Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

17cases from 12 jurisdictions
€1.21bnTotal of monetary amounts (13 cases with an amount)
€530mLargest single case: TikTok Technology Limited
€2.31mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20242€93.4m
Q4 20243€255.8m
Q1 20251€13,604
Q2 20251€530m
Q3 20254€326.3m
Q4 20252€750,000
Q1 20262€3.71m
Q2 20262€140,706
Q3 20260—

17 cases

26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters HungaryData protection €140,706

On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.

What organisations can take from it

Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.

Relevance to training and awareness

Handling leaked personal data in newsrooms

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection
Legal basis
DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
intentional
Published
26 May 2026

Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years DenmarkData protection Fine

The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.

What organisations can take from it

‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Feb 2026 Disney DTC, LLC und ABC Enterprises, Inc. (The Walt Disney Company)California: $2.75 million against Disney over incomplete opt-outs for streaming USA, CACookies and tracking €2.31m

Disney implemented objections to the sale and sharing of data only for individual services or devices rather than across the whole account, continued to disclose data via embedded ad-tech providers and offered no opt-out in connected TV apps. It was the largest CCPA settlement at the time of the agreement with the Attorney General of California.

What organisations can take from it

An opt-out must take effect across all services, devices and integrated third-party providers of an account.

Authority / court
Attorney General of California (California Department of Justice)
Area of law
Data protection · Cookies and tracking
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more
Published
11 Feb 2026

Original amount 2,750,000 USD, converted at the ECB reference rate of 11 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts EU levelData subject rights and transparency —

On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.

What organisations can take from it

Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.

Authority / court
Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
Status of proceedings
unknown
Sector
Media and online platforms
Published
2 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent FranceCookies and tracking €750,000

On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.

What organisations can take from it

A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Published
27 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Sep 2025 TikTok Pte. Ltd.Canadian regulators: TikTok inadequately protected children's data CanadaMarketing and consent Other

The joint investigation by the Office of the Privacy Commissioner of Canada and the supervisory authorities of Québec, British Columbia and Alberta found that every year hundreds of thousands of children used the platform despite the minimum age of 13, and that TikTok processed data without valid consent, including for profiling and advertising. TikTok undertook to improve age verification and make privacy notices easier to understand, and already during the investigation largely stopped targeted advertising to under-18s (except by broad categories such as language and approximate location).

What organisations can take from it

Age limits in the terms of use are not enough – platforms need effective age verification and child-appropriate transparency.

Authority / court
Office of the Privacy Commissioner of Canada gemeinsam mit den Aufsichten von Québec, British Columbia und Alberta
Area of law
Data protection · Marketing and consent
Legal basis
PIPEDA und Datenschutzgesetze für den Privatsektor von Québec, British Columbia und Alberta
Action
Other
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
23 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Google LLC und Google Ireland LimitedGoogle: 325 million EUR – advertising cookies at account creation and ads in the Gmail inbox FranceCookies and tracking €325m

When creating a Google account, users were not sufficiently informed that advertising cookies were necessarily placed in the process; in addition, Google displayed advertisements between e-mails in Gmail without prior consent. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 200 million EUR on Google LLC and 125 million EUR on Google Ireland and ordered remedial action within six months, subject to a penalty payment of 100,000 EUR per day.

What organisations can take from it

Do not tacitly tie advertising cookies to account creation – and advertising in the inbox counts as direct marketing requiring consent.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés; Art. L. 34-5 Code des postes et des communications électroniques
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner AustriaCookies and tracking €6,200

In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.

What organisations can take from it

Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Jul 2025 Healthline Media LLCCalifornia: $1.55 million against Healthline over disclosure of illness-related article titles USA, CACookies and tracking €1.31m

Despite objections, the health portal continued to pass data to advertising partners and transmitted article titles suggestive of diagnoses for targeted advertising; the consent banner did not stop the tracking. In addition, the required contractual clauses with advertising partners were missing. The settlement was reached with the Attorney General of California.

What organisations can take from it

Test consent banners technically: if rejecting does not actually switch off tracking, that is misleading and unlawful.

Authority / court
Attorney General of California (California Department of Justice)
Area of law
Data protection · Cookies and tracking
Legal basis
California Consumer Privacy Act (CCPA), Unfair Competition Law
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
1 Jul 2025

Original amount 1,550,000 USD, converted at the ECB reference rate of 1 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China IrelandInternational data transfers €530m

TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.

What organisations can take from it

Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · International data transfers
Legal basis
Art. 46 Abs. 1, Art. 13 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
2 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication PolandData breaches and data security €13,604

Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.

What organisations can take from it

Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.

Relevance to training and awareness

Protection of data subjects in press reports; encryption of storage media

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
Action
Fine
Status of proceedings
under appeal
Sector
Media and online platforms
Published
11 Mar 2025

Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification IrelandData breaches and data security €251m

In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).

What organisations can take from it

Make data breach notifications complete, and document every breach internally in a traceable manner.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
17 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Nov 2024 Netflix International B.V.AP: 4.75 million EUR against Netflix over insufficient privacy information NetherlandsData subject rights and transparency €4.75m

Between 2018 and 2020, Netflix did not adequately inform customers about what happens to their data, and the information available was partly unclear. The Dutch supervisory authority (Autoriteit Persoonsgegevens, AP) imposed 4.75 million EUR; Netflix has since revised its privacy statement.

What organisations can take from it

Privacy notices must be complete and comprehensible – and responses to customer requests must also be specific rather than generic.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a i. V. m. Art. 12 Abs. 1, Art. 13 Abs. 1 lit. c, e, f und Abs. 2 lit. a, Art. 15 Abs. 1 lit. a, c, d und Abs. 2 DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
The privacy statement and the information provided were subsequently improved.
Published
18 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) GermanyData breaches and data security Other

In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.

What organisations can take from it

Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.

Authority / court
Bundesgerichtshof (VI. Zivilsenat)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 82 Abs. 1 DSGVO
Action
Other
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
18 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2024 Meta Platforms Ireland LimitedIreland: 91 million EUR against Meta over plaintext passwords IrelandData breaches and data security €91m

Meta stored users' passwords unencrypted in plaintext in internal systems and reported this to Ireland's Data Protection Commission (DPC) in March 2019. The DPC found infringements of the security obligations (Art. 5(1)(f), Art. 32(1)) and of the notification and documentation obligations (Art. 33(1) and (5)), and additionally issued a reprimand.

What organisations can take from it

Never store or log passwords in plaintext – not even in internal systems.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 und 5
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
According to the DPC, the passwords were not disclosed to external third parties.
Published
27 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2024 Vinted, UABVinted pays 2.39 million EUR over ‘shadow banning’ and handling of erasure requests LithuaniaData subject rights and transparency €2.39m

Acting on complaints from France and Poland, the Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that the second-hand platform rejected erasure requests when users did not state a ‘specific reason’ under Art. 17 GDPR, throttled users without their knowledge through ‘shadow banning’ and could not demonstrate how it handled access requests. Fine of 2,385,276 EUR. Source: archived copy of the press release.

What organisations can take from it

Covert restrictions on users are non-transparent – and erasure requests must not fail on formalities such as a requirement to give reasons.

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a, Art. 5 Abs. 2, Art. 12 Abs. 1 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
3 Jul 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial