Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Autoriteit Persoonsgegevens (AP) €395m 100 % · 5 cases
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €290m |
| Q4 2024 | 1 | €4.75m |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €50,000 |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €175,000 |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €100m |
| Q3 2026 | 0 | — |
5 cases
1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia €100m
Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.
Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack €175,000
In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.
Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
- Published
- 17 Dec 2025
- HAN krijgt boete van 175.000 euro voor onvoldoende beveiliging van persoonsgegevens Press release of an authority
- Boete HAN Decision of an authority
- AP: Besluit tot oplegging van een bestuurlijke boete aan Stichting Hogeschool van Arnhem en Nijmegen Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2025 AS Watson (Health & Beauty Continental Europe) B.V.AP reduces cookie fine against Kruidvat operator AS Watson to 50,000 EUR after objection €50,000
The company behind the Kruidvat drugstore chain tracked visitors to Kruidvat.nl with tracking cookies without their knowledge or consent, enabling it to build profiles from location, pages visited, shopping basket and purchases. The Dutch data protection authority (Autoriteit Persoonsgegevens, AP) had imposed 600,000 EUR in 2024, upheld the objection in May 2025 and reduced the fine to 50,000 EUR.
Set tracking cookies in an online shop only after genuine consent – pre-ticked or hidden consent is not sufficient.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 6 Abs. 1 i. V. m. Art. 5 Abs. 1 lit. a DSGVO (Tracking-Cookies ohne Einwilligung)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Retail and e-commerce
- Published
- 12 Jun 2025
- Besluit op bezwaar AS Watson – Kruidvat (27 mei 2025) Decision of an authority
- Besluit boete AS Watson – Kruidvat Decision of an authority
- AP – Boete van 600.000 euro voor tracking cookies op Kruidvat.nl Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 Netflix International B.V.AP: 4.75 million EUR against Netflix over insufficient privacy information €4.75m
Between 2018 and 2020, Netflix did not adequately inform customers about what happens to their data, and the information available was partly unclear. The Dutch supervisory authority (Autoriteit Persoonsgegevens, AP) imposed 4.75 million EUR; Netflix has since revised its privacy statement.
Privacy notices must be complete and comprehensible – and responses to customer requests must also be specific rather than generic.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a i. V. m. Art. 12 Abs. 1, Art. 13 Abs. 1 lit. c, e, f und Abs. 2 lit. a, Art. 15 Abs. 1 lit. a, c, d und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- The privacy statement and the information provided were subsequently improved.
- Published
- 18 Dec 2024
- Boete Netflix (Besluit van 26 november 2024) Decision of an authority
- AP – Boete Netflix voor niet goed informeren klanten Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2024 Uber Technologies Inc. und Uber B.V.Uber: 290 million EUR – driver data sent to the USA for two years without a transfer tool €290m
Uber stored sensitive data of European drivers – including location, payment and identity document data, and in some cases criminal and health data – on servers in the USA and from August 2021 no longer used any transfer tool. Following complaints from more than 170 French drivers, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 290 million EUR; it was the AP’s third fine against Uber.
Intra-group transfers to headquarters are third-country transfers – anyone who lets a transfer tool lapse transfers data without a legal basis.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 26 Aug 2024
- AP legt Uber boete op van 290 miljoen euro om doorgifte data chauffeurs naar VS (26.08.2024) Press release of an authority
- AP, Besluit boete Uber doorgifte naar VS vom 22.07.2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link