Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Agencija za zaštitu osobnih podataka (AZOP) €12.2m 100 % · 7 cases
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €5.47m |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €190,000 |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 2 | €421,000 |
| Q4 2025 | 2 | €6m |
| Q1 2026 | 1 | €100,000 |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
7 cases
19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files €100,000
An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).
Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.
Data minimisation for ID copies, retention periods
Missing or inadequate training played a role in the decision.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- No damage to data subjects was found.
- Published
- 19 Feb 2026
- Agenciji za nekretnine izrečena kazna u iznosu od 100.000,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers €1.5m
The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).
Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Dec 2025
- Banci izrečena upravna novčana kazna u iznosu od 1,5 milijuna eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses €4.5m
The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.
Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 14 Nov 2025
- AZOP: Administrative Fine of EUR 4.5 Million Imposed on a Telecommunications Operator (14.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords €320,000
The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).
Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.
Secure password storage in software development
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 31, Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 22 Jul 2025
- Izrečene dvije upravne novčane kazne u iznosu od 370.000 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data €101,000
Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).
Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.
Access control and deletion periods for register data
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cap due to public tasks (Art. 44 of the Implementing Act).
- Published
- 2 Jul 2025
- Izrečeno osam upravnih novčanih kazni u ukupnom iznosu od 350.500,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup €190,000
In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.
Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.
Notification of data breaches within 72 hours
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 13 Sep 2024
- Izdane nove upravne novčane kazne u ukupnom iznosu od 270.700 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Oct 2023 EOS Matrix d.o.o.Croatia: 5.47 million EUR against debt collection company EOS Matrix after data leak €5.47m
An anonymous tip-off accompanied by a USB stick proved that data of 181,641 debtors had leaked from the debt collection company’s records; there were no systems for detecting unusual data retrievals. In addition, EOS Matrix stored health data up to and including diagnoses, data of non-debtors and call recordings without a legal basis; the Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 5.47 million EUR.
Employees’ free-text notes can turn into impermissible health data – clear recording rules and monitoring of data retrievals are mandatory.
No recording of health data in call notes
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 2, Art. 6 Abs. 1, Art. 9 Abs. 2, Art. 12, 13, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 5 Oct 2023
- Debt collection agency EOS Matrix d.o.o. imposed with administrative fine in the amount of 5.47 million EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link