Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €8.53m 100 % · 3 cases
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €2.39m |
| Q4 2024 | 1 | €4.75m |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | — |
| Q1 2026 | 1 | €1.4m |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
4 cases
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 Netflix International B.V.AP: 4.75 million EUR against Netflix over insufficient privacy information €4.75m
Between 2018 and 2020, Netflix did not adequately inform customers about what happens to their data, and the information available was partly unclear. The Dutch supervisory authority (Autoriteit Persoonsgegevens, AP) imposed 4.75 million EUR; Netflix has since revised its privacy statement.
Privacy notices must be complete and comprehensible – and responses to customer requests must also be specific rather than generic.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a i. V. m. Art. 12 Abs. 1, Art. 13 Abs. 1 lit. c, e, f und Abs. 2 lit. a, Art. 15 Abs. 1 lit. a, c, d und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- The privacy statement and the information provided were subsequently improved.
- Published
- 18 Dec 2024
- Boete Netflix (Besluit van 26 november 2024) Decision of an authority
- AP – Boete Netflix voor niet goed informeren klanten Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2024 Vinted, UABVinted pays 2.39 million EUR over ‘shadow banning’ and handling of erasure requests €2.39m
Acting on complaints from France and Poland, the Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that the second-hand platform rejected erasure requests when users did not state a ‘specific reason’ under Art. 17 GDPR, throttled users without their knowledge through ‘shadow banning’ and could not demonstrate how it handled access requests. Fine of 2,385,276 EUR. Source: archived copy of the press release.
Covert restrictions on users are non-transparent – and erasure requests must not fail on formalities such as a requirement to give reasons.
- Authority / court
- Valstybinė duomenų apsaugos inspekcija (VDAI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 5 Abs. 2, Art. 12 Abs. 1 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 3 Jul 2024
- VDAI, Pranešimas 2024-07-03 (Archivkopie web.archive.org von vdai.lrv.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link