Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

23cases from 14 jurisdictions
€20.2mTotal of monetary amounts (18 cases with an amount)
€498,750Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€5.47m
Q1 20240—
Q2 20240—
Q3 20241€950,490
Q4 20242€950,000
Q1 20255€305,000
Q2 20252€920,000
Q3 20254€1.9m
Q4 20253€3.87m
Q1 20260—
Q2 20263€278,500
Q3 20262€5.51m

23 cases

3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection ItalyMarketing and consent €5.51m

For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).

What organisations can take from it

An objection to advertising must take effect immediately and reliably across all channels – including app messages.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data SwitzerlandData subject rights and transparency Order

The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.

What organisations can take from it

Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.

Authority / court
Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 6, Art. 19, Art. 31
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection MaltaMarketing and consent €1,000

Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.

What organisations can take from it

An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.

Relevance to training and awareness

Passing marketing objections on to service providers (suppression lists)

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ FranceCookies and tracking €1.5m

When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.

What organisations can take from it

Cookie settings must apply across all domains of a service – including when users move to affiliated sites.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Corrections during the proceedings, cooperation.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login FinlandData breaches and data security €865,000

Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.

What organisations can take from it

Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
28 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service FinlandData breaches and data security €1.8m

After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.

What organisations can take from it

Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
Published
10 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR RomaniaData breaches and data security €2,990

A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.

What organisations can take from it

Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.

Relevance to training and awareness

Identity verification and fraud detection in remote applications

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
12 Aug 2025

Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers EstoniaData subject rights and transparency Order

The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.

What organisations can take from it

Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data CroatiaData breaches and data security €101,000

Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.

Relevance to training and awareness

Access control and deletion periods for register data

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cap due to public tasks (Art. 44 of the Implementing Act).
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2025 CaixaBank, S.A.AEPD: 200,000 EUR against CaixaBank over continued storage of a non-customer's data SpainMarketing and consent €200,000

A person who was not (or no longer) a customer received a letter from CaixaBank about an update to its privacy statement, announcing that she would be contacted about her advertising preferences. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) considered the continued storage of her data to be an infringement of the principle of storage limitation and imposed 200,000 EUR; the bank's request for reconsideration was dismissed as inadmissible.

What organisations can take from it

Before mass mailings, check whether the recipients' data may still be stored at all – former customers should be deleted, not written to.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2025 Iberinform Internacional, S.A.AEPD: 720,000 EUR against business information agency Iberinform for purchased data on entrepreneurs SpainData subject rights and transparency €720,000

Since 2008, Iberinform had obtained data on sole traders through a supply contract with Camerdata and used it to enrich its own files for commercial information services. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found no legal basis for this and no information of the data subjects, and imposed 360,000 EUR for each (720,000 EUR in total) as well as an order to bring the processing into compliance; the request for reconsideration (recurso de reposición) was rejected.

What organisations can take from it

Companies that purchase personal data from third parties need their own legal basis and must actively inform the data subjects.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 14 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long CyprusData subject rights and transparency €10,000

The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.

What organisations can take from it

Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent CyprusData breaches and data security Reprimand or warning

An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.

What organisations can take from it

Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.

Relevance to training and awareness

Disclosure of customer data to agents and colleagues in their own matters

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The company implemented the order

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms SwitzerlandData subject rights and transparency Order

From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.

What organisations can take from it

Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.

Relevance to training and awareness

Handling access requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
1 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jan 2025 Εθνική Τράπεζα της Ελλάδος Α.Ε. (National Bank of Greece)Greece: 120,000 EUR against National Bank of Greece after misdirected payment via mobile number GreeceData breaches and data security €120,000

An IRIS transfer made by mobile number via the bank’s app ended up with an uninvolved customer instead of the intended recipient because the number had been assigned incorrectly. By Decision 3/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed 100,000 EUR for inaccurate data, insufficient security, lack of data protection by design and failure to notify the data breach, as well as 20,000 EUR for breach of the right of access.

What organisations can take from it

Even a single misdirected payment can be a notifiable data breach – customer complaints must be assessed internally as a possible incident.

Relevance to training and awareness

Recognising and reporting data breaches

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. d und f, Art. 15, 25, 32, 33, 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Jan 2025 Luxembourg credit institution: 175,000 EUR for late responses to data subject requests LuxembourgData subject rights and transparency €175,000

Following 47 complaints, the Commission nationale pour la protection des données (Luxembourg data protection authority, CNPD) found that a Luxembourg credit institution (pseudonymised in the decision as ‘Société A’) had not responded to data subjects’ requests on time; the CNPD did not accept the reference to the COVID-19 pandemic. It issued a reprimand (rappel à l’ordre) and imposed 175,000 EUR.

What organisations can take from it

Data subject requests require deadline tracking and a monitored DPO mailbox – staff shortages are no excuse.

Relevance to training and awareness

Deadlines for data subject requests

Authority / court
Commission nationale pour la protection des données (CNPD) – formation restreinte
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 12 Abs. 3 und 4
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father CyprusEmployee data Reprimand or warning

A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.

What organisations can take from it

HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.

Relevance to training and awareness

Confidential delivery of HR correspondence

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links FinlandData breaches and data security €950,000

On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.

What organisations can take from it

Personal links are not access protection – sensitive customer data requires authentication and regular security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
20 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing PolandData breaches and data security €950,490

In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.

What organisations can take from it

Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.

Relevance to training and awareness

Misdirected documents and notification of data subjects

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
9 Sep 2024

Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Oct 2023 EOS Matrix d.o.o.Croatia: 5.47 million EUR against debt collection company EOS Matrix after data leak CroatiaData breaches and data security €5.47m

An anonymous tip-off accompanied by a USB stick proved that data of 181,641 debtors had leaked from the debt collection company’s records; there were no systems for detecting unusual data retrievals. In addition, EOS Matrix stored health data up to and including diagnoses, data of non-debtors and call recordings without a legal basis; the Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 5.47 million EUR.

What organisations can take from it

Employees’ free-text notes can turn into impermissible health data – clear recording rules and monitoring of data retrievals are mandatory.

Relevance to training and awareness

No recording of health data in call notes

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 2, Art. 6 Abs. 1, Art. 9 Abs. 2, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Oct 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial