Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Amazon France Logistique SAS 1 case 9 % · €15m
- Berliner Verkehrsbetriebe (BVG) AöR 1 case 9 % ·
- Foodinho S.r.l. (Glovo-Gruppe) 1 case 9 % · €5m
- MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App) 1 case 9 % · €100m
- Poczta Polska S.A. 1 case 9 % · €232,208
- Posti Jakelu Oy 1 case 9 % ·
- SIA "EUROPARK LATVIA" 1 case 9 % · €25,000
- Uber Technologies Inc. und Uber B.V. 1 case 9 % · €290m
- Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt) 1 case 9 % ·
- Waxholms Ångfartygs Aktiebolag 1 case 9 % · €6,801
- 1 more1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €3m |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €290m |
| Q4 2024 | 2 | €5m |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €6,801 |
| Q3 2025 | 0 | — |
| Q4 2025 | 2 | €15m |
| Q1 2026 | 1 | €232,208 |
| Q2 2026 | 2 | €100m |
| Q3 2026 | 1 | — |
11 cases
7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles Order
The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.
Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.
Consent and proportionality in employee monitoring
- Authority / court
- Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 7 Jul 2026
- Upravno sodišče znova potrdilo prakso IP: sistematično GPS sledenje zaposlenim ni dopustno brez tehtnega razloga Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late Reprimand or warning
A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.
Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.
Reporting process for data breaches and management of service providers
- Authority / court
- Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- BVG has announced measures against similar incidents.
- Published
- 4 May 2026
- Datenschutzbeauftragte verwarnt BVG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia €100m
Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.
Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent €232,208
The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.
Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Mitigating circumstances
- During the proceedings the function was made independent and placed directly under the management board.
- Published
- 26 Jan 2026
Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.
- Kara dla Poczty Polskiej za brak zapewnienia niezależności sprawowania funkcji IOD Press release of an authority
- Decyzja DKN.5131.4.2025 z 2 stycznia 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR €15m
In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.
Store employee performance metrics only for as long and in as much detail as their specific purpose requires.
- Authority / court
- Conseil d'État
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Conseil d'État, décision n° 492830 du 23 décembre 2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Nov 2025 SIA "EUROPARK LATVIA"Europark Latvia pays 25,000 EUR for payment reminders sent to outdated addresses €25,000
Following several complaints, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined how the parking operator collects contractual penalties: invoices were sent to previous rather than current registered addresses, claims were handed over to debt collection services and entered in the database of Kredītinformācijas Birojs. The authority found breaches of the principles of lawfulness, data minimisation and confidentiality and of the accountability obligation and imposed 25,000 EUR (previous year’s turnover according to the decision: 8,323,178 EUR).
Anyone collecting debts or reporting them to credit agencies must first ensure that address data are up to date.
Data quality in receivables management
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection
- Legal basis
- Art. 5 Abs. 1 lit. a, c, f und Abs. 2, Art. 83 Abs. 5 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Culpability
- intentional
- Mitigating circumstances
- Practice changed after the proceedings began; contracts concluded with the population and vehicle registers (PMLP, CSDD)
- DVI Lēmums Nr. 01630000100425-3 Par soda piemērošanu (SIA „EUROPARK LATVIA“), 24.11.2025 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2025 Waxholms Ångfartygs AktiebolagWaxholmsbolaget: fine for processing a captain’s breathalyser test results €6,801
The shipping company processed results of on-board breath alcohol tests that could be attributed to a complainant employed as a captain. The Swedish Authority for Privacy Protection (IMY) regarded this as processing without a legal basis and as unlawful processing of health data and imposed 75,000 SEK.
Monitoring data such as alcohol test results are employees’ health data – access, storage and legal basis must be settled before such tests are introduced.
Employee health data (alcohol tests)
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 6, Art. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 18 Jun 2025
Original amount 75,000 SEK, converted at the ECB reference rate of 18 Jun 2025.
