Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Google LLC €1.19bn 91 % · 1 case
- Vodafone GmbH €45m 3 % · 1 case
- Free Mobile SAS und Free SAS €42m 3 % · 1 case
- Avast Software s.r.o. €13.9m 1 % · 1 case
- Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt) €4.5m 0 % · 1 case
- Advanced Computer Software Group Ltd €3.68m 0 % · 1 case
- Wind Tre S.p.A. €1.72m 0 % · 1 case
- Nexpublica France €1.7m 0 % · 1 case
- LastPass UK Ltd €1.39m 0 % · 1 case
- Vodafone – Πάναφον Α.Ε.Ε.Τ. €700,000 0 % · 1 case
- 12 more€1.51m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €157,176 |
| Q2 2024 | 2 | €13.9m |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €5,363 |
| Q1 2025 | 2 | €3.69m |
| Q2 2025 | 3 | €45.9m |
| Q3 2025 | 1 | €300,000 |
| Q4 2025 | 5 | €1.2bn |
| Q1 2026 | 3 | €42.6m |
| Q2 2026 | 2 | €1.72m |
| Q3 2026 | 2 | €260,022 |
22 cases
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students Order
According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.
Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- FTC Act (Verbot unlauterer und irreführender Praktiken)
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 5 Jun 2026
- FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students' Personal Data Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy €5,000
Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.
Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.
Right of access to call recordings
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15 Abs. 1 und 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 25 Mar 2026
- Finlex – Tietosuojavaltuutettu 2.3.2026 (puhelutallenteet) Decision of an authority
- Tietosuojavaltuutettu – Suomen Numerokeskukselle seuraamusmaksu puutteista puhelutallenteiden antamisessa (25.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data €564,626
The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).
Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
- Published
- 26 Jan 2026
Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.
- IMY – Tillsyn Sportadmin i Skandinavien AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2025-7801 (26.01.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts €42m
Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.
Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
- Published
- 14 Jan 2026
- Violation de données : sanction de 42 millions d'euros à l'encontre des sociétés FREE MOBILE et FREE Press release of an authority
- Délibération SAN-2026-001 du 8 janvier 2026 (FREE MOBILE) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws €1.7m
As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.
Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Délibération SAN-2025-015 du 22 décembre 2025 (NEXPUBLICA FRANCE) Decision of an authority
- Les sanctions prononcées par la CNIL Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis €5,000
The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.
Data brokers must be able to prove for every record on which legal basis it was collected and resold.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database €1.39m
In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.
Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.
Separation of personal and work devices and credentials
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 11 Dec 2025
Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.
- Password manager provider fined £1.2m by ICO for data breach Press release of an authority
- ICO Enforcement: LastPass UK Ltd Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses €4.5m
The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.
Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 14 Nov 2025
- AZOP: Administrative Fine of EUR 4.5 Million Imposed on a Telecommunications Operator (14.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data €1.19bn
Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.
Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.
- Authority / court
- Office of the Attorney General of Texas
- Area of law
- Data protection · Cookies and tracking
- Action
- Other
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 31 Oct 2025
Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.
- Attorney General Ken Paxton Finalizes Historic Settlement with Google and Secures $1.375 Billion Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor €300,000
Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.
Processors are also independently liable for the security of the systems they operate.
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
- DVI – Zusammenfassung der Entscheidung zu SIA „ZZ Dats“ (08.09.2025) Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names €700,000
Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.
Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.
Identity verification when concluding contracts in partner distribution
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Απόφαση 27/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps €45m
Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.
Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.
Insider threats and oversight of sales partners
- Authority / court
- Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
- Published
- 3 Jun 2025
- Pressemitteilung 6/2025: BfDI verhängt Geldbußen gegen Vodafone Press release of an authority
- BfDI – Übersicht Pressemitteilungen (Datum 03.06.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 May 2025 Xfera Móviles, S.A.U.AEPD: 200,000 EUR against Xfera (MásMóvil) over number porting without consent €200,000
A customer's mobile number was ported to MásMóvil without the customer having requested it; the new SIM card was handed over to a third party who did not identify themselves. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found processing without a legal basis, imposed 200,000 EUR and ordered measures against such incidents; the company's request for reconsideration was unsuccessful.
Issue SIM cards and carry out porting only after robust identity verification – couriers and sales partners must comply with this too.
Identity verification for porting and SIM handover (SIM swapping)
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- AEPD Resolución PS/00170/2024 (EXP202301365) Decision of an authority
- AEPD Resolución recurso de reposición PS/00170/2024 (Datum der Ausgangsentscheidung 30.05.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA €3.68m
Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.
MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data processors
- Legal basis
- UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
- Published
- 27 Mar 2025
Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.
- Software provider fined £3m following 2022 ransomware attack Press release of an authority
- ICO Enforcement: Advanced Computer Software Group Limited Enforcement database of an authority
- ICO Penalty Notice: Advanced Computer Software Group Ltd Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees €14,974
Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.
BCC, use of messaging apps, sending customer documents
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 20 Jan 2025
Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.
- ANSPDCP – Comunicat de presă 20.01.2025 (Vodafone Romania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware €5,363
As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.
A backup only counts if restoration is tested regularly – including access to the keys.
- Authority / court
- Dänisches Gericht auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO; Auftragsverarbeitungsvertrag
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.
- Databehandler indstillet til bøde (Uptime-IT ApS) Press release of an authority
- Datatilsynet – Bødesager Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack Other
Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.
Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.
Passing real data to service providers for support
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data processors
- Legal basis
- Datenschutzgesetz (DSG)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 1 May 2024
- EDÖB schliesst Untersuchungen gegen das Unternehmen Xplain und die Bundesämter fedpol und BAZG ab Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2024 Avast Software s.r.o.Avast: 351 million CZK for passing browsing histories to Jumpshot €13.9m
In 2019, the antivirus manufacturer passed pseudonymised browsing histories of around 100 million users to its subsidiary Jumpshot, which sold insights into online behaviour to marketing clients. The data declared as anonymous allowed re-identification and users were misinformed; the Úřad pro ochranu osobních údajů (Czech data protection authority, ÚOOÚ) imposed a final fine of 351 million CZK.
Pseudonymised data are not anonymous data – anyone passing on usage data must assess re-identification risks and inform users honestly.
- Authority / court
- Úřad pro ochranu osobních údajů (ÚOOÚ)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (unrechtmäßige Verarbeitung, Transparenz), One-Stop-Shop-Verfahren
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 15 Apr 2024
Original amount 351,000,000 CZK, converted at the ECB reference rate of 15 Apr 2024.
- ÚOOÚ uložil pokutu 351 mil. Kč za porušení GDPR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jan 2024 Black Tiger Belgium (vormals Bisnode Belgium)Black Tiger Belgium: fine for non-transparent data trading, reduced by 10% in court €157,176
The data broker processed data obtained from third-party sources (including the companies register) on a large scale and over a long period without proactively informing the data subjects; access requests were answered incompletely and the record of processing activities had gaps. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed three fines totalling 174,640 EUR and prohibited, among other things, the ‘Data Quality’ service until data subjects had been informed; on 4 September 2024 the Brussels Market Court set aside the orders and reduced the fines by 10% to a total of 157,176 EUR.
Anyone collecting data indirectly must actively inform data subjects – legitimate interest does not hold where laws prohibit further use.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO – Rechtmäßigkeit, Fairness und Transparenz, Auskunftsrecht, Verzeichnis von Verarbeitungstätigkeiten
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Discontinuation of the ‘Data Delivery’ service and destruction of the CMX consumer database.
- Published
- 16 Jan 2024
Checked against the official source on 25 Sep 2026 · Direct link