.ESAEPDGDPR€40,000
15 Feb 2018Nazzareno SalernoNazzareno Salerno was fined for unlawful processing of personal data by sending electoral propaganda emails without proper consent. This breached Garante rules on data handling by political parties.ITGaranteGDPR€12,000
16 Apr 2010NAVIRCONET, S.LNAVIRCONET, S.L was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
27 Jun 2022NAVThe Norwegian DPA fined NAV 5,000,000 NOK for making CVs available on arbeidsplassen.no without a lawful basis under the GDPR. The case concerned unauthorized processing of personal data relating to job seekers and employees.NODatatilsynetGDPR€480,000
24 May 2022NAVThe Norwegian DPA, Datatilsynet, notified NAV of a NOK 5 million fine for making job seekers’ CVs available on arbeidsplassen.no without a legal basis. The issue affected more than 1.8 million people.NODatatilsynetGDPR€485,000
04 Dec 2014Nautica Cicuttin s.r.l.Nautica Cicuttin s.r.l. was fined by the Garante 2,400 EUR for providing inadequate information to data subjects about the processing of personal data collected through a web form on its website. The breach concerned the duty to provide clear information before collecting the data.ITGaranteGDPR€2,400
05 Mar 2012NAUTALIA VIAJES, S.L.NAUTALIA VIAJES, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial messages without prior consent from recipients. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€1,200
11 Jul 2013Naturmedia s.r.l.Naturmedia s.r.l. was fined EUR 2,400 by the Italian Garante. The case concerned the collection of personal data without providing the required information notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
01 Jan 2023NATURGY IBERIA, S.A.Naturgy Iberia was fined for changing a customer's gas and electricity supplier without authorization. The authority found that this breached Article 6(1) of the GDPR because there was no lawful basis for the processing.ESAEPDGDPR€100,000
24 Mar 2023NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing.ESAEPDGDPR€10,000
12 Aug 2021NATURAL LOGISTICS, S.L.NATURAL LOGISTICS, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient's objection. This breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€3,000
26 Apr 2024Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began.DKDatatilsynetGDPR€6,705