Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by topic- Data processors €45m 75 % · 3 cases
- Marketing and consent €13m 22 % · 2 cases
- Video surveillance €1.52m 3 % · 2 cases
- Data subject rights and transparency €220,500 0 % · 4 cases
- Cookies and tracking €6,200 0 % · 1 case
- no topic €5,000 0 % · 1 case
- Employee data €1,000 0 % · 1 case
- Data breaches and data security — 0 % · 2 cases
Who?
by sectorAll sectors
- Telecoms, IT and software €45m 75 % · 2 cases
- Other €13m 22 % · 2 cases
- Retail and e-commerce €1.7m 3 % · 3 cases
- Food and agriculture €20,000 0 % · 1 case
- Media and online platforms €6,200 0 % · 2 cases
- Healthcare €6,000 0 % · 2 cases
- Financial services and insurance — 0 % · 2 cases
- Construction and real estate — 0 % · 1 case
- Transport, logistics and shipping — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €20,000 |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | — |
| Q3 2024 | 1 | €1.5m |
| Q4 2024 | 2 | €5,000 |
| Q1 2025 | 1 | — |
| Q2 2025 | 1 | €45m |
| Q3 2025 | 3 | €202,200 |
| Q4 2025 | 0 | — |
| Q1 2026 | 1 | €25,500 |
| Q2 2026 | 5 | €13m |
| Q3 2026 | 0 | — |
16 cases
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function Fine
In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.
Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.
- Authority / court
- Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5, Art. 25 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Liability of senior managers
- According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
- Published
- 10 Jun 2026
- Landgericht Berlin bestätigt Verstoß der Deutsche Wohnen SE gegen die DSGVO Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late Reprimand or warning
A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.
Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.
Reporting process for data breaches and management of service providers
- Authority / court
- Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- BVG has announced measures against similar incidents.
- Published
- 4 May 2026
- Datenschutzbeauftragte verwarnt BVG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising Order
Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.
An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.
Handling objections to advertising and deletion requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Published
- 26 Jun 2026
- Verfügung des EDÖB gegen Cream della Cream Switzerland GmbH und Philipp Plein International AG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests €195,000
A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).
Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.
Timely handling of access requests
- Authority / court
- Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Betroffenenrechte)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 30 Sep 2025
- Zwischenbilanz 2025: HmbBfDI verhängt Bußgelder von insgesamt 775.000 Euro Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Aug 2025 Fachärztliche Ordination (Kardiologie, anonymisiert)Cardiologist pays 1,000 EUR for unauthorised ELGA access to a former employee's data €1,000
On 1 August 2024, a doctor accessed e-prescriptions and medication data of a former employee twelve times in the ELGA electronic health record without any treatment relationship. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 1,000 EUR (plus 100 EUR in costs); confession and a clean record were mitigating factors.
Access to health records is only permitted where there is a treatment relationship – and it is logged.
Access to health data only where there is a treatment relationship
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 1, Art. 9 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- No previous record, negligence, full cooperation and confession.
- Datenschutzbehörde, Straferkenntnis 2025-0.625.944 vom 21.08.2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner €6,200
In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.
Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- DSB Straferkenntnis GZ 2025-0.276.820 vom 06.08.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps €45m
Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.
Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.
Insider threats and oversight of sales partners
- Authority / court
- Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
- Published
- 3 Jun 2025
- Pressemitteilung 6/2025: BfDI verhängt Geldbußen gegen Vodafone Press release of an authority
- BfDI – Übersicht Pressemitteilungen (Datum 03.06.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms Order
From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.
Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.
Handling access requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 1 Jul 2025
- Verfügung des EDÖB gegen die Cembra Money Bank AG Press release of an authority
- Verfügung des EDÖB vom 29. Januar 2025 gegen Cembra Money Bank AG Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) Other
In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.
Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.
- Authority / court
- Bundesgerichtshof (VI. Zivilsenat)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 82 Abs. 1 DSGVO
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 18 Nov 2024
- BGH Pressemitteilung Nr. 218/2024 – Leitentscheidung zum Scraping Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer €5,000
A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.
Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection
- Legal basis
- Art. 37, Art. 38 Abs. 6 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 50 to 249
- Liability of senior managers
- The managing director was also appointed as data protection officer – an impermissible conflict of interest.
- DSB Straferkenntnis GZ 2024-0.641.771 vom 16.10.2024 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Aug 2024 DSB: 1.5 million EUR against retail chain over cameras on self-checkouts, PIN pad and surroundings €1.5m
In 2022, a retail company (name pseudonymised) used nine cameras in one branch to film, among other things, the self-service checkouts including the keypad of the card payment terminal, as well as public areas, bus stops and neighbouring properties. The Austrian data protection authority (Datenschutzbehörde, DSB) imposed 1.5 million EUR for lack of a legal basis and infringement of data minimisation; the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the amount on 25 July 2025, and an appeal on points of law is pending.
Align cameras in retail closely with their protective purpose – PIN entries, public spaces and neighbouring properties must not be in the frame.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Retail and e-commerce
- DSB Straferkenntnis GZ 2023-0.680.196 vom 16.08.2024 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack Other
Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.
Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.
Passing real data to service providers for support
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data processors
- Legal basis
- Datenschutzgesetz (DSG)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 1 May 2024
- EDÖB schliesst Untersuchungen gegen das Unternehmen Xplain und die Bundesämter fedpol und BAZG ab Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Dec 2023 DSB: 20,000 EUR against restaurant business over constant surveillance of kitchen and pick-up area €20,000
A restaurant company with a delivery and pick-up service (name pseudonymised) recorded workstations in the kitchen and pick-up area without interruption, even outside opening hours, and stored the recordings for 14 days. In addition, there had been no record of processing activities since 2018; the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 20,000 EUR, and the penalty decision is final.
Even small businesses may not film employees permanently – and they need a record of their processing activities.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 30 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- DSB Straferkenntnis GZ 2023-0.583.644 vom 07.12.2023 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link