Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Feb 2021KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR.ESAEPDGDPR€3,000
01 Jan 2023KUGELCHEN PROPIERTIES, S.L.KUGELCHEN PROPIERTIES, S.L. was fined by the AEPD EUR 2,000 for processing personal data without consent. The company continued charging a customer despite requests to delete personal data and stop transactions.ESAEPDGDPR€2,000
18 Jan 2018KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code.ITGaranteGDPR€180,000
18 May 2022Kredyt Inkaso Investments RO S.A.The company unlawfully processed personal data by disclosing it excessively, including health data. The authority found a breach of personal data processing principles.ROANSPDCPGDPR€5,000
01 Jan 2016KREDITECH SPAIN, S.L.KREDITECH SPAIN, S.L. was fined by the AEPD 5,000 EUR for continuing to send commercial emails to a complainant after the complainant exercised the right to data deletion. The authority found this conduct breached the LSSI.ESAEPDePrivacy€5,000
24 Sept 2015KREDITECH SPAIN S.L.KREDITECH SPAIN S.L. was fined by the AEPD in the amount of 2,600 EUR for sending unsolicited commercial emails to a complainant. The authority found this conduct to be in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,600
11 Feb 2021Krajową Szkołę Sądownictwa i Prokuratury z siedzibą w Z.,UODO imposed a PLN 100,000 administrative fine on the National School of Judiciary and Public Prosecution. The authority found that the entity failed to implement appropriate technical and organizational measures to ensure the ongoing confidentiality of processing services and breached GDPR Article 28(3).PLUODOGDPR€22,235
12 Jun 2025Krajowa Szkoła Sądownictwa i Prokuratury (KSSiP)The President of the Polish data protection authority imposed a PLN 100,000 fine on the National School of Judiciary and Public Prosecution for breaching data protection rules during a data migration. The Supreme Administrative Court upheld the decision, making the sanction final.PLUrząd Ochrony Danych OsobowychGDPR€23,425
29 Sept 2021Kræftens BekæmpelseKræftens Bekæmpelse was fined by Datatilsynet 75,000 DKK for inadequate protection of sensitive health data. The incident affected at least 1,448 individuals and resulted from missing security measures that allowed unauthorized access to personal data.DKDatatilsynetGDPR€10,086
20 May 2026KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service.GBICOePrivacy€346,000
02 Nov 2021Közterület megfigyelése magánszemély általThe case concerned unlawful processing of personal data through surveillance cameras installed on a property. The authority found breaches of GDPR Articles 5, 6, and 13 and imposed a fine of HUF 50,000 on the controller.HUNAIHGDPR€139
02 Mar 2022Közös Nevező 2018 párt és dr. Gődény György aláírásgyűjtéshez kapcsolódó adatkezelésének jogszerűségeThe NAIH imposed a HUF 3,000,000 fine on entities involved in a signature campaign against mandatory vaccinations. The authority found that personal data were collected without meeting GDPR requirements on lawfulness, purpose limitation, transparency, and information provision.HUNAIHGDPR€7,860
30 Sept 2020Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis.HUNAIHGDPR€2,740
04 Sept 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection.HUNAIHGDPR€2,540
24 Jul 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés és törlési kérelem nem teljesítéseThe authority imposed a fine for a negligent GDPR breach involving the processing of personal data without a legal basis in connection with debt collection. It also found that deletion requests from the data subject were not fulfilled.HUNAIHGDPR€25,100
13 Jan 2023Követelésérvényesítési célú adatkezelés és ahhoz kapcsolódó érdekmérlegelés, továbbá adattovábbítások jogszerűségének kérdéseThe authority found unlawful data processing related to credit account management and debt collection. A fine was imposed on the controller for breaching GDPR requirements.HUNAIHGDPR€2,520
17 Dec 2021Kormánytisztviselő jogviszonyának megszűnésével összefüggésben egészségügyi adat kezelése, és erre irányuló hozzáférés megtagadásaThe authority found that the controller unlawfully denied access to personal data and failed to provide complete information about data processed in connection with the termination of employment. This breached GDPR Articles 12, 14, and 15.HUNAIHGDPR€1,632
06 Jul 2006Korallina Tours s.r.l.Korallina Tours s.r.l. was fined EUR 2,582 by the Garante for sending unsolicited promotional emails. The case concerns a breach of data protection obligations, including the duty to provide information to the authority under applicable law.ITGaranteGDPR€2,582
02 May 2023KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards.ISPersónuverndGDPR€26,720
19 Mar 2026KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes.ISPersónuverndGDPR€20,910