Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,929 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Capita plc und Capita Pension Solutions Limited €16.1m 45 % · 1 case
- Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen) €13m 36 % · 1 case
- Informa D&B, S.A. €1.8m 5 % · 1 case
- Anonymised companies €1.22m 3 % · 17 cases
- Profisportorganisation, Spanien (anonymisiert) €1m 3 % · 1 case
- Solocal Marketing Services €900,000 2 % · 1 case
- Marketing-Unternehmen, UK (anonymisiert) €346,600 1 % · 1 case
- Callcenter (anonymisiert) €259,327 1 % · 2 cases
- National Amusements, Inc. €235,206 1 % · 1 case
- Direktmarketing-Unternehmen, UK (anonymisiert) €150,737 0 % · 1 case
- 25 more€1.12m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €235,206 |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
13 Nov 2024 National Amusements, Inc.Cinema operator National Amusements: 250,000 USD over data breach and late notice €235,206
In December 2022 an attacker used an employee's stolen credentials to break into the systems of the cinema operator National Amusements because multi-factor authentication was not enforced for all access routes; data such as social security, passport and account numbers of 82,128 people was affected – according to the company, current and former employees and contractors – of whom 23,365 were in New York, and some of the social security numbers were stored unencrypted. Those affected were only notified on 18 December 2023, more than a year after the incident. Under the Assurance of Discontinuance with the New York Attorney General's office, the company pays 250,000 USD and must introduce, among other things, encryption, password rules, vulnerability testing and an incident response plan. The authority allegedly made the findings set out here; this account is not based on a final judgment.
Employee data also triggers notification duties – notice must not wait until the data review is fully completed.
Multi-factor authentication for all access routes; timely notification of data breaches
Missing or inadequate training played a role in the decision.
- Authority / court
- Office of the New York State Attorney General (Bureau of Internet & Technology)
- Area of law
- Data protection · Employee data
- Legal basis
- New York Executive Law § 63(12); New York General Business Law § 899-aa (Benachrichtigung bei Datenpannen) und § 899-bb (SHIELD Act, Datensicherheit)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Published
- 15 Nov 2024
Original amount 250,000 USD, converted at the ECB reference rate of 13 Nov 2024.
- NYAG, In the Matter of National Amusements, Inc., Assurance of Discontinuance No. 24-024 (wirksam 13.11.2024) Decision of an authority
- NYAG-Pressemitteilung: Attorney General James Secures $250,000 from Movie Theater Operator for Failing to Protect Employees' Personal Information (15.11.2024) Press release of an authority
Checked against the official source on 3 Oct 2026 · Direct link