Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

6cases from 6 jurisdictions
€51.1mTotal of monetary amounts (5 cases with an amount)
€45mLargest single case: Vodafone GmbH
€1.7mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241—
Q3 20240—
Q4 20241€5,363
Q1 20251€3.68m
Q2 20252€45.7m
Q3 20250—
Q4 20251€1.7m
Q1 20260—
Q2 20260—
Q3 20260—

6 cases

22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws FranceData processors €1.7m

As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.

What organisations can take from it

Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names GreeceData processors €700,000

Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.

What organisations can take from it

Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.

Relevance to training and awareness

Identity verification when concluding contracts in partner distribution

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA United KingdomData processors €3.68m

Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.

What organisations can take from it

MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data processors
Legal basis
UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
Published
27 Mar 2025

Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware DenmarkData processors €5,363

As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.

What organisations can take from it

A backup only counts if restoration is tested regularly – including access to the keys.

Authority / court
Dänisches Gericht auf Anzeige der Datatilsynet
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO; Auftragsverarbeitungsvertrag
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack SwitzerlandData processors Other

Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.

What organisations can take from it

Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.

Relevance to training and awareness

Passing real data to service providers for support

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data processors
Legal basis
Datenschutzgesetz (DSG)
Action
Other
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
1 May 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial