Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

6cases from 1 jurisdiction
€873.5mTotal of monetary amounts
€530mLargest single case: TikTok Technology Limited
€45.8mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€91m
Q4 20241€251m
Q1 20250—
Q2 20252€530.6m
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20261€277,500
Q3 20261€645,000

6 cases

25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records IrelandData breaches and data security €645,000

In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.

What organisations can take from it

Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.

Relevance to training and awareness

Physical security and retention of paper records

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector
Employees
10,000 or more
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2025 Department of Social Protection (DSP)DPC: 550,000 EUR against Irish social protection ministry over facial matching without legal basis IrelandData subject rights and transparency €550,000

For registration for the Public Services Card, the ministry created biometric facial templates of a large part of the population without a sufficiently clear legal basis, with deficient information and an incomplete data protection impact assessment. Ireland's Data Protection Commission (DPC) issued a reprimand, imposed 550,000 EUR and ordered the biometric processing to be stopped within nine months if no valid legal basis is found.

What organisations can take from it

Biometric procedures require a precise statutory basis and a complete impact assessment before they are rolled out widely.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und e, Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 Abs. 7 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Mitigating circumstances
No deficiencies were found in the technical and organisational security measures.
Published
12 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China IrelandInternational data transfers €530m

TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.

What organisations can take from it

Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · International data transfers
Legal basis
Art. 46 Abs. 1, Art. 13 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
2 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification IrelandData breaches and data security €251m

In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).

What organisations can take from it

Make data breach notifications complete, and document every breach internally in a traceable manner.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
17 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2024 Meta Platforms Ireland LimitedIreland: 91 million EUR against Meta over plaintext passwords IrelandData breaches and data security €91m

Meta stored users' passwords unencrypted in plaintext in internal systems and reported this to Ireland's Data Protection Commission (DPC) in March 2019. The DPC found infringements of the security obligations (Art. 5(1)(f), Art. 32(1)) and of the notification and documentation obligations (Art. 33(1) and (5)), and additionally issued a reprimand.

What organisations can take from it

Never store or log passwords in plaintext – not even in internal systems.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 und 5
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
According to the DPC, the passwords were not disclosed to external third parties.
Published
27 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial