Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Infinite Styles Services Co. Limited (Shein) €150m 90 % · 1 case
- Anonymised companies €7.76m 5 % · 5 cases
- Centros Comerciales Carrefour, S.A. €3.2m 2 % · 1 case
- Elkjøp Nordic AS, Elkjøp Norge AS €1.85m 1 % · 1 case
- Sprinter Megacentros del Deporte, S.L. €1.56m 1 % · 1 case
- Tractor Supply Company €1.16m 1 % · 1 case
- Verkkokauppa.com Oyj €792,639 0 % · 1 case
- Todd Snyder, Inc. €304,793 0 % · 1 case
- Elderly Aids Limited €221,691 0 % · 1 case
- IDdesign A/S €200,986 0 % · 1 case
- 9 more€175,245
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €1.56m |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
1 case
28 Nov 2025 Sprinter Megacentros del Deporte, S.L.AEPD: €1.56m fine for sporting goods retailer Sprinter after data breach €1.56m
Following a cyber attack involving unauthorised access to data, which according to the decision may have affected up to around 6.38 million people (including around 4.67 million customers in Spain as well as employees and former employees), the AEPD as lead authority found inadequate security measures (Art. 5(1)(f) GDPR). The sanction of 2,600,000 EUR was reduced by 40% to 1,560,000 EUR because liability was acknowledged and payment made voluntarily; remedial measures were also ordered.
Large holdings of customer and employee data need protective measures commensurate with their volume and sensitivity.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 1,000 to 9,999
- Mitigating circumstances
- 40% reduction for acknowledgement of liability and voluntary payment (Art. 85 LPACAP).
- Published
- 19 Dec 2025
- AEPD, Resolución PS/00373/2025 (EXP202401683), Sprinter Megacentros del Deporte Decision of an authority
- BOE: Resolución de 10 de diciembre de 2025 der AEPD, Sanktionen über 1 Mio. Euro Official register or notice
Checked against the official source on 28 Sep 2026 · Direct link