Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Nov 2023Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv.HUNAIHGDPR€21,200
11 Jan 2023KENAI MEDIA, S.L.KENAI MEDIA, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case concerned the publication of a video featuring the complainant without proper consent.ESAEPDGDPR€10,000
28 Feb 2019Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF.HUNAIHGDPR€3,160
29 Sept 2021K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured.ITGaranteGDPR€5,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined by ANSPDCP €2,000 for a data security breach. The case concerned an incident affecting data protection and required supervisory authority action.ROANSPDCPGDPR€2,000
27 Dec 2022Kaufland România SCSKaufland România SCS was fined by ANSPDCP EUR 3,000 for GDPR violations. The investigation was completed in November 2022.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for a data security breach. The case concerns an incident affecting data protection and resulted in an administrative sanction.ROANSPDCPGDPR€2,000
03 Jun 2022Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for failing to follow internal complaint procedures. This allowed a security guard to improperly access and misuse personal data, resulting in a breach of data confidentiality.ROANSPDCPGDPR€2,000
05 Dec 2024KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities.FRCNILGDPR€200,000
05 Dec 2024KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights.FRCNILGDPR€240,000
02 Dec 2020Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€389,000
12 May 2021KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued.GRHDPAGDPR€5,000
24 Aug 2023Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13.HUNAIHGDPR€2,600
17 Jul 2020Kamera munkahelyi ebédlőben és munkavégzésre kialakított helyiségbenThe authority found that the controller unlawfully processed employees' personal data through a surveillance system without a valid legal basis. It also failed to provide adequate prior information, breaching GDPR principles of purpose limitation, data minimization, and fairness.HUNAIHGDPR€1,415
25 Mar 2021Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing.HUNAIHGDPR€1,370
19 Mar 2020Kamerafelvételek korlátozása, kiadása érintetti kérésreThe controller did not provide adequate information on processing restrictions and access rights related to surveillance camera footage. The authority found this to breach the accountability principle.HUNAIHGDPR€5,620
31 May 2019Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach.HUNAIHGDPR€2,156
26 May 2022Kalemci MusaThe sole proprietorship “Turkish City” was fined 2,000 EUR by the Garante. The authority found that its video surveillance system did not meet the information requirements under GDPR Article 13.ITGaranteGDPR€2,000
09 Jul 2025KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements.ESAEPDGDPR€900