Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €28.6m 100 % · 28 cases
- Order — 0 % · 4 cases
- Other — 0 % · 1 case
Who?
by sectorAll sectors
- Telecoms, IT and software €14m 49 % · 3 cases
- Media and online platforms €8.53m 30 % · 4 cases
- Financial services and insurance €2.41m 8 % · 7 cases
- Retail and e-commerce €2.15m 8 % · 6 cases
- Automotive €582,573 2 % · 1 case
- Public sector €550,000 2 % · 2 cases
- Energy and utilities €196,000 1 % · 2 cases
- Construction and real estate €100,000 0 % · 1 case
- Other €67,629 0 % · 5 cases
- Healthcare €21,274 0 % · 3 cases
- 1 more€0
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €157,176 |
| Q2 2024 | 1 | €13.9m |
| Q3 2024 | 1 | €2.39m |
| Q4 2024 | 3 | €4.76m |
| Q1 2025 | 5 | €768,073 |
| Q2 2025 | 4 | €1.3m |
| Q3 2025 | 4 | €1.35m |
| Q4 2025 | 4 | €1.52m |
| Q1 2026 | 8 | €1.54m |
| Q2 2026 | 4 | €988,639 |
| Q3 2026 | 0 | — |
35 cases
15 Apr 2024 Avast Software s.r.o.Avast: 351 million CZK for passing browsing histories to Jumpshot €13.9m
In 2019, the antivirus manufacturer passed pseudonymised browsing histories of around 100 million users to its subsidiary Jumpshot, which sold insights into online behaviour to marketing clients. The data declared as anonymous allowed re-identification and users were misinformed; the Úřad pro ochranu osobních údajů (Czech data protection authority, ÚOOÚ) imposed a final fine of 351 million CZK.
Pseudonymised data are not anonymous data – anyone passing on usage data must assess re-identification risks and inform users honestly.
- Authority / court
- Úřad pro ochranu osobních údajů (ÚOOÚ)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (unrechtmäßige Verarbeitung, Transparenz), One-Stop-Shop-Verfahren
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 15 Apr 2024
Original amount 351,000,000 CZK, converted at the ECB reference rate of 15 Apr 2024.
- ÚOOÚ uložil pokutu 351 mil. Kč za porušení GDPR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit €792,639
The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.
Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.
- Authority / court
- Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Retail and e-commerce
- Published
- 18 Jun 2026
- Supreme Administrative Court upholds the administrative fine imposed on Verkkokauppa.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency €86,000
The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.
Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.
Recording of customer calls
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- APD – Décision quant au fond n° 102/2026 du 12 mai 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2026 Loblaw Companies LimitedOPC: Loblaw must change retention of PC Optimum data after account deletion Other
During a wave of boycotts in 2024, Loblaw did not process deletion requests in time and retained purchase and usage data from the loyalty programme (more than 17 million members) even after accounts were closed, without demonstrating effective anonymisation. Loblaw undertook to the Office of the Privacy Commissioner of Canada (OPC) to have the anonymisation independently reviewed and to carry out annual deletions.
Companies that continue to use data as anonymous after account deletion must be able to demonstrate the re-identification risk – IP addresses are often enough to link data to a person.
- Authority / court
- Office of the Privacy Commissioner of Canada (OPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- PIPEDA
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 5 Mar 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy €5,000
Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.
Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.
Right of access to call recordings
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15 Abs. 1 und 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 25 Mar 2026
- Finlex – Tietosuojavaltuutettu 2.3.2026 (puhelutallenteet) Decision of an authority
- Tietosuojavaltuutettu – Suomen Numerokeskukselle seuraamusmaksu puutteista puhelutallenteiden antamisessa (25.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files €100,000
An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).
Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.
Data minimisation for ID copies, retention periods
Missing or inadequate training played a role in the decision.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- No damage to data subjects was found.
- Published
- 19 Feb 2026
- Agenciji za nekretnine izrečena kazna u iznosu od 100.000,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers €1.5m
The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).
Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Dec 2025
- Banci izrečena upravna novčana kazna u iznosu od 1,5 milijuna eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers €17,600
The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.
New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Mitigating circumstances
- Partial immediate payment (20% reduction under Art. 85 LPACAP).
- AEPD Resolución PS/00160/2024 (EXP202308414) Decision of an authority
- AEPD Resolución recurso de reposición PS/00160/2024 (Datum der Ausgangsentscheidung 13.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests €195,000
A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).
Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.
Timely handling of access requests
- Authority / court
- Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Betroffenenrechte)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 30 Sep 2025
- Zwischenbilanz 2025: HmbBfDI verhängt Bußgelder von insgesamt 775.000 Euro Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2025 Tractor Supply CompanyCPPA: $1.35 million against Tractor Supply over missing opt-out mechanisms €1.16m
The rural retail giant inadequately informed consumers and job applicants about their rights, offered no effective means of opting out of the sale and sharing of data (including no Global Privacy Control) and passed data on to third parties without the required contracts. An officer must certify compliance annually for four years, as required by the California Privacy Protection Agency (CPPA).
Privacy notices must also cover job applicants, and browser opt-out signals such as GPC must be implemented technically.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 30 Sep 2025
Original amount 1,350,000 USD, converted at the ECB reference rate of 26 Sep 2025.
- CPPA: Tractor Supply Company enforcement decision Press release of an authority
- CPPA Order of Decision and Stipulated Final Order: Tractor Supply Company (ENF24-M-TR-04) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB —
The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.
Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-413/23 P
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Verordnung (EU) 2018/1725 (Informationspflicht)
- Status of proceedings
- under appeal
- Sector
- Public sector
- Published
- 4 Sep 2025
- Press Release No 107/25: Judgment of the Court in Case C-413/23 P EDPS v SRB Court press release
Checked against the official source on 25 Sep 2026 · Direct link