Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- TikTok Technology Limited €530m 44 % · 1 case
- Meta Platforms Ireland Limited €342m 28 % · 2 cases
- Google LLC und Google Ireland Limited €325m 27 % · 1 case
- Netflix International B.V. €4.75m 0 % · 1 case
- Vinted, UAB €2.39m 0 % · 1 case
- Disney DTC, LLC und ABC Enterprises, Inc. (The Walt Disney Company) €2.31m 0 % · 1 case
- Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo) €1.4m 0 % · 1 case
- Healthline Media LLC €1.31m 0 % · 1 case
- Les Publications Condé Nast €750,000 0 % · 1 case
- Mediaworks Hungary Zrt. €140,706 0 % · 1 case
- 5 more€13,604
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 2 | €93.4m |
| Q4 2024 | 3 | €255.8m |
| Q1 2025 | 1 | €13,604 |
| Q2 2025 | 1 | €530m |
| Q3 2025 | 4 | €326.3m |
| Q4 2025 | 2 | €750,000 |
| Q1 2026 | 2 | €3.71m |
| Q2 2026 | 2 | €140,706 |
| Q3 2026 | 0 | — |
17 cases
26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters €140,706
On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.
Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.
Handling leaked personal data in newsrooms
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- intentional
- Published
- 26 May 2026
Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.
- NAIH/962-10/2026 – Határozat (Mediaworks Hungary Zrt.) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years Fine
The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.
‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Mitigating circumstances
- Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.
- Datatilsynet – Gyldendal indstilles til bøde (Opdatering: afgjort 14. april 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Feb 2026 Disney DTC, LLC und ABC Enterprises, Inc. (The Walt Disney Company)California: $2.75 million against Disney over incomplete opt-outs for streaming €2.31m
Disney implemented objections to the sale and sharing of data only for individual services or devices rather than across the whole account, continued to disclose data via embedded ad-tech providers and offered no opt-out in connected TV apps. It was the largest CCPA settlement at the time of the agreement with the Attorney General of California.
An opt-out must take effect across all services, devices and integrated third-party providers of an account.
- Authority / court
- Attorney General of California (California Department of Justice)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 11 Feb 2026
Original amount 2,750,000 USD, converted at the ECB reference rate of 11 Feb 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent €750,000
On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.
A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Published
- 27 Nov 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Sep 2025 TikTok Pte. Ltd.Canadian regulators: TikTok inadequately protected children's data Other
The joint investigation by the Office of the Privacy Commissioner of Canada and the supervisory authorities of Québec, British Columbia and Alberta found that every year hundreds of thousands of children used the platform despite the minimum age of 13, and that TikTok processed data without valid consent, including for profiling and advertising. TikTok undertook to improve age verification and make privacy notices easier to understand, and already during the investigation largely stopped targeted advertising to under-18s (except by broad categories such as language and approximate location).
Age limits in the terms of use are not enough – platforms need effective age verification and child-appropriate transparency.
- Authority / court
- Office of the Privacy Commissioner of Canada gemeinsam mit den Aufsichten von Québec, British Columbia und Alberta
- Area of law
- Data protection · Marketing and consent
- Legal basis
- PIPEDA und Datenschutzgesetze für den Privatsektor von Québec, British Columbia und Alberta
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 23 Sep 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Sep 2025 Google LLC und Google Ireland LimitedGoogle: 325 million EUR – advertising cookies at account creation and ads in the Gmail inbox €325m
When creating a Google account, users were not sufficiently informed that advertising cookies were necessarily placed in the process; in addition, Google displayed advertisements between e-mails in Gmail without prior consent. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 200 million EUR on Google LLC and 125 million EUR on Google Ireland and ordered remedial action within six months, subject to a penalty payment of 100,000 EUR per day.
Do not tacitly tie advertising cookies to account creation – and advertising in the inbox counts as direct marketing requiring consent.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés; Art. L. 34-5 Code des postes et des communications électroniques
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner €6,200
In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.
Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- DSB Straferkenntnis GZ 2025-0.276.820 vom 06.08.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Jul 2025 Healthline Media LLCCalifornia: $1.55 million against Healthline over disclosure of illness-related article titles €1.31m
Despite objections, the health portal continued to pass data to advertising partners and transmitted article titles suggestive of diagnoses for targeted advertising; the consent banner did not stop the tracking. In addition, the required contractual clauses with advertising partners were missing. The settlement was reached with the Attorney General of California.
Test consent banners technically: if rejecting does not actually switch off tracking, that is misleading and unlawful.
- Authority / court
- Attorney General of California (California Department of Justice)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- California Consumer Privacy Act (CCPA), Unfair Competition Law
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 1 Jul 2025
Original amount 1,550,000 USD, converted at the ECB reference rate of 1 Jul 2025.
- Attorney General Bonta Announces Largest CCPA Settlement to Date, Secures $1.55 Million from Healthline.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China €530m
TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.
Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 46 Abs. 1, Art. 13 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 2 May 2025
- Irish Data Protection Commission fines TikTok €530 million and orders corrective measures Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication €13,604
Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.
Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.
Protection of data subjects in press reports; encryption of storage media
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Published
- 11 Mar 2025
Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.
- Kara dla Polskiego Radia Szczecin za brak procedur chroniących prawa bohaterów publikacji Press release of an authority
- WSA oddalił skargę na decyzję Prezesa UODO w sprawie kary dla Radia Szczecin Press release of an authority
- Decyzja DKN.5112.10.2024 z 6 marca 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification €251m
In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).
Make data breach notifications complete, and document every breach internally in a traceable manner.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 17 Dec 2024
- Irish Data Protection Commission fines Meta €251 Million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 Netflix International B.V.AP: 4.75 million EUR against Netflix over insufficient privacy information €4.75m
Between 2018 and 2020, Netflix did not adequately inform customers about what happens to their data, and the information available was partly unclear. The Dutch supervisory authority (Autoriteit Persoonsgegevens, AP) imposed 4.75 million EUR; Netflix has since revised its privacy statement.
Privacy notices must be complete and comprehensible – and responses to customer requests must also be specific rather than generic.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a i. V. m. Art. 12 Abs. 1, Art. 13 Abs. 1 lit. c, e, f und Abs. 2 lit. a, Art. 15 Abs. 1 lit. a, c, d und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- The privacy statement and the information provided were subsequently improved.
- Published
- 18 Dec 2024
- Boete Netflix (Besluit van 26 november 2024) Decision of an authority
- AP – Boete Netflix voor niet goed informeren klanten Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) Other
In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.
Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.
- Authority / court
- Bundesgerichtshof (VI. Zivilsenat)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 82 Abs. 1 DSGVO
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 18 Nov 2024
- BGH Pressemitteilung Nr. 218/2024 – Leitentscheidung zum Scraping Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2024 Meta Platforms Ireland LimitedIreland: 91 million EUR against Meta over plaintext passwords €91m
Meta stored users' passwords unencrypted in plaintext in internal systems and reported this to Ireland's Data Protection Commission (DPC) in March 2019. The DPC found infringements of the security obligations (Art. 5(1)(f), Art. 32(1)) and of the notification and documentation obligations (Art. 33(1) and (5)), and additionally issued a reprimand.
Never store or log passwords in plaintext – not even in internal systems.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 und 5
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- According to the DPC, the passwords were not disclosed to external third parties.
- Published
- 27 Sep 2024
- Irish Data Protection Commission fines Meta Ireland €91 million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2024 Vinted, UABVinted pays 2.39 million EUR over ‘shadow banning’ and handling of erasure requests €2.39m
Acting on complaints from France and Poland, the Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that the second-hand platform rejected erasure requests when users did not state a ‘specific reason’ under Art. 17 GDPR, throttled users without their knowledge through ‘shadow banning’ and could not demonstrate how it handled access requests. Fine of 2,385,276 EUR. Source: archived copy of the press release.
Covert restrictions on users are non-transparent – and erasure requests must not fail on formalities such as a requirement to give reasons.
- Authority / court
- Valstybinė duomenų apsaugos inspekcija (VDAI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 5 Abs. 2, Art. 12 Abs. 1 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 3 Jul 2024
- VDAI, Pranešimas 2024-07-03 (Archivkopie web.archive.org von vdai.lrv.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link