Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Anonymised companies €14.7m 25 % · 11 cases
- Woori Card Co., Ltd. €8.51m 14 % · 1 case
- Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia) €5.51m 9 % · 1 case
- Hyundai Marine & Fire Insurance Co., Ltd. €4.12m 7 % · 1 case
- Versicherer, Spanien (anonymisiert) €4m 7 % · 1 case
- Kakaopay Corp. €3.99m 7 % · 1 case
- Großbank, Spanien (anonymisiert) €3.5m 6 % · 1 case
- Experian Nederland B.V. €2.7m 5 % · 1 case
- S-Pankki Oyj €1.8m 3 % · 1 case
- ING Bank N.V., Sucursal en España €1.6m 3 % · 1 case
- 28 more€8.46m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €4m |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Dec 2024 Versicherer, Spanien (anonymisiert)AEPD: EUR 4m fine for an insurer after access via a broker account €4m
Following several complaints about a data breach, the Spanish data protection authority AEPD found that an attacker using an insurance broker's credentials was able to access extensive data held by an insurer, including on former customers, because basic security measures, separation of datasets and an impact assessment were lacking. Fines of 1,000,000 EUR (Art. 5(1)(f)), 1,000,000 EUR (Art. 32), 2,000,000 EUR (Art. 25) and 1,000,000 EUR (Art. 35) were set, 5,000,000 EUR in total; after voluntary payment without admission of liability, 4,000,000 EUR became payable.
External accounts such as those of brokers need strong authentication and must only reach the data that is actually required.
Securing intermediary and partner accounts
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, 25, 32, 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- 20% reduction for voluntary payment (Art. 85 LPACAP), without admission of liability.
- Published
- 13 May 2025
- AEPD, Resoluciones (Übersicht) (Entscheidung 2024) Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link