BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Jan 2024 | Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis. | HU | NAIH | GDPR | €2,580 | ↗ |
| 03 Mar 2020 | Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle. | NL | AP | GDPR | €525,000 | ↗ |
| 16 Feb 2026 | KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €500,000 | ↗ |
| 02 Nov 2023 | KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 24 Mar 2025 | Komendant Główny PolicjiThe President of the Polish data protection authority imposed an administrative fine of PLN 75,000 on the Commander-in-Chief of the Police. The authority found that, during a press conference, personal data and health information of a woman were disclosed without a legal basis. | PL | Urząd Ochrony Danych Osobowych | GDPR | €17,960 | ↗ |
| 19 Mar 2025 | Komendanta Głównego PolicjiUODO imposed an administrative fine of PLN 75,000 on the Chief Police Commander. The decision was based on breaches of Article 6(1) and Article 9(1) of Regulation 2016/679 concerning the processing of personal data and special-category data. | PL | UODO | GDPR | €17,906 | ↗ |
| 29 Dec 2025 | KomendantaUODO imposed an administrative fine of PLN 40,000 on Komendanta for unlawful processing of personal data, including special category data, by publishing it on a website without a legal basis. The authority also found that appropriate technical and organizational measures were not implemented and ordered the processing operations to be brought into compliance with GDPR requirements. | PL | UODO | GDPR | €9,457 | ↗ |
| 01 Jan 2019 | KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis. | NL | Autoriteit Persoonsgegevens | GDPR | €525,000 | ↗ |
| 05 Jul 2017 | Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 07 Nov 2025 | Klass Wagen S.R.L.Klass Wagen S.R.L. was fined by ANSPDCP EUR 7,000 for failing to promptly report a personal data breach. The incident involved unauthorized access to its contract management system after a former employee disclosed credentials, affecting personal data of many individuals, including data subjects from other EU member states. | RO | ANSPDCP | GDPR | €7,000 | ↗ |
| 28 Mar 2022 | Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making. | SE | IMY | GDPR | €719,000 | ↗ |
| 12 Feb 2026 | Klab s.r.l.Klab s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to obtain valid consent for marketing purposes. The authority also found that the company did not provide adequate information about the legal basis for data processing, in breach of GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 18 Jun 2021 | Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed. | HU | NAIH | GDPR | €14,050 | ↗ |
| 28 Jul 2025 | KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 04 Apr 2013 | Kinesi s.r.l.Kinesi s.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through a website form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Jan 2023 | Kildare County CouncilThe Irish DPC imposed a fine of EUR 50,000 on Kildare County Council in inquiry 05/SIU/2018. The fine has been collected. | IE | DPC | GDPR | €50,000 | ↗ |
| 11 Apr 2013 | Kihria S.r.l.Kihria S.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate information about data collection through a website contact form. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 15 Feb 2021 | KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF. | HU | NAIH | GDPR | €4,185 | ↗ |
| 16 Dec 2020 | [...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group. | HU | NAIH | GDPR | €1,012 | ↗ |
| 04 Oct 2019 | Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance. | HU | NAIH | GDPR | €15,050 | ↗ |