Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
€5.07mTotal of monetary amounts
€3.68mLargest single case: Advanced Computer Software Group Ltd
€2.54mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Information Commissioner's Office (ICO) €5.07m 100 % · 2 cases

What for?

by topic
  1. Data processors €3.68m 73 % · 1 case
  2. Data breaches and data security €1.39m 27 % · 1 case

Who?

by company
  1. Advanced Computer Software Group Ltd €3.68m 73 % · 1 case
  2. LastPass UK Ltd €1.39m 27 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20251€3.68m
Q2 20250—
Q3 20250—
Q4 20251€1.39m
Q1 20260—
Q2 20260—
Q3 20260—

2 cases

20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database United KingdomData breaches and data security €1.39m

In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.

What organisations can take from it

Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.

Relevance to training and awareness

Separation of personal and work devices and credentials

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
11 Dec 2025

Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA United KingdomData processors €3.68m

Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.

What organisations can take from it

MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data processors
Legal basis
UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
Published
27 Mar 2025

Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial