Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
€40,076Total of monetary amounts
€21,331Largest single case: Timegrip AS
€20,038Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Datatilsynet €40,076 100 % · 2 cases

What for?

by action
  1. Fine €40,076 100 % · 2 cases

Who?

by sector

All sectors

  1. Telecoms, IT and software €21,331 53 % · 1 case
  2. Retail and e-commerce €18,745 47 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20261€21,331
Q2 20260—
Q3 20261€18,745

2 cases

12 Aug 2026 Lab Pharma ASLab Pharma AS: NOK 205,000 for threatening Datatilsynet staff NorwayData subject rights and transparency €18,745

Datatilsynet (Norwegian Data Protection Authority) fined the online dietary supplement retailer Lab Pharma AS NOK 205,000 for breaching its duty to cooperate with the supervisory authority (Art. 31 GDPR): the company had threatened case handlers with police reports and lawsuits in order to end the investigation of a complaint, and submitted requested documents late. The authority also ordered the company to delete the name and images of a former advertising partner (an influencer) from all its websites and to stop using her data for marketing until it can demonstrate a legal basis, as the underlying contract had already expired in March 2017.

What organisations can take from it

Anyone who considers a supervisory order unlawful must use the available appeal routes – threats against case handlers and missed deadlines become a sanctionable breach in their own right.

Relevance to training and awareness

Dealing with supervisory authorities and the duty to cooperate

Authority / court
Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 31, Art. 58 Abs. 2 lit. f, g und i, Art. 83 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Liability of senior managers
Datatilsynet attributed the intentional conduct of the company's management to the company.
Published
17 Aug 2026

Original amount 205,000 NOK, converted at the ECB reference rate of 12 Aug 2026.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jan 2026 Timegrip ASTimegrip AS: NOK 250,000 for denying staff access to time records NorwayData subject rights and transparency €21,331

Datatilsynet (Norwegian Data Protection Authority) fined the time-recording system provider Timegrip AS NOK 250,000 because, after a retail chain went bankrupt, the company refused 80 former employees access to their clock-in data, which they needed to document their wage claims. The authority treated Timegrip as controller, since after the bankruptcy the company alone in fact decided on storage, use and access, and found a breach of the right of access under Art. 15(1) and (3) GDPR. A fine of NOK 750,000 had been notified; the authority took into account, among other things, the confused situation and its own long case-handling time.

What organisations can take from it

Processors should agree in their contracts how data will be released if the controller goes bankrupt – whoever in fact controls the data is liable as controller, including for access requests.

Relevance to training and awareness

Employees' right of access and the allocation of controller and processor roles

Authority / court
Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 15 Abs. 1 und 3, Art. 58 Abs. 2 lit. i, Art. 83 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Mitigating circumstances
The confused situation after the customer's bankruptcy (given only limited weight) and Datatilsynet's long case-handling time; NOK 750,000 had been notified.
Published
20 Jan 2026

Original amount 250,000 NOK, converted at the ECB reference rate of 16 Jan 2026.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial