Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by action- Fine €45m 100 % · 1 case
- Other — 0 % · 1 case
- Reprimand or warning — 0 % · 1 case
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €45m |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | — |
| Q3 2026 | 0 | — |
3 cases
4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late Reprimand or warning
A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.
Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.
Reporting process for data breaches and management of service providers
- Authority / court
- Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- BVG has announced measures against similar incidents.
- Published
- 4 May 2026
- Datenschutzbeauftragte verwarnt BVG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps €45m
Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.
Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.
Insider threats and oversight of sales partners
- Authority / court
- Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
- Published
- 3 Jun 2025
- Pressemitteilung 6/2025: BfDI verhängt Geldbußen gegen Vodafone Press release of an authority
- BfDI – Übersicht Pressemitteilungen (Datum 03.06.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack Other
Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.
Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.
Passing real data to service providers for support
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data processors
- Legal basis
- Datenschutzgesetz (DSG)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 1 May 2024
- EDÖB schliesst Untersuchungen gegen das Unternehmen Xplain und die Bundesämter fedpol und BAZG ab Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link