Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €582,573 |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 2 | €140,080 |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
3 cases
25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR €125,083
In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).
Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 25 Mar 2026
Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.
- ANSPDCP – Comunicat de presă 25.03.2026 (RENAULT COMMERCIAL ROUMANIE S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR €14,997
An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.
Handling employees’ health data, e-mail distribution lists
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 19 Jan 2026
Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.
- ANSPDCP – Comunicat de presă 19.01.2026 (Continental Automotive Products SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Mar 2025 American Honda Motor Co., Inc.CPPA: $632,500 against Honda over obstructed privacy requests €582,573
Honda required excessive information for opt-out requests, used a cookie tool without equivalent choices, made it harder to appoint authorised agents and passed data on to ad-tech firms without the required contracts. The order of the California Privacy Protection Agency (CPPA) requires, among other things, a simplified procedure and training for employees.
Do not undermine data subject rights through form hurdles or asymmetric consent dialogues.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Automotive
- Employees
- 10,000 or more
- Published
- 12 Mar 2025
Original amount 632,500 USD, converted at the ECB reference rate of 7 Mar 2025.
- CPPA: Enforcement action against American Honda Motor Co. Press release of an authority
- CPPA Order of Decision: American Honda Motor Co., Inc. (ENF23-V-HO-2) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link