Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Curenergía Comercializador de Último Recurso, S.A.U. 1 case 13 % · €500,000
- Enel Energia S.p.A. 1 case 13 % · €79.1m
- HEP-Toplinarstvo d.o.o. 1 case 13 % · €320,000
- Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt) 1 case 13 % · €6,000
- Société Wallonne des Eaux (SWDE) 1 case 13 % · €86,000
- South Staffordshire Plc und South Staffordshire Water Plc 1 case 13 % · €1.12m
- Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC) 1 case 13 % ·
- Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank) 1 case 13 % · €110,000
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €79.1m |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €320,000 |
| Q4 2025 | 1 | €500,000 |
| Q1 2026 | 0 | — |
| Q2 2026 | 4 | €1.32m |
| Q3 2026 | 0 | — |
8 cases
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency €86,000
The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.
Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.
Recording of customer calls
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- APD – Décision quant au fond n° 102/2026 du 12 mai 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack €1.12m
In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.
Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.
Recognising phishing
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- 40% reduction for early admission of liability; payment agreed without appeal.
- Published
- 11 May 2026
Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.
- Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach Press release of an authority
- ICO Enforcement: South Staffordshire Plc and South Staffordshire Water Plc Enforcement database of an authority
- ICO Monetary Penalty Notice: South Staffordshire Plc and South Staffordshire Water Plc Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles €6,000
A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.
GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.
GPS tracking and employee data protection
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Liability of senior managers
- Additional fine of 600 EUR on the responsible person.
- Published
- 15 Apr 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat €500,000
An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.
Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.
Diligence in customer service / misdirected messages
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 25 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- AEPD Resolución PS/00190/2024 (EXP202316394) Decision of an authority
- AEPD Resolución recurso de reposición PS/00190/2024 (Datum der Ausgangsentscheidung 22.12.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords €320,000
The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).
Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.
Secure password storage in software development
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 31, Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 22 Jul 2025
- Izrečene dvije upravne novčane kazne u iznosu od 370.000 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Mar 2025 Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC)Cyprus: reprimand for electricity supplier EAC over insecure app registration Reprimand or warning
A customer denied having registered in the EAC Mobile App and having changed his billing address there; the supplier could not prove that the mobile number used for identification originated from the customer himself. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) found breaches of accountability and data security, issued a reprimand and ordered the delivery address to be clarified with the customer in writing.
Self-registration in customer portals needs robust identity verification – otherwise invoices and data can be redirected.
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24, Art. 32 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Απόφαση – Γνωστοποίηση παραβίασης, Εφαρμογή EAC Mobile App (11.03.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Feb 2024 Enel Energia S.p.A.Garante: record fine of 79 million EUR against Enel Energia over illegal telemarketing €79.1m
Unauthorised intermediaries exploited security gaps in Enel's customer and activation systems for illegal telemarketing; over several years, at least 9,300 contracts were activated, 978 of which were purchased from companies outside the sales network. The Italian data protection authority (Garante per la protezione dei dati personali) imposed 79,107,101 EUR; the Rome court (Tribunale di Roma) upheld the decision on 18 September 2025, and an appeal is pending.
Companies that organise sales through partners must secure their systems against third-party access and reject contracts from unknown sources.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO; Codice privacy (Telemarketing)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- Employees
- 10,000 or more
- Published
- 29 Feb 2024
- Telemarketing: il Garante privacy sanziona Enel Energia Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link