Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

15cases from 13 jurisdictions
€154.3mTotal of monetary amounts (12 cases with an amount)
€197,993Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€1.5m
Q4 20240—
Q1 20251€500
Q2 20253€364,793
Q3 20254€151.6m
Q4 20250—
Q1 20262—
Q2 20263€887,639
Q3 20261€1,000

15 cases

2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR LatviaCookies and tracking €1,000

In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.

What organisations can take from it

Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.

Relevance to training and awareness

Cookie banners and cooperation with the supervisory authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit FinlandData subject rights and transparency €792,639

The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.

What organisations can take from it

Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.

Authority / court
Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
18 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage GreeceVideo surveillance €95,000

A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.

What organisations can take from it

Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.

Relevance to training and awareness

Handling video footage and access requests

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising SwitzerlandMarketing and consent Order

Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.

What organisations can take from it

An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.

Relevance to training and awareness

Handling objections to advertising and deletion requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Marketing and consent
Legal basis
DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements LuxembourgMarketing and consent overturned

In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.

What organisations can take from it

Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.

Authority / court
Cour administrative (Luxemburg); Verfahren der CNPD
Area of law
Data protection · Marketing and consent
Legal basis
Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
Action
Order
Status of proceedings
overturned
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Amazon had implemented the compliance order before the hearing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 Loblaw Companies LimitedOPC: Loblaw must change retention of PC Optimum data after account deletion CanadaData subject rights and transparency Other

During a wave of boycotts in 2024, Loblaw did not process deletion requests in time and retained purchase and usage data from the loyalty programme (more than 17 million members) even after accounts were closed, without demonstrating effective anonymisation. Loblaw undertook to the Office of the Privacy Commissioner of Canada (OPC) to have the anonymisation independently reviewed and to carry out annual deletions.

What organisations can take from it

Companies that continue to use data as anonymous after account deletion must be able to demonstrate the re-identification risk – IP addresses are often enough to link data to a person.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
PIPEDA
Action
Other
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
5 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests GermanyData subject rights and transparency €195,000

A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).

What organisations can take from it

Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.

Relevance to training and awareness

Timely handling of access requests

Authority / court
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Betroffenenrechte)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
30 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2025 Tractor Supply CompanyCPPA: $1.35 million against Tractor Supply over missing opt-out mechanisms USA, CAData subject rights and transparency €1.16m

The rural retail giant inadequately informed consumers and job applicants about their rights, offered no effective means of opting out of the sale and sharing of data (including no Global Privacy Control) and passed data on to third parties without the required contracts. An officer must certify compliance annually for four years, as required by the California Privacy Protection Agency (CPPA).

What organisations can take from it

Privacy notices must also cover job applicants, and browser opt-out signals such as GPC must be implemented technically.

Authority / court
California Privacy Protection Agency (CPPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more
Published
30 Sep 2025

Original amount 1,350,000 USD, converted at the ECB reference rate of 26 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Sep 2025 IDdesign A/SIDdesign: High Court raises GDPR fine to 1.5 million DKK – group turnover counts DenmarkData protection €200,986

The furniture retailer had stored data of around 385,000 customers in a legacy system without retention periods. The district court had imposed 100,000 DKK; following a referral to the CJEU on whether the fine is to be calculated on the basis of the turnover of the entire group, the High Court increased the fine to 1.5 million DKK.

What organisations can take from it

Retention periods also apply to legacy systems in individual branches – and the group turnover counts when setting the fine.

Authority / court
Vestre Landsret (auf Anzeige der Datatilsynet)
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 83
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Original amount 1,500,000 DKK, converted at the ECB reference rate of 2 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Infinite Styles Services Co. Limited (Shein)Shein: 150 million EUR – cookies without consent and despite rejection FranceCookies and tracking €150m

On shein.com, advertising cookies were placed without consent as soon as the site was accessed; in addition to an incomplete cookie banner, there was an advertising pop-up without an option to reject. After clicking ‘Reject all’ or withdrawing consent, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 150 million EUR.

