Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

7cases from 1 jurisdiction
€12.2mTotal of monetary amounts
€5.47mLargest single case: EOS Matrix d.o.o.
€320,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€5.47m
Q1 20240—
Q2 20240—
Q3 20241€190,000
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20252€421,000
Q4 20252€6m
Q1 20261€100,000
Q2 20260—
Q3 20260—

7 cases

19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files CroatiaData subject rights and transparency €100,000

An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.

Relevance to training and awareness

Data minimisation for ID copies, retention periods

Missing or inadequate training played a role in the decision.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
negligent
Mitigating circumstances
No damage to data subjects was found.
Published
19 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses CroatiaInternational data transfers €4.5m

The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.

What organisations can take from it

Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords CroatiaData breaches and data security €320,000

The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).

What organisations can take from it

Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.

Relevance to training and awareness

Secure password storage in software development

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 31, Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
22 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data CroatiaData breaches and data security €101,000

Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.

Relevance to training and awareness

Access control and deletion periods for register data

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cap due to public tasks (Art. 44 of the Implementing Act).
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup CroatiaData breaches and data security €190,000

In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.

What organisations can take from it

Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.

Relevance to training and awareness

Notification of data breaches within 72 hours

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
13 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Oct 2023 EOS Matrix d.o.o.Croatia: 5.47 million EUR against debt collection company EOS Matrix after data leak CroatiaData breaches and data security €5.47m

An anonymous tip-off accompanied by a USB stick proved that data of 181,641 debtors had leaked from the debt collection company’s records; there were no systems for detecting unusual data retrievals. In addition, EOS Matrix stored health data up to and including diagnoses, data of non-debtors and call recordings without a legal basis; the Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 5.47 million EUR.

What organisations can take from it

Employees’ free-text notes can turn into impermissible health data – clear recording rules and monitoring of data retrievals are mandatory.

Relevance to training and awareness

No recording of health data in call notes

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 2, Art. 6 Abs. 1, Art. 9 Abs. 2, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Oct 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial