Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
—Total of monetary amounts (0 cases with an amount)
—Largest single case
—Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23 — 0 % · 1 case
  2. Gerichtshof der Europäischen Union, Rs. C-340/21 — 0 % · 1 case
  3. Gerichtshof der Europäischen Union, Rs. C-413/23 P — 0 % · 1 case

What for?

by topic
  1. Data subject rights and transparency — 0 % · 2 cases
  2. Data breaches and data security — 0 % · 1 case

Who?

by sector

All sectors

  1. Public sector — 0 % · 2 cases
  2. Media and online platforms — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20251—
Q4 20251—
Q1 20260—
Q2 20260—
Q3 20260—

3 cases

2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts EU levelData subject rights and transparency —

On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.

What organisations can take from it

Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.

Authority / court
Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
Status of proceedings
unknown
Sector
Media and online platforms
Published
2 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB EU levelData subject rights and transparency —

The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.

What organisations can take from it

Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.

Authority / court
Gerichtshof der Europäischen Union, Rs. C-413/23 P
Area of law
Data protection · Data subject rights and transparency
Legal basis
Verordnung (EU) 2018/1725 (Informationspflicht)
Status of proceedings
under appeal
Sector
Public sector
Published
4 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Dec 2023 Natsionalna agentsia za prihodite (NAP, bulgarische Steuerbehörde)CJEU: after hacker attack, Bulgaria's tax authority must prove adequate security EU levelData breaches and data security —

Following a cyber attack in 2019, data on millions of people from the IT system of the Bulgarian tax authority (Natsionalna agentsia za prihodite, NAP) was published on the internet. The Court of Justice of the European Union (Case C-340/21) ruled that the controller must prove the adequacy of its protective measures, can be liable even for attacks by third parties, and that the mere fear of misuse of data can constitute non-material damage.

What organisations can take from it

After an attack, the company bears the burden of proving adequate security – documenting the measures protects against liability.

Authority / court
Gerichtshof der Europäischen Union, Rs. C-340/21
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 24, Art. 32, Art. 82
Status of proceedings
unknown
Sector
Public sector
Published
14 Dec 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial