Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

5cases from 1 jurisdiction
€45.2mTotal of monetary amounts (2 cases with an amount)
€45mLargest single case: Vodafone GmbH
€22.6mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) €45m 100 % · 1 case
  2. Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI) €195,000 0 % · 1 case
  3. Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI) — 0 % · 1 case
  4. Bundesgerichtshof (VI. Zivilsenat) — 0 % · 1 case
  5. Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit) — 0 % · 1 case

What for?

by topic
  1. Data processors €45m 100 % · 2 cases
  2. Data subject rights and transparency €195,000 0 % · 1 case
  3. Data breaches and data security — 0 % · 2 cases

Who?

by sector

All sectors

  1. Telecoms, IT and software €45m 100 % · 1 case
  2. Retail and e-commerce €195,000 0 % · 1 case
  3. Construction and real estate — 0 % · 1 case
  4. Media and online platforms — 0 % · 1 case
  5. Transport, logistics and shipping — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20241—
Q1 20250—
Q2 20251€45m
Q3 20251€195,000
Q4 20250—
Q1 20260—
Q2 20262—
Q3 20260—

5 cases

9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function GermanyData breaches and data security Fine

In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.

What organisations can take from it

Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.

Authority / court
Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5, Art. 25 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
Published
10 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late GermanyData processors Reprimand or warning

A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.

What organisations can take from it

Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.

Relevance to training and awareness

Reporting process for data breaches and management of service providers

Authority / court
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Mitigating circumstances
BVG has announced measures against similar incidents.
Published
4 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests GermanyData subject rights and transparency €195,000

A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).

What organisations can take from it

Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.

Relevance to training and awareness

Timely handling of access requests

Authority / court
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Betroffenenrechte)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
30 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) GermanyData breaches and data security Other

In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.

What organisations can take from it

Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.

Authority / court
Bundesgerichtshof (VI. Zivilsenat)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 82 Abs. 1 DSGVO
Action
Other
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
18 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial