Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

7cases from 1 jurisdiction
€4.41mTotal of monetary amounts (5 cases with an amount)
€1.8mLargest single case: S-Pankki Oyj
€865,000Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium) €3.62m 82 % · 5 cases
  2. Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten €792,639 18 % · 1 case
  3. Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus — 0 % · 1 case

What for?

by topic
  1. Data breaches and data security €3.62m 82 % · 3 cases
  2. Data subject rights and transparency €797,639 18 % · 3 cases
  3. Cookies and tracking — 0 % · 1 case

Who?

by sector

All sectors

  1. Financial services and insurance €3.62m 82 % · 3 cases
  2. Retail and e-commerce €792,639 18 % · 1 case
  3. Telecoms, IT and software €5,000 0 % · 1 case
  4. Healthcare — 0 % · 1 case
  5. Transport, logistics and shipping — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20242€950,000
Q1 20250—
Q2 20251—
Q3 20251€1.8m
Q4 20251€865,000
Q1 20261€5,000
Q2 20261€792,639
Q3 20260—

7 cases

12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit FinlandData subject rights and transparency €792,639

The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.

What organisations can take from it

Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.

Authority / court
Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
18 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy FinlandData subject rights and transparency €5,000

Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.

What organisations can take from it

Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.

Relevance to training and awareness

Right of access to call recordings

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15 Abs. 1 und 3
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login FinlandData breaches and data security €865,000

Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.

What organisations can take from it

Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
28 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service FinlandData breaches and data security €1.8m

After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.

What organisations can take from it

Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
Published
10 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine FinlandCookies and tracking overturned

In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).

What organisations can take from it

Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.

Relevance to training and awareness

Tracking pixels on sensitive websites

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
Area of law
Data protection · Cookies and tracking
Legal basis
DSGVO Art. 9, Art. 25, Art. 32
Action
Fine
Status of proceedings
overturned
Sector
Healthcare
Published
4 Jun 2025

Amount in EUR; no ECB reference rate is available for this currency.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links FinlandData breaches and data security €950,000

On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.

What organisations can take from it

Personal links are not access protection – sensitive customer data requires authentication and regular security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
20 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Nov 2024 Posti Jakelu OyPosti: 2.4 million EUR for automatically created e-mailboxes – court annuls fine FinlandData subject rights and transparency overturned

Customers who ordered, for example, mail forwarding automatically received an electronic OmaPosti mailbox that could not be deselected separately; they were also informed insufficiently and in part incorrectly about the activation. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found no contractual legal basis for this bundling and imposed 2.4 million EUR together with a reprimand and an order to rectify the situation. On 3 November 2025 the Helsinki Administrative Court upheld the reprimand and the order on account of the insufficient information but annulled the fine, as it considered the processing necessary for the contract on Posti’s electronic services.

What organisations can take from it

Do not sell add-on services on the back of the contractual legal basis – anything not necessary for the main contract requires a separate choice.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 6 Abs. 1 lit. b, Art. 13, Art. 25
Action
Fine
Status of proceedings
overturned
Sector
Transport, logistics and shipping
Published
15 Nov 2024

Amount in EUR; no ECB reference rate is available for this currency.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial