Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jan 2024Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis.HUNAIHGDPR€2,580
03 Mar 2020Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle.NLAPGDPR€525,000
16 Feb 2026KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR.ESAEPDGDPR€500,000
02 Nov 2023KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List.ESAEPDePrivacy€5,000
24 Mar 2025Komendant Główny PolicjiThe President of the Polish data protection authority imposed an administrative fine of PLN 75,000 on the Commander-in-Chief of the Police. The authority found that, during a press conference, personal data and health information of a woman were disclosed without a legal basis.PLUrząd Ochrony Danych OsobowychGDPR€17,960
19 Mar 2025Komendanta Głównego PolicjiUODO imposed an administrative fine of PLN 75,000 on the Chief Police Commander. The decision was based on breaches of Article 6(1) and Article 9(1) of Regulation 2016/679 concerning the processing of personal data and special-category data.PLUODOGDPR€17,906
29 Dec 2025KomendantaUODO imposed an administrative fine of PLN 40,000 on Komendanta for unlawful processing of personal data, including special category data, by publishing it on a website without a legal basis. The authority also found that appropriate technical and organizational measures were not implemented and ordered the processing operations to be brought into compliance with GDPR requirements.PLUODOGDPR€9,457
01 Jan 2019KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis.NLAutoriteit PersoonsgegevensGDPR€525,000
05 Jul 2017Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
07 Nov 2025Klass Wagen S.R.L.Klass Wagen S.R.L. was fined by ANSPDCP EUR 7,000 for failing to promptly report a personal data breach. The incident involved unauthorized access to its contract management system after a former employee disclosed credentials, affecting personal data of many individuals, including data subjects from other EU member states.ROANSPDCPGDPR€7,000
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
12 Feb 2026Klab s.r.l.Klab s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to obtain valid consent for marketing purposes. The authority also found that the company did not provide adequate information about the legal basis for data processing, in breach of GDPR requirements.ITGaranteGDPR€1,000
18 Jun 2021Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed.HUNAIHGDPR€14,050
28 Jul 2025KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications.ESAEPDePrivacy€15,000
04 Apr 2013Kinesi s.r.l.Kinesi s.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through a website form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
16 Jan 2023Kildare County CouncilThe Irish DPC imposed a fine of EUR 50,000 on Kildare County Council in inquiry 05/SIU/2018. The fine has been collected.IEDPCGDPR€50,000
11 Apr 2013Kihria S.r.l.Kihria S.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate information about data collection through a website contact form. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
15 Feb 2021KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF.HUNAIHGDPR€4,185
16 Dec 2020[...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group.HUNAIHGDPR€1,012
04 Oct 2019Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance.HUNAIHGDPR€15,050