Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) €14,000 100 % · 5 cases
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 2 | €4,000 |
| Q1 2025 | 3 | €10,000 |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
5 cases
11 Mar 2025 Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC)Cyprus: reprimand for electricity supplier EAC over insecure app registration Reprimand or warning
A customer denied having registered in the EAC Mobile App and having changed his billing address there; the supplier could not prove that the mobile number used for identification originated from the customer himself. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) found breaches of accountability and data security, issued a reprimand and ordered the delivery address to be clarified with the customer in writing.
Self-registration in customer portals needs robust identity verification – otherwise invoices and data can be redirected.
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24, Art. 32 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Απόφαση – Γνωστοποίηση παραβίασης, Εφαρμογή EAC Mobile App (11.03.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long €10,000
The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.
Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση – Διατήρηση δεδομένων πέραν της νόμιμης περιόδου (ΟΧΣ, 10.03.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent Reprimand or warning
An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.
Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.
Disclosure of customer data to agents and colleagues in their own matters
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The company implemented the order
- Απόφαση – Γνωστοποίηση περιστατικού παραβίασης δεδομένων (Trust International Insurance, 07.02.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father Reprimand or warning
A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.
HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.
Confidential delivery of HR correspondence
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση – Παράπονο vs Eurolife Ltd (23.12.2024) Decision of an authority
- 28/03/2025 Αποφάσεις: Οκτώβριος – Δεκέμβριος 2024 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 CMC Certus Management Consultants LtdCyprus: 4,000 EUR against visa service provider CMC Certus – client documents on Scribd €4,000
Without informing them, the residence permit consultancy sent a client couple’s marriage certificate and proof of salary to a sister company in Georgia for translation; the documents subsequently appeared publicly on the Scribd platform. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 2,000 EUR each for an impermissible transfer to a third country and for lack of security measures, as well as a reprimand for insufficient cooperation.
Translation by a group company in a third country is also a data transfer – requiring safeguards, information and confidentiality rules.
Passing client documents on to translators and group companies
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 31, Art. 44 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Decision – Complaint against CMC Certus Management Consultants Ltd (26.11.2024) Decision of an authority
- 28/03/2025 Αποφάσεις: Οκτώβριος – Δεκέμβριος 2024 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link