BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Nov 2023 | Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv. | HU | NAIH | GDPR | €21,200 | ↗ |
| 11 Jan 2023 | KENAI MEDIA, S.L.KENAI MEDIA, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case concerned the publication of a video featuring the complainant without proper consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 28 Feb 2019 | Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF. | HU | NAIH | GDPR | €3,160 | ↗ |
| 29 Sept 2021 | K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Aug 2024 | Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 22 Aug 2024 | Kaufland România SCSKaufland România SCS was fined by ANSPDCP €2,000 for a data security breach. The case concerned an incident affecting data protection and required supervisory authority action. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 27 Dec 2022 | Kaufland România SCSKaufland România SCS was fined by ANSPDCP EUR 3,000 for GDPR violations. The investigation was completed in November 2022. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 22 Aug 2024 | Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for a data security breach. The case concerns an incident affecting data protection and resulted in an administrative sanction. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 03 Jun 2022 | Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for failing to follow internal complaint procedures. This allowed a security guard to improperly access and misuse personal data, resulting in a breach of data confidentiality. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities. | FR | CNIL | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights. | FR | CNIL | GDPR | €240,000 | ↗ |
| 02 Dec 2020 | Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €389,000 | ↗ |
| 12 May 2021 | KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued. | GR | HDPA | GDPR | €5,000 | ↗ |
| 24 Aug 2023 | Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €2,600 | ↗ |
| 17 Jul 2020 | Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness. | HU | NAIH | GDPR | €1,415 | ↗ |
| 25 Mar 2021 | Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing. | HU | NAIH | GDPR | €1,370 | ↗ |
| 19 Mar 2020 | Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle. | HU | NAIH | GDPR | €5,620 | ↗ |
| 31 May 2019 | Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach. | HU | NAIH | GDPR | €2,156 | ↗ |
| 26 May 2022 | Kalemci MusaThe sole proprietorship “Turkish City” was fined 2,000 EUR by the Garante. The authority found that its video surveillance system did not meet the information requirements under GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 09 Jul 2025 | KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements. | ES | AEPD | GDPR | €900 | ↗ |