Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23 — 0 % · 1 case
- Gerichtshof der Europäischen Union, Rs. C-340/21 — 0 % · 1 case
- Gerichtshof der Europäischen Union, Rs. C-413/23 P — 0 % · 1 case
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | — |
| Q4 2025 | 1 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
3 cases
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB —
The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.
Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-413/23 P
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Verordnung (EU) 2018/1725 (Informationspflicht)
- Status of proceedings
- under appeal
- Sector
- Public sector
- Published
- 4 Sep 2025
- Press Release No 107/25: Judgment of the Court in Case C-413/23 P EDPS v SRB Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Dec 2023 Natsionalna agentsia za prihodite (NAP, bulgarische Steuerbehörde)CJEU: after hacker attack, Bulgaria's tax authority must prove adequate security —
Following a cyber attack in 2019, data on millions of people from the IT system of the Bulgarian tax authority (Natsionalna agentsia za prihodite, NAP) was published on the internet. The Court of Justice of the European Union (Case C-340/21) ruled that the controller must prove the adequacy of its protective measures, can be liable even for attacks by third parties, and that the mere fear of misuse of data can constitute non-material damage.
After an attack, the company bears the burden of proving adequate security – documenting the measures protects against liability.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-340/21
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 24, Art. 32, Art. 82
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 14 Dec 2023
Checked against the official source on 25 Sep 2026 · Direct link