Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
€2.24mTotal of monetary amounts
€1.85mLargest single case: Elkjøp Nordic AS, Elkjøp Norge AS
€182,038Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Datatilsynet €2.24m 100 % · 4 cases

What for?

by topic
  1. Marketing and consent €1.85m 83 % · 1 case
  2. no topic €342,745 15 % · 1 case
  3. Data subject rights and transparency €40,076 2 % · 2 cases

Who?

by sector

All sectors

  1. Retail and e-commerce €1.87m 84 % · 2 cases
  2. Telecoms, IT and software €364,076 16 % · 2 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20251€342,745
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20261€21,331
Q2 20261€1.85m
Q3 20261€18,745

4 cases

12 Aug 2026 Lab Pharma ASLab Pharma AS: NOK 205,000 for threatening Datatilsynet staff NorwayData subject rights and transparency €18,745

Datatilsynet (Norwegian Data Protection Authority) fined the online dietary supplement retailer Lab Pharma AS NOK 205,000 for breaching its duty to cooperate with the supervisory authority (Art. 31 GDPR): the company had threatened case handlers with police reports and lawsuits in order to end the investigation of a complaint, and submitted requested documents late. The authority also ordered the company to delete the name and images of a former advertising partner (an influencer) from all its websites and to stop using her data for marketing until it can demonstrate a legal basis, as the underlying contract had already expired in March 2017.

What organisations can take from it

Anyone who considers a supervisory order unlawful must use the available appeal routes – threats against case handlers and missed deadlines become a sanctionable breach in their own right.

Relevance to training and awareness

Dealing with supervisory authorities and the duty to cooperate

Authority / court
Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 31, Art. 58 Abs. 2 lit. f, g und i, Art. 83 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Liability of senior managers
Datatilsynet attributed the intentional conduct of the company's management to the company.
Published
17 Aug 2026

Original amount 205,000 NOK, converted at the ECB reference rate of 12 Aug 2026.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Jun 2026 Elkjøp Nordic AS, Elkjøp Norge ASElkjøp: NOK 20m fine over invalid consent in customer club NorwayMarketing and consent €1.85m

Datatilsynet (Norwegian Data Protection Authority) fined Elkjøp Nordic AS and Elkjøp Norge AS NOK 20,000,000. Following an on-site inspection in June 2022, the authority found that consent for the customer club was neither informed nor specific nor freely given, that club data had been reused without a legal basis for the 'kundematch' (customer match) tool, that the lawfulness of so-called offline conversions had not been assessed and documented, and that rectification requests had not been handled within the deadlines. The decision was adopted under the cooperation mechanism with the supervisory authorities of Sweden, Iceland, Finland and Denmark; more than six million club members across the Nordic countries were affected.

What organisations can take from it

Anyone who ties discounts to club membership must obtain separate, informed and freely given consent in advance for each marketing purpose and must not reuse club data for new purposes such as audience matching without assessment.

Relevance to training and awareness

Valid consent in customer clubs and loyalty programmes

Authority / court
Datatilsynet
Area of law
Data protection · Marketing and consent
Legal basis
Art. 6 Abs. 1 i. V. m. Art. 4 Nr. 11, Art. 6 Abs. 4, Art. 5 Abs. 2 i. V. m. Art. 5 Abs. 1 lit. a, Art. 12 Abs. 3 DSGVO; Art. 58 Abs. 2 lit. i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Improvements made after the inspection, Datatilsynet's long case-handling time and the lack of evidence that sensitive data were processed; the amount is well below the starting point in the EDPB guidelines (0.4–0.8% of group turnover).
Published
4 Jun 2026

Original amount 20,000,000 NOK, converted at the ECB reference rate of 1 Jun 2026.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jan 2026 Timegrip ASTimegrip AS: NOK 250,000 for denying staff access to time records NorwayData subject rights and transparency €21,331

Datatilsynet (Norwegian Data Protection Authority) fined the time-recording system provider Timegrip AS NOK 250,000 because, after a retail chain went bankrupt, the company refused 80 former employees access to their clock-in data, which they needed to document their wage claims. The authority treated Timegrip as controller, since after the bankruptcy the company alone in fact decided on storage, use and access, and found a breach of the right of access under Art. 15(1) and (3) GDPR. A fine of NOK 750,000 had been notified; the authority took into account, among other things, the confused situation and its own long case-handling time.

What organisations can take from it

Processors should agree in their contracts how data will be released if the controller goes bankrupt – whoever in fact controls the data is liable as controller, including for access requests.

Relevance to training and awareness

Employees' right of access and the allocation of controller and processor roles

Authority / court
Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 15 Abs. 1 und 3, Art. 58 Abs. 2 lit. i, Art. 83 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Mitigating circumstances
The confused situation after the customer's bankruptcy (given only limited weight) and Datatilsynet's long case-handling time; NOK 750,000 had been notified.
Published
20 Jan 2026

Original amount 250,000 NOK, converted at the ECB reference rate of 16 Jan 2026.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Mar 2025 Telenor ASATelenor ASA: NOK 4m fine over data protection officer set-up and internal control NorwayData protection €342,745

Following an inspection, Datatilsynet (Norwegian Data Protection Authority) fined Telenor ASA NOK 4,000,000 because the group parent had not put in place appropriate organisational measures and policies for the position of its data protection officer (Art. 24(1) and (2) GDPR). The authority also issued a reprimand because for about one year there was no reporting line from the data protection officer to the highest management level, and ordered the company to carry out a documented assessment of whether it must designate a data protection officer and to revise its record of processing activities. According to Datatilsynet, the decision has been appealed and a ruling by the Personvernnemnda (Privacy Appeals Board) is expected in autumn 2026. The decision is not final.

What organisations can take from it

The data protection officer's role must be documented – with a direct reporting line to top management, clear rules on the officer's involvement and an assessment of potential conflicts of interest.

Relevance to training and awareness

Position and independence of the data protection officer

Authority / court
Datatilsynet
Area of law
Data protection
Legal basis
Art. 24 Abs. 1 und 2, Art. 30, Art. 37 Abs. 7, Art. 38 Abs. 2 und 3, Art. 58 Abs. 2 lit. b, d und i DSGVO; § 26 personopplysningsloven
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
No specific harm to data subjects was identified; the long case-handling time was taken into account when setting the amount.
Published
14 Mar 2025

Original amount 4,000,000 NOK, converted at the ECB reference rate of 10 Mar 2025.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial