Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
€2.4mTotal of monetary amounts
€2.39mLargest single case: Vinted, UAB
€9,000Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Valstybinė duomenų apsaugos inspekcija (VDAI) €2.4m 100 % · 3 cases

What for?

by topic
  1. Data subject rights and transparency €2.39m 99 % · 1 case
  2. Data breaches and data security €18,000 1 % · 2 cases

Who?

by sector

All sectors

  1. Media and online platforms €2.39m 99 % · 1 case
  2. Public sector €18,000 1 % · 2 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€2.39m
Q4 20241€9,000
Q1 20251€9,000
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20260—

3 cases

21 Jan 2025 Užimtumo tarnyba prie Lietuvos Respublikos socialinės apsaugos ir darbo ministerijosEmployment service sends Excel file with data of 29,636 clients – 9,000 EUR LithuaniaData breaches and data security €9,000

An employee accidentally attached an Excel file containing data of 29,636 clients, including health data, to an e-mail sent to 292 clients. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that measures to prevent data leakage had not been sufficiently tested and that the employee had not been involved in data classification and had been insufficiently instructed; fine of 9,000 EUR. Date = publication; source: archived copy.

What organisations can take from it

One wrong attachment is enough for a mass data breach – DLP tools only help if all employees are trained and involved.

Relevance to training and awareness

Checking e-mail attachments, data classification

Missing or inadequate training played a role in the decision.

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
21 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Oct 2024 Vilniaus rajono savivaldybės administracijaRansomware attack on Vilnius district administration – data protection fine of 9,000 EUR LithuaniaData breaches and data security €9,000

Following a break-in into the district administration’s servers in which data were encrypted, services failed and social benefits were delayed. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found insufficient malware protection, deficient management of rights and passwords, a lack of recovery and insufficient information of data subjects and imposed 9,000 EUR. Date = publication; source: archived copy.

What organisations can take from it

Backups, patch management and password rules are a data protection duty for public authorities too – and data subjects must receive specific advice on protecting themselves.

Relevance to training and awareness

Password security, ransomware preparedness

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. b, c und d, Art. 34 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
18 Oct 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2024 Vinted, UABVinted pays 2.39 million EUR over ‘shadow banning’ and handling of erasure requests LithuaniaData subject rights and transparency €2.39m

Acting on complaints from France and Poland, the Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that the second-hand platform rejected erasure requests when users did not state a ‘specific reason’ under Art. 17 GDPR, throttled users without their knowledge through ‘shadow banning’ and could not demonstrate how it handled access requests. Fine of 2,385,276 EUR. Source: archived copy of the press release.

What organisations can take from it

Covert restrictions on users are non-transparent – and erasure requests must not fail on formalities such as a requirement to give reasons.

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a, Art. 5 Abs. 2, Art. 12 Abs. 1 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
3 Jul 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial