Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Datatilsynet 4 cases 100 % · €2.24m
What for?
by topic- Data subject rights and transparency 2 cases 50 % · €40,076
- Marketing and consent 1 case 25 % · €1.85m
- no topic 1 case 25 % · €342,745
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €342,745 |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 1 | €21,331 |
| Q2 2026 | 1 | €1.85m |
| Q3 2026 | 1 | €18,745 |
4 cases
12 Aug 2026 Lab Pharma ASLab Pharma AS: NOK 205,000 for threatening Datatilsynet staff €18,745
Datatilsynet (Norwegian Data Protection Authority) fined the online dietary supplement retailer Lab Pharma AS NOK 205,000 for breaching its duty to cooperate with the supervisory authority (Art. 31 GDPR): the company had threatened case handlers with police reports and lawsuits in order to end the investigation of a complaint, and submitted requested documents late. The authority also ordered the company to delete the name and images of a former advertising partner (an influencer) from all its websites and to stop using her data for marketing until it can demonstrate a legal basis, as the underlying contract had already expired in March 2017.
Anyone who considers a supervisory order unlawful must use the available appeal routes – threats against case handlers and missed deadlines become a sanctionable breach in their own right.
Dealing with supervisory authorities and the duty to cooperate
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 31, Art. 58 Abs. 2 lit. f, g und i, Art. 83 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Liability of senior managers
- Datatilsynet attributed the intentional conduct of the company's management to the company.
- Published
- 17 Aug 2026
Original amount 205,000 NOK, converted at the ECB reference rate of 12 Aug 2026.
- Datatilsynet: Overtredelsesgebyr til Lab Pharma AS (17.08.2026) Press release of an authority
- Datatilsynet, Vedtak om overtredelsesgebyr og pålegg om sletting og stans – Lab Pharma AS, 23/00435-62, 12.08.2026 Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
1 Jun 2026 Elkjøp Nordic AS, Elkjøp Norge ASElkjøp: NOK 20m fine over invalid consent in customer club €1.85m
Datatilsynet (Norwegian Data Protection Authority) fined Elkjøp Nordic AS and Elkjøp Norge AS NOK 20,000,000. Following an on-site inspection in June 2022, the authority found that consent for the customer club was neither informed nor specific nor freely given, that club data had been reused without a legal basis for the 'kundematch' (customer match) tool, that the lawfulness of so-called offline conversions had not been assessed and documented, and that rectification requests had not been handled within the deadlines. The decision was adopted under the cooperation mechanism with the supervisory authorities of Sweden, Iceland, Finland and Denmark; more than six million club members across the Nordic countries were affected.
Anyone who ties discounts to club membership must obtain separate, informed and freely given consent in advance for each marketing purpose and must not reuse club data for new purposes such as audience matching without assessment.
Valid consent in customer clubs and loyalty programmes
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 6 Abs. 1 i. V. m. Art. 4 Nr. 11, Art. 6 Abs. 4, Art. 5 Abs. 2 i. V. m. Art. 5 Abs. 1 lit. a, Art. 12 Abs. 3 DSGVO; Art. 58 Abs. 2 lit. i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Mitigating circumstances
- Improvements made after the inspection, Datatilsynet's long case-handling time and the lack of evidence that sensitive data were processed; the amount is well below the starting point in the EDPB guidelines (0.4–0.8% of group turnover).
- Published
- 4 Jun 2026
Original amount 20,000,000 NOK, converted at the ECB reference rate of 1 Jun 2026.
- Datatilsynet: Overtredelsesgebyr til Elkjøp (04.06.2026) Press release of an authority
- Datatilsynet, Vedtak om overtredelsesgebyr – Kundeklubb og de registrertes rettigheter, 22/00049-13, 01.06.2026 Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
16 Jan 2026 Timegrip ASTimegrip AS: NOK 250,000 for denying staff access to time records €21,331
Datatilsynet (Norwegian Data Protection Authority) fined the time-recording system provider Timegrip AS NOK 250,000 because, after a retail chain went bankrupt, the company refused 80 former employees access to their clock-in data, which they needed to document their wage claims. The authority treated Timegrip as controller, since after the bankruptcy the company alone in fact decided on storage, use and access, and found a breach of the right of access under Art. 15(1) and (3) GDPR. A fine of NOK 750,000 had been notified; the authority took into account, among other things, the confused situation and its own long case-handling time.
Processors should agree in their contracts how data will be released if the controller goes bankrupt – whoever in fact controls the data is liable as controller, including for access requests.
Employees' right of access and the allocation of controller and processor roles
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 15 Abs. 1 und 3, Art. 58 Abs. 2 lit. i, Art. 83 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Mitigating circumstances
- The confused situation after the customer's bankruptcy (given only limited weight) and Datatilsynet's long case-handling time; NOK 750,000 had been notified.
- Published
- 20 Jan 2026
Original amount 250,000 NOK, converted at the ECB reference rate of 16 Jan 2026.
- Datatilsynet: Overtredelsesgebyr for manglende innsyn (20.01.2026) Press release of an authority
- Datatilsynet, Vedtak om ileggelse av overtredelsesgebyr – Timegrip AS, 20/02911-20, 16.01.2026 Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
10 Mar 2025 Telenor ASATelenor ASA: NOK 4m fine over data protection officer set-up and internal control €342,745
Following an inspection, Datatilsynet (Norwegian Data Protection Authority) fined Telenor ASA NOK 4,000,000 because the group parent had not put in place appropriate organisational measures and policies for the position of its data protection officer (Art. 24(1) and (2) GDPR). The authority also issued a reprimand because for about one year there was no reporting line from the data protection officer to the highest management level, and ordered the company to carry out a documented assessment of whether it must designate a data protection officer and to revise its record of processing activities. According to Datatilsynet, the decision has been appealed and a ruling by the Personvernnemnda (Privacy Appeals Board) is expected in autumn 2026. The decision is not final.
The data protection officer's role must be documented – with a direct reporting line to top management, clear rules on the officer's involvement and an assessment of potential conflicts of interest.
Position and independence of the data protection officer
- Authority / court
- Datatilsynet
- Area of law
- Data protection
- Legal basis
- Art. 24 Abs. 1 und 2, Art. 30, Art. 37 Abs. 7, Art. 38 Abs. 2 und 3, Art. 58 Abs. 2 lit. b, d und i DSGVO; § 26 personopplysningsloven
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- No specific harm to data subjects was identified; the long case-handling time was taken into account when setting the amount.
- Published
- 14 Mar 2025
Original amount 4,000,000 NOK, converted at the ECB reference rate of 10 Mar 2025.
- Datatilsynet: Telenor ASA er ilagt sanksjoner for mangler ved personvernombudsordning og internkontroll (14.03.2025) Press release of an authority
- Datatilsynet, Vedtak – Personvernombudets rolle i Telenor ASA, 21/03823-45, 10.03.2025 Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link