- IMY – Tillsyn Waxholms Ångfartygs AB (WÅAB) Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2024-1520 (18.06.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 Foodinho S.r.l. (Glovo-Gruppe)Garante: 5 million EUR against Glovo subsidiary Foodinho over monitoring of riders €5m
The delivery platform unlawfully processed data on more than 35,000 riders: facial recognition for identity verification, location tracking even outside working hours and automated assessments without human review. Foodinho had already been sanctioned with 2.6 million EUR in 2021; in addition to 5 million EUR, the Italian data protection authority (Garante per la protezione dei dati personali) prohibited the biometric processing.
Algorithmic management of workers requires transparency and human review, and must not include tracking outside working hours.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO (u. a. Transparenz, biometrische Daten, automatisierte Entscheidungen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Repeat case
- yes
- Published
- 22 Nov 2024
- Rider, Garante privacy: no all'algoritmo incontestabile dai lavoratori Press release of an authority
- Garante – Rider: Sanzione di 2,6 milioni di euro a una piattaforma del gruppo Glovo (2021) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 Posti Jakelu OyPosti: 2.4 million EUR for automatically created e-mailboxes – court annuls fine overturned
Customers who ordered, for example, mail forwarding automatically received an electronic OmaPosti mailbox that could not be deselected separately; they were also informed insufficiently and in part incorrectly about the activation. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found no contractual legal basis for this bundling and imposed 2.4 million EUR together with a reprimand and an order to rectify the situation. On 3 November 2025 the Helsinki Administrative Court upheld the reprimand and the order on account of the insufficient information but annulled the fine, as it considered the processing necessary for the contract on Posti’s electronic services.
Do not sell add-on services on the back of the contractual legal basis – anything not necessary for the main contract requires a separate choice.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 6 Abs. 1 lit. b, Art. 13, Art. 25
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Transport, logistics and shipping
- Published
- 15 Nov 2024
Amount in EUR; no ECB reference rate is available for this currency.
- Tietosuojavaltuutettu – Postille seuraamusmaksu OmaPosti-palvelun tietosuojapuutteista (15.11.2024) Press release of an authority
- Finlex – Tietosuojavaltuutettu 13.11.2024 (sähköinen postilaatikko) Decision of an authority
- Helsingin hallinto-oikeus – kumosi Posti Jakelu Oy:lle määrätyn 2,4 miljoonan euron seuraamusmaksun (03.11.2025) Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2024 Uber Technologies Inc. und Uber B.V.Uber: 290 million EUR – driver data sent to the USA for two years without a transfer tool €290m
Uber stored sensitive data of European drivers – including location, payment and identity document data, and in some cases criminal and health data – on servers in the USA and from August 2021 no longer used any transfer tool. Following complaints from more than 170 French drivers, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 290 million EUR; it was the AP’s third fine against Uber.
Intra-group transfers to headquarters are third-country transfers – anyone who lets a transfer tool lapse transfers data without a legal basis.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 26 Aug 2024
- AP legt Uber boete op van 290 miljoen euro om doorgifte data chauffeurs naar VS (26.08.2024) Press release of an authority
- AP, Besluit boete Uber doorgifte naar VS vom 22.07.2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Feb 2024 Ελληνικά Ταχυδρομεία Α.Ε. (ΕΛΤΑ, Hellenic Post)Greece: almost 3 million EUR against Hellenic Post after ransomware attack €3m
In a cyber attack in 2022, attackers obtained administrator access, disabled protective software, encrypted files and later published stolen data on the darknet. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the postal company had not implemented the necessary technical and organisational measures or its own security policy and, by Decision 10/2024, imposed 2,995,140 EUR.
A security policy on paper offers no protection – what is examined is whether it has actually been implemented.
Cyber defence, handling of administrator accounts
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Επιβολή προστίμου σε εταιρία για μη ορθή τήρηση τεχνικών και οργανωτικών μέτρων (Απόφαση 10/2024) Decision of an authority
- Απόφαση 10/2024 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link