Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

5cases from 1 jurisdiction
€395mTotal of monetary amounts
€290mLargest single case: Uber Technologies Inc. und Uber B.V.
€4.75mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€290m
Q4 20241€4.75m
Q1 20250—
Q2 20251€50,000
Q3 20250—
Q4 20251€175,000
Q1 20260—
Q2 20261€100m
Q3 20260—

5 cases

1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia NetherlandsInternational data transfers €100m

Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.

What organisations can take from it

Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack NetherlandsData breaches and data security €175,000

In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.

What organisations can take from it

Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Mitigating circumstances
Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 AS Watson (Health & Beauty Continental Europe) B.V.AP reduces cookie fine against Kruidvat operator AS Watson to 50,000 EUR after objection NetherlandsCookies and tracking €50,000

The company behind the Kruidvat drugstore chain tracked visitors to Kruidvat.nl with tracking cookies without their knowledge or consent, enabling it to build profiles from location, pages visited, shopping basket and purchases. The Dutch data protection authority (Autoriteit Persoonsgegevens, AP) had imposed 600,000 EUR in 2024, upheld the objection in May 2025 and reduced the fine to 50,000 EUR.

What organisations can take from it

Set tracking cookies in an online shop only after genuine consent – pre-ticked or hidden consent is not sufficient.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 6 Abs. 1 i. V. m. Art. 5 Abs. 1 lit. a DSGVO (Tracking-Cookies ohne Einwilligung)
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
12 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Nov 2024 Netflix International B.V.AP: 4.75 million EUR against Netflix over insufficient privacy information NetherlandsData subject rights and transparency €4.75m

Between 2018 and 2020, Netflix did not adequately inform customers about what happens to their data, and the information available was partly unclear. The Dutch supervisory authority (Autoriteit Persoonsgegevens, AP) imposed 4.75 million EUR; Netflix has since revised its privacy statement.

What organisations can take from it

Privacy notices must be complete and comprehensible – and responses to customer requests must also be specific rather than generic.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a i. V. m. Art. 12 Abs. 1, Art. 13 Abs. 1 lit. c, e, f und Abs. 2 lit. a, Art. 15 Abs. 1 lit. a, c, d und Abs. 2 DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
The privacy statement and the information provided were subsequently improved.
Published
18 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jul 2024 Uber Technologies Inc. und Uber B.V.Uber: 290 million EUR – driver data sent to the USA for two years without a transfer tool NetherlandsInternational data transfers €290m

Uber stored sensitive data of European drivers – including location, payment and identity document data, and in some cases criminal and health data – on servers in the USA and from August 2021 no longer used any transfer tool. Following complaints from more than 170 French drivers, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 290 million EUR; it was the AP’s third fine against Uber.

What organisations can take from it

Intra-group transfers to headquarters are third-country transfers – anyone who lets a transfer tool lapse transfers data without a legal basis.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44 DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Transport, logistics and shipping
Employees
10,000 or more
Repeat case
yes
Published
26 Aug 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial