Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

6cases from 1 jurisdiction
€2.65mTotal of monetary amounts
€143,655Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€55,102
Q3 20241€950,490
Q4 20240—
Q1 20251€13,604
Q2 20250—
Q3 20251€2,669
Q4 20250—
Q1 20262€1.63m
Q2 20260—
Q3 20260—

6 cases

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent PolandData protection €232,208

The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.

What organisations can take from it

Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Repeat case
yes
Mitigating circumstances
During the proceedings the function was made independent and placed directly under the management board.
Published
26 Jan 2026

Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN PolandData protection €2,669

For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.

What organisations can take from it

This also applies in small practices and companies: management cannot be its own data protection officer.

Relevance to training and awareness

Role and independence of the data protection officer; release of patient records

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
An independent external data protection officer was appointed in July 2024.
Published
29 Sep 2025

Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication PolandData breaches and data security €13,604

Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.

What organisations can take from it

Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.

Relevance to training and awareness

Protection of data subjects in press reports; encryption of storage media

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
Action
Fine
Status of proceedings
under appeal
Sector
Media and online platforms
Published
11 Mar 2025

Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing PolandData breaches and data security €950,490

In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.

What organisations can take from it

Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.

Relevance to training and awareness

Misdirected documents and notification of data subjects

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
9 Sep 2024

Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Apr 2024 Res-Gastro M. Gaweł Sp. k.UODO: 238,345 PLN against