Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Anonymised companies €14.7m 25 % · 11 cases
- Woori Card Co., Ltd. €8.51m 14 % · 1 case
- Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia) €5.51m 9 % · 1 case
- Hyundai Marine & Fire Insurance Co., Ltd. €4.12m 7 % · 1 case
- Versicherer, Spanien (anonymisiert) €4m 7 % · 1 case
- Kakaopay Corp. €3.99m 7 % · 1 case
- Großbank, Spanien (anonymisiert) €3.5m 6 % · 1 case
- Experian Nederland B.V. €2.7m 5 % · 1 case
- S-Pankki Oyj €1.8m 3 % · 1 case
- ING Bank N.V., Sucursal en España €1.6m 3 % · 1 case
- 28 more€8.46m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €3.5m |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
12 Dec 2024 Großbank, Spanien (anonymisiert)AEPD: EUR 3.5 million fine on a major bank as an authorised person could view another account €3.5m
A person authorised for only two of the accounts of a customer of a major Spanish bank was able, in online banking, to view the financial information of a joint account held by the customer with another co-holder, for which that person had no authorisation. The Spanish data protection authority AEPD imposed EUR 500,000 (Art. 5(1)(f)) and EUR 3,000,000 for lack of data protection by design (Art. 25), EUR 3,500,000 in total, dropped the Art. 32 charge and ordered adjustments; the request for reconsideration was dismissed.
Online banking permissions must be cleanly separated per account; an authorisation must not extend to other people's products.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 25 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- AEPD, Resoluciones (Übersicht) (Entscheidung 2024) Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link