Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €51.1m 100 % · 5 cases
- Other — 0 % · 1 case
Who?
by company- Vodafone GmbH €45m 88 % · 1 case
- Advanced Computer Software Group Ltd €3.68m 7 % · 1 case
- Nexpublica France €1.7m 3 % · 1 case
- Vodafone – Πάναφον Α.Ε.Ε.Τ. €700,000 1 % · 1 case
- Uptime-IT ApS €5,363 0 % · 1 case
- Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG) — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €5,363 |
| Q1 2025 | 1 | €3.68m |
| Q2 2025 | 2 | €45.7m |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €1.7m |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
6 cases
22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws €1.7m
As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.
Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Délibération SAN-2025-015 du 22 décembre 2025 (NEXPUBLICA FRANCE) Decision of an authority
- Les sanctions prononcées par la CNIL Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names €700,000
Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.
Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.
Identity verification when concluding contracts in partner distribution
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Απόφαση 27/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps €45m
Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.
Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.
Insider threats and oversight of sales partners
- Authority / court
- Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
- Published
- 3 Jun 2025
- Pressemitteilung 6/2025: BfDI verhängt Geldbußen gegen Vodafone Press release of an authority
- BfDI – Übersicht Pressemitteilungen (Datum 03.06.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA €3.68m
Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.
MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data processors
- Legal basis
- UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
- Published
- 27 Mar 2025
Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.
- Software provider fined £3m following 2022 ransomware attack Press release of an authority
- ICO Enforcement: Advanced Computer Software Group Limited Enforcement database of an authority
- ICO Penalty Notice: Advanced Computer Software Group Ltd Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware €5,363
As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.
A backup only counts if restoration is tested regularly – including access to the keys.
- Authority / court
- Dänisches Gericht auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO; Auftragsverarbeitungsvertrag
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.
- Databehandler indstillet til bøde (Uptime-IT ApS) Press release of an authority
- Datatilsynet – Bødesager Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack Other
Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.
Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.
Passing real data to service providers for support
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data processors
- Legal basis
- Datenschutzgesetz (DSG)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 1 May 2024
- EDÖB schliesst Untersuchungen gegen das Unternehmen Xplain und die Bundesämter fedpol und BAZG ab Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link