Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
—Total of monetary amounts (0 cases with an amount)
—Largest single case
—Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB) — 0 % · 3 cases
  2. Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025 — 0 % · 1 case

What for?

by topic
  1. Data subject rights and transparency — 0 % · 2 cases
  2. Data processors — 0 % · 1 case
  3. Marketing and consent — 0 % · 1 case

Who?

by sector

All sectors

  1. Financial services and insurance — 0 % · 2 cases
  2. Retail and e-commerce — 0 % · 1 case
  3. Telecoms, IT and software — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241—
Q3 20240—
Q4 20240—
Q1 20251—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20262—
Q3 20260—

4 cases

22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data SwitzerlandData subject rights and transparency Order

The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.

What organisations can take from it

Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.

Authority / court
Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 6, Art. 19, Art. 31
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising SwitzerlandMarketing and consent Order

Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.

What organisations can take from it

An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.

Relevance to training and awareness

Handling objections to advertising and deletion requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Marketing and consent
Legal basis
DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms SwitzerlandData subject rights and transparency Order

From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.

What organisations can take from it

Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.

Relevance to training and awareness

Handling access requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
1 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack SwitzerlandData processors Other

Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.

What organisations can take from it

Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.

Relevance to training and awareness

Passing real data to service providers for support

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data processors
Legal basis
Datenschutzgesetz (DSG)
Action
Other
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
1 May 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial