Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

8cases from 1 jurisdiction
€26mTotal of monetary amounts (7 cases with an amount)
€1.39mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€898,979
Q4 20240—
Q1 20251€3.68m
Q2 20252€2.81m
Q3 20250—
Q4 20252€17.5m
Q1 20260—
Q2 20261€1.12m
Q3 20261—

8 cases

15 Oct 2025 Capita plc und Capita Pension Solutions LimitedICO: £14 million against Capita after ransomware attack affecting 6.6 million people United KingdomData breaches and data security €16.1m

In March 2023, an employee unintentionally downloaded malicious files; although an alert was triggered after ten minutes, the device was only isolated after 58 hours. Attackers stole around one terabyte of data on 6.6 million people (including pension data and criminal record information). Fines imposed by the UK Information Commissioner's Office (ICO): £8 million against Capita plc and £6 million against Capita Pension Solutions.

What organisations can take from it

Security alerts need binding response times and an adequately staffed SOC – known vulnerabilities must be remedied across the group.

Relevance to training and awareness

Handling malicious downloads and security alerts

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32
Action
Fine
Status of proceedings
final
Sector
Other
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
£45 million had provisionally been proposed; reduced, among other things, for security improvements, credit monitoring for those affected and cooperation with authorities and the NCSC.
Published
15 Oct 2025

Original amount 14,000,000 GBP, converted at the ECB reference rate of 15 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Jul 2026 Metropolitan Police ServiceICO: order and reprimand against London's Met Police after disclosure of sensitive data United KingdomData breaches and data security Order

The Metropolitan Police handed a defendant unredacted documents containing the new address and telephone number of a stalking victim, and in a circular e-mail disclosed 18 people with a parliamentary connection in an open recipient list. The UK Information Commissioner's Office (ICO) ordered improvements within 3 and 12 months, including in data protection training completion rates.

What organisations can take from it

Policies are not enough if mandatory training goes uncompleted for years – monitor and enforce training completion rates.

Relevance to training and awareness

Redacting documents, e-mail distribution lists (BCC), data protection training

Missing or inadequate training played a role in the decision.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Data Protection Act 2018, Section 40
Action
Order
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Culpability
negligent
Published
5 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack United KingdomData breaches and data security €1.12m

In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.

What organisations can take from it

Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.

Relevance to training and awareness

Recognising phishing

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
40% reduction for early admission of liability; payment agreed without appeal.
Published
11 May 2026

Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database United KingdomData breaches and data security €1.39m

In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.

What organisations can take from it

Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.

Relevance to training and awareness

Separation of personal and work devices and credentials

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
11 Dec 2025

Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data United KingdomData breaches and data security €2.74m

From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.

What organisations can take from it

Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
negligent
Published
17 Jun 2025

Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2025 DPP Law LtdICO: £60,000 against law firm DPP Law over hack and late notification United KingdomData breaches and data security €69,458

In 2022, attackers used brute force to penetrate the law firm's network via a rarely used administrator account without MFA and stole 32 GB of highly sensitive data, which appeared on the dark web. The firm only learned of this from the National Crime Agency and reported the incident to the UK Information Commissioner's Office (ICO) only 43 days later.

What organisations can take from it

Even small law firms need MFA on admin accounts and a reporting process that meets the 72-hour deadline.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2, Art. 33 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Published
16 Apr 2025

Original amount 60,000 GBP, converted at the ECB reference rate of 14 Apr 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA United KingdomData processors €3.68m

Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.

What organisations can take from it

MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data processors
Legal basis
UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
Published
27 Mar 2025

Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2024 Police Service of Northern Ireland (PSNI)ICO: £750,000 against Northern Ireland police after spreadsheet error in FOI response United KingdomData breaches and data security €898,979

In its response to a freedom of information request, the Police Service of Northern Ireland (PSNI) published an Excel file whose hidden worksheet contained the surnames, initials, rank and role of all 9,483 employees. The file was visible for just over two hours and was deleted after almost three hours; the police assumed that it had fallen into the hands of dissident republicans.

What organisations can take from it

Before releasing any file, check for hidden sheets, metadata and raw data – a four-eyes approval process prevents such breaches.

Relevance to training and awareness

Checking files before publication (hidden worksheets)

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Employees
1,000 to 9,999
Culpability
negligent
Mitigating circumstances
Application of the public sector approach; without it, the fine would have been £5.6 million.
Published
3 Oct 2024

Original amount 750,000 GBP, converted at the ECB reference rate of 26 Sep 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial