Klarna fined over £570,000 for GDPR violations

Buy Now, Pay Later (BNPL) pioneer Klarna has been handed a SEK7.5 million (£574,000 fine) for violating the EU's General Data Protection Regulation (GDPR) rules.

On Monday, Sweden's Administrative Court of Appeal ruled in favour of the Swedish Authority for Privacy Protection (IMY), formerly the Swedish Data Protection Agency (SDPA), which said in March 2022 that Klarna had not complied with GDPR rule around how it informs users about its handling of their personal data.

The court concluded that Klarna failed to give clients sufficient information about how it would store their personal data and that the privacy notes were unclear or difficult to access. The case specifically related to privacy notes used between March and June 2020, though Klarna has since updated those terms and conditions.

GDPR compels companies to inform users and clients about how and why they handle personal data, including ‘the right to be forgotten' where individuals can make a request for erasure verbally or in writing.

Monday’s ruling restores the fine to the full amount originally sought by the SDPA after a lower court last year reduced the fine to SEK6 million (£459,000).

A spokesperson for the company told Reuters that it was “too early to comment” on the ruling. In response to the original report in 2022 Klarna said that the case revolved around the privacy information provided to clients, and that it had nothing to do with its actual data collection or handling processes.



Share Story:

Recent Stories


Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.

Legacy isn’t the enemy: what FSIs can do to keep their systems up and running
In this webinar we will examine some of the steps FSIs have already taken to rigorously monitor and test systems – both manually and with AI-powered automation – while satisfying the concerns of regulators and customers.

Optimising digital banking: Unifying communications for seamless CX
In the digital age, financial institutions risk falling behind their rivals if they fail to unite fragmented communications ecosystems to deliver seamless, personalised customer experiences.

This FStech webinar sponsored by Precisely explores vital strategies to optimise cross-channel messaging through omnichannel orchestration and real-time customer data access.