BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Apr 2026 | Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose. | SI | Informacijski pooblaščenec | GDPR | €6,000 | ↗ |
| 25 Jul 2025 | Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract. | SI | IP-RS | GDPR | €5,610 | ↗ |
| 29 Jul 2025 | Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness. | SI | IP-RS | GDPR | €10,614 | ↗ |
| 01 Dec 2025 | Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop. | SI | IP-RS | GDPR | €1,000 | ↗ |
| 26 Nov 2025 | Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR. | SI | IP-RS | GDPR | €6,000 | ↗ |
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 13 Aug 2025 | Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR. | SI | IP-RS | GDPR | €500 | ↗ |
| 22 Jul 2025 | Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements. | SI | IP-RS | GDPR | €2,000 | ↗ |
| 08 Dec 2025 | Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR. | SI | IP-RS | GDPR | €4,800 | ↗ |
| 02 Dec 2020 | Sahlgrenska UniversitetssjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €340,000 | ↗ |
| 11 May 2020 | Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32. | SE | IMY | GDPR | €11,321 | ↗ |
| 07 Jun 2021 | Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000. | SE | IMY | GDPR | €64,643 | ↗ |
| 28 Mar 2022 | Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making. | SE | IMY | GDPR | €719,000 | ↗ |
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |
| 26 Feb 2025 | SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed. | SE | Integritetsskyddsmyndigheten | GDPR | €538,000 | ↗ |
| 04 Feb 2025 | Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate. | SE | Integritetsskyddsmyndigheten | GDPR | €1,138,000 | ↗ |
| 09 Jun 2021 | Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures. | SE | IMY | GDPR | €34,794 | ↗ |
| 12 Jun 2023 | Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language. | SE | IMY | GDPR | €4,992,000 | ↗ |
| 03 Jun 2025 | Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €5,309,000 | ↗ |
| 28 Aug 2023 | Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1). | SE | IMY | GDPR | €2,941,000 | ↗ |