Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

8cases from 8 jurisdictions
€81.2mTotal of monetary amounts (7 cases with an amount)
€79.1mLargest single case: Enel Energia S.p.A.
€320,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20241€79.1m
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20251—
Q2 20250—
Q3 20251€320,000
Q4 20251€500,000
Q1 20260—
Q2 20264€1.32m
Q3 20260—

8 cases

5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) GreeceData subject rights and transparency €110,000

Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.

What organisations can take from it

Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency BelgiumData subject rights and transparency €86,000

The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.

What organisations can take from it

Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.

Relevance to training and awareness

Recording of customer calls

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack United KingdomData breaches and data security €1.12m

In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.

What organisations can take from it

Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.

Relevance to training and awareness

Recognising phishing

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
40% reduction for early admission of liability; payment agreed without appeal.
Published
11 May 2026

Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles SloveniaEmployee data €6,000

A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.

What organisations can take from it

GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.

Relevance to training and awareness

GPS tracking and employee data protection

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Liability of senior managers
Additional fine of 600 EUR on the responsible person.
Published
15 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat SpainData processors €500,000

An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.

What organisations can take from it

Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.

Relevance to training and awareness

Diligence in customer service / misdirected messages

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data processors
Legal basis
Art. 25 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords CroatiaData breaches and data security €320,000

The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).

What organisations can take from it

Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.

Relevance to training and awareness

Secure password storage in software development

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 31, Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
22 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Mar 2025 Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC)Cyprus: reprimand for electricity supplier EAC over insecure app registration CyprusData breaches and data security Reprimand or warning

A customer denied having registered in the EAC Mobile App and having changed his billing address there; the supplier could not prove that the mobile number used for identification originated from the customer himself. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) found breaches of accountability and data security, issued a reprimand and ordered the delivery address to be clarified with the customer in writing.

What organisations can take from it

Self-registration in customer portals needs robust identity verification – otherwise invoices and data can be redirected.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24, Art. 32 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Feb 2024 Enel Energia S.p.A.Garante: record fine of 79 million EUR against Enel Energia over illegal telemarketing ItalyMarketing and consent €79.1m

Unauthorised intermediaries exploited security gaps in Enel's customer and activation systems for illegal telemarketing; over several years, at least 9,300 contracts were activated, 978 of which were purchased from companies outside the sales network. The Italian data protection authority (Garante per la protezione dei dati personali) imposed 79,107,101 EUR; the Rome court (Tribunale di Roma) upheld the decision on 18 September 2025, and an appeal is pending.

What organisations can take from it

Companies that organise sales through partners must secure their systems against third-party access and reject contracts from unknown sources.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO; Codice privacy (Telemarketing)
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities
Employees
10,000 or more
Published
29 Feb 2024
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial