Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

17cases from 13 jurisdictions
€111mTotal of monetary amounts
€45mLargest single case: Vodafone GmbH
€300,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20241€157,176
Q2 20241€13.9m
Q3 20240—
Q4 20241€5,363
Q1 20251€14,974
Q2 20253€45.9m
Q3 20251€300,000
Q4 20253€6.21m
Q1 20263€42.6m
Q2 20261€1.72m
Q3 20262€260,022

17 cases

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff ItalyData breaches and data security €1.72m

Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.

What organisations can take from it

Staff in branches and partner shops must verify alleged support calls before granting access.

Relevance to training and awareness

Social engineering / fake IT support

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO (Integrität und Vertraulichkeit, Art. 32)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy FinlandData subject rights and transparency €5,000

Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.

What organisations can take from it

Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.

Relevance to training and awareness

Right of access to call recordings

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15 Abs. 1 und 3
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data SwedenData breaches and data security €564,626

The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).

What organisations can take from it

Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
Published
26 Jan 2026

Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts FranceData breaches and data security €42m

Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.

What organisations can take from it

Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
Published
14 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws FranceData processors €1.7m

As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.

What organisations can take from it

Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis BelgiumMarketing and consent €5,000

The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.

What organisations can take from it

Data brokers must be able to prove for every record on which legal basis it was collected and resold.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses CroatiaInternational data transfers €4.5m

The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.

What organisations can take from it

Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor LatviaData breaches and data security €300,000

Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.

What organisations can take from it

Processors are also independently liable for the security of the systems they operate.

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names GreeceData processors €700,000

Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.

What organisations can take from it

Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.

Relevance to training and awareness

Identity verification when concluding contracts in partner distribution

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 May 2025 Xfera Móviles, S.A.U.AEPD: 200,000 EUR against Xfera (MásMóvil) over number porting without consent SpainData breaches and data security €200,000

A customer's mobile number was ported to MásMóvil without the customer having requested it; the new SIM card was handed over to a third party who did not identify themselves. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found processing without a legal basis, imposed 200,000 EUR and ordered measures against such incidents; the company's request for reconsideration was unsuccessful.

What organisations can take from it

Issue SIM cards and carry out porting only after robust identity verification – couriers and sales partners must comply with this too.

Relevance to training and awareness

Identity verification for porting and SIM handover (SIM swapping)

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees RomaniaData breaches and data security €14,974

Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.

Relevance to training and awareness

BCC, use of messaging apps, sending customer documents

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
20 Jan 2025

Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware DenmarkData processors €5,363

As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.

What organisations can take from it

A backup only counts if restoration is tested regularly – including access to the keys.

Authority / court
Dänisches Gericht auf Anzeige der Datatilsynet
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO; Auftragsverarbeitungsvertrag
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2024 Avast Software s.r.o.Avast: 351 million CZK for passing browsing histories to Jumpshot CzechiaData subject rights and transparency €13.9m

In 2019, the antivirus manufacturer passed pseudonymised browsing histories of around 100 million users to its subsidiary Jumpshot, which sold insights into online behaviour to marketing clients. The data declared as anonymous allowed re-identification and users were misinformed; the Úřad pro ochranu osobních údajů (Czech data protection authority, ÚOOÚ) imposed a final fine of 351 million CZK.

What organisations can take from it

Pseudonymised data are not anonymous data – anyone passing on usage data must assess re-identification risks and inform users honestly.

Authority / court
Úřad pro ochranu osobních údajů (ÚOOÚ)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (unrechtmäßige Verarbeitung, Transparenz), One-Stop-Shop-Verfahren
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
15 Apr 2024

Original amount 351,000,000 CZK, converted at the ECB reference rate of 15 Apr 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jan 2024 Black Tiger Belgium (vormals Bisnode Belgium)Black Tiger Belgium: fine for non-transparent data trading, reduced by 10% in court BelgiumData subject rights and transparency €157,176

The data broker processed data obtained from third-party sources (including the companies register) on a large scale and over a long period without proactively informing the data subjects; access requests were answered incompletely and the record of processing activities had gaps. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed three fines totalling 174,640 EUR and prohibited, among other things, the ‘Data Quality’ service until data subjects had been informed; on 4 September 2024 the Brussels Market Court set aside the orders and reduced the fines by 10% to a total of 157,176 EUR.

What organisations can take from it

Anyone collecting data indirectly must actively inform data subjects – legitimate interest does not hold where laws prohibit further use.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO – Rechtmäßigkeit, Fairness und Transparenz, Auskunftsrecht, Verzeichnis von Verarbeitungstätigkeiten
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software
Mitigating circumstances
Discontinuation of the ‘Data Delivery’ service and destruction of the CMX consumer database.
Published
16 Jan 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial