Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €342m 100 % · 3 cases
- Other — 0 % · 1 case
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €91m |
| Q4 2024 | 2 | €251m |
| Q1 2025 | 1 | €13,604 |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
4 cases
6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication €13,604
Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.
Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.
Protection of data subjects in press reports; encryption of storage media
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Published
- 11 Mar 2025
Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.
- Kara dla Polskiego Radia Szczecin za brak procedur chroniących prawa bohaterów publikacji Press release of an authority
- WSA oddalił skargę na decyzję Prezesa UODO w sprawie kary dla Radia Szczecin Press release of an authority
- Decyzja DKN.5112.10.2024 z 6 marca 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification €251m
In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).
Make data breach notifications complete, and document every breach internally in a traceable manner.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 17 Dec 2024
- Irish Data Protection Commission fines Meta €251 Million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) Other
In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.
Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.
- Authority / court
- Bundesgerichtshof (VI. Zivilsenat)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 82 Abs. 1 DSGVO
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 18 Nov 2024
- BGH Pressemitteilung Nr. 218/2024 – Leitentscheidung zum Scraping Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2024 Meta Platforms Ireland LimitedIreland: 91 million EUR against Meta over plaintext passwords €91m
Meta stored users' passwords unencrypted in plaintext in internal systems and reported this to Ireland's Data Protection Commission (DPC) in March 2019. The DPC found infringements of the security obligations (Art. 5(1)(f), Art. 32(1)) and of the notification and documentation obligations (Art. 33(1) and (5)), and additionally issued a reprimand.
Never store or log passwords in plaintext – not even in internal systems.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 und 5
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- According to the DPC, the passwords were not disclosed to external third parties.
- Published
- 27 Sep 2024
- Irish Data Protection Commission fines Meta Ireland €91 million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link