What organisations can take from it

A cookie banner must work technically: rejecting and withdrawing consent must actually stop cookies from being placed and read.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Umsetzung von Art. 5 Abs. 3 ePrivacy-Richtlinie)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 AS Watson (Health & Beauty Continental Europe) B.V.AP reduces cookie fine against Kruidvat operator AS Watson to 50,000 EUR after objection NetherlandsCookies and tracking €50,000

The company behind the Kruidvat drugstore chain tracked visitors to Kruidvat.nl with tracking cookies without their knowledge or consent, enabling it to build profiles from location, pages visited, shopping basket and purchases. The Dutch data protection authority (Autoriteit Persoonsgegevens, AP) had imposed 600,000 EUR in 2024, upheld the objection in May 2025 and reduced the fine to 50,000 EUR.

What organisations can take from it

Set tracking cookies in an online shop only after genuine consent – pre-ticked or hidden consent is not sufficient.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 6 Abs. 1 i. V. m. Art. 5 Abs. 1 lit. a DSGVO (Tracking-Cookies ohne Einwilligung)
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
12 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 May 2025 Todd Snyder, Inc.Todd Snyder: 345,178 USD – tracking opt-out ineffective for 40 days USA, CACookies and tracking €304,793

For 40 days, the fashion retailer’s misconfigured privacy portal did not process objections to the sale and sharing of personal data; in addition, the company required too much data and identity verification before an opt-out. The California Privacy Protection Agency (CPPA) imposed 345,178 USD and required correct configuration of consent management and employee training.

What organisations can take from it

A consent management platform does not relieve companies of responsibility: check regularly whether opt-outs are actually implemented technically.

Relevance to training and awareness

Configuration and monitoring of consent management platforms

Missing or inadequate training played a role in the decision.

Authority / court
California Privacy Protection Agency (CPPA), Board
Area of law
Data protection · Cookies and tracking
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce

Original amount 345,178 USD, converted at the ECB reference rate of 6 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Apr 2025 Dante International SADante International fails to act on erasure requests – 10,000 EUR RomaniaData subject rights and transparency €10,000

Although the platform operator had repeatedly confirmed to a customer that his e-mail addresses had been deleted, he continued to receive feedback requests; in addition, certain partners could see the address. The Romanian data protection authority (ANSPDCP) found breaches of transparency and erasure obligations, imposed 49,770 lei (10,000 EUR) and ordered, among other things, training of the staff responsible.

What organisations can take from it

A confirmed erasure must actually be implemented in all systems – including feedback and partner tools.

Relevance to training and awareness

Handling erasure requests in customer service

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12 Abs. 1 i. V. m. Art. 17 und 19 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
24 Apr 2025

Original amount 49,770 RON, converted at the ECB reference rate of 24 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2025 SIA "VSV ZOO"Pet shop VSV ZOO fails to respond to review of privacy policy – 500 EUR LatviaData subject rights and transparency €500

As part of a preventive review of the privacy policy on zoopasaule.lv, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) repeatedly asked the online pet retailer for information from July 2024 onwards. The company let the first deadlines lapse, later twice asked for an extension citing the absence of its programmer, and still did not deliver thereafter. The DVI imposed 500 EUR for failure to cooperate with the supervisory authority.

What organisations can take from it

A preventive request from the supervisory authority is also binding – anyone who does not respond is sanctioned before the actual deficiency is even addressed.

Relevance to training and awareness

Handling letters from the data protection authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. d und e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Aug 2024 DSB: 1.5 million EUR against retail chain over cameras on self-checkouts, PIN pad and surroundings AustriaVideo surveillance €1.5m

In 2022, a retail company (name pseudonymised) used nine cameras in one branch to film, among other things, the self-service checkouts including the keypad of the card payment terminal, as well as public areas, bus stops and neighbouring properties. The Austrian data protection authority (Datenschutzbehörde, DSB) imposed 1.5 million EUR for lack of a legal basis and infringement of data minimisation; the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the amount on 25 July 2025, and an appeal on points of law is pending.

What organisations can take from it

Align cameras in retail closely with their protective purpose – PIN entries, public spaces and neighbouring properties must not be in the frame.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial