Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €16.2m 100 % · 4 cases
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €5,005 |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €69,458 |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €16.1m |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 1 | €2,998 |
4 cases
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Oct 2025 Capita plc und Capita Pension Solutions LimitedICO: £14 million against Capita after ransomware attack affecting 6.6 million people €16.1m
In March 2023, an employee unintentionally downloaded malicious files; although an alert was triggered after ten minutes, the device was only isolated after 58 hours. Attackers stole around one terabyte of data on 6.6 million people (including pension data and criminal record information). Fines imposed by the UK Information Commissioner's Office (ICO): £8 million against Capita plc and £6 million against Capita Pension Solutions.
Security alerts need binding response times and an adequately staffed SOC – known vulnerabilities must be remedied across the group.
Handling malicious downloads and security alerts
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- £45 million had provisionally been proposed; reduced, among other things, for security improvements, credit monitoring for those affected and cooperation with authorities and the NCSC.
- Published
- 15 Oct 2025
Original amount 14,000,000 GBP, converted at the ECB reference rate of 15 Oct 2025.
- Capita fined £14m for data breach affecting over 6m people Press release of an authority
- ICO Enforcement: Capita plc Enforcement database of an authority
- ICO Monetary Penalty Notice: Capita plc and Capita Pension Solutions Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2025 DPP Law LtdICO: £60,000 against law firm DPP Law over hack and late notification €69,458
In 2022, attackers used brute force to penetrate the law firm's network via a rarely used administrator account without MFA and stole 32 GB of highly sensitive data, which appeared on the dark web. The firm only learned of this from the National Crime Agency and reported the incident to the UK Information Commissioner's Office (ICO) only 43 days later.
Even small law firms need MFA on admin accounts and a reporting process that meets the 72-hour deadline.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2, Art. 33 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- negligent
- Published
- 16 Apr 2025
Original amount 60,000 GBP, converted at the ECB reference rate of 14 Apr 2025.
- Law firm fined £60,000 following cyber attack Press release of an authority
- ICO Enforcement: DPP Law Ltd Enforcement database of an authority
- ICO Monetary Penalty Notice: DPP Law Ltd Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2024 EURO MINI STORAGE ROMANIA SRLEuro Mini Storage paralysed for weeks after cyber attack – 5,000 EUR €5,005
A cyber attack on the server paralysed the company for several weeks and allowed access to customer data. The Romanian data protection authority (ANSPDCP) imposed 24,884.50 lei (5,000 EUR) for insufficient security measures and ordered access logging with a retention period of at least 30 days as well as backups. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Logging and tested backups determine whether an attack means days or weeks of downtime.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 5 Mar 2024
Original amount 24,884.5 RON, converted at the ECB reference rate of 5 Mar 2024.
- ANSPDCP – Comunicat de presă 05.03.2024 (EURO MINI STORAGE ROMANIA SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link