Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

15cases from 3 jurisdictions
€59.8mTotal of monetary amounts (8 cases with an amount)
€45mLargest single case: Vodafone GmbH
€110,250Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€20,000
Q1 20240—
Q2 20241—
Q3 20241€1.5m
Q4 20242€5,000
Q1 20251—
Q2 20251€45m
Q3 20252€201,200
Q4 20250—
Q1 20261€25,500
Q2 20265€13m
Q3 20260—

15 cases

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data SwitzerlandData subject rights and transparency Order

The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.

What organisations can take from it

Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.

Authority / court
Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 6, Art. 19, Art. 31
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function GermanyData breaches and data security Fine

In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.

What organisations can take from it

Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.

Authority / court
Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5, Art. 25 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
Published
10 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late GermanyData processors Reprimand or warning

A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.

What organisations can take from it

Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.

Relevance to training and awareness

Reporting process for data breaches and management of service providers

Authority / court
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Mitigating circumstances
BVG has announced measures against similar incidents.
Published
4 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising SwitzerlandMarketing and consent Order

Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.

What organisations can take from it

An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.

Relevance to training and awareness

Handling objections to advertising and deletion requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Marketing and consent
Legal basis
DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants AustriaData subject rights and transparency €25,500

The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).

What organisations can take from it

Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.

Relevance to training and awareness

Recording of telephone calls and applicant data

Authority / court
Datenschutzbehörde
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
Action
Fine
Status of proceedings
under appeal
Sector
Other
Employees
Under 50
Mitigating circumstances
No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests GermanyData subject rights and transparency €195,000

A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).

What organisations can take from it

Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.

Relevance to training and awareness

Timely handling of access requests

Authority / court
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Betroffenenrechte)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
30 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner AustriaCookies and tracking €6,200

In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.

What organisations can take from it

Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms SwitzerlandData subject rights and transparency Order

From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.

What organisations can take from it

Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.

Relevance to training and awareness

Handling access requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
1 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) GermanyData breaches and data security Other

In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.

What organisations can take from it

Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.

Authority / court
Bundesgerichtshof (VI. Zivilsenat)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 82 Abs. 1 DSGVO
Action
Other
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
18 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer AustriaData protection €5,000

A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.

What organisations can take from it

Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection
Legal basis
Art. 37, Art. 38 Abs. 6 DSGVO
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
50 to 249
Liability of senior managers
The managing director was also appointed as data protection officer – an impermissible conflict of interest.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Aug 2024 DSB: 1.5 million EUR against retail chain over cameras on self-checkouts, PIN pad and surroundings AustriaVideo surveillance €1.5m

In 2022, a retail company (name pseudonymised) used nine cameras in one branch to film, among other things, the self-service checkouts including the keypad of the card payment terminal, as well as public areas, bus stops and neighbouring properties. The Austrian data protection authority (Datenschutzbehörde, DSB) imposed 1.5 million EUR for lack of a legal basis and infringement of data minimisation; the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the amount on 25 July 2025, and an appeal on points of law is pending.

What organisations can take from it

Align cameras in retail closely with their protective purpose – PIN entries, public spaces and neighbouring properties must not be in the frame.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack SwitzerlandData processors Other

Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.

What organisations can take from it

Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.

Relevance to training and awareness

Passing real data to service providers for support

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data processors
Legal basis
Datenschutzgesetz (DSG)
Action
Other
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
1 May 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Dec 2023 DSB: 20,000 EUR against restaurant business over constant surveillance of kitchen and pick-up area AustriaVideo surveillance €20,000

A restaurant company with a delivery and pick-up service (name pseudonymised) recorded workstations in the kitchen and pick-up area without interruption, even outside opening hours, and stored the recordings for 14 days. In addition, there had been no record of processing activities since 2018; the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 20,000 EUR, and the penalty decision is final.

What organisations can take from it

Even small businesses may not film employees permanently – and they need a record of their processing activities.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 30 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Food and agriculture

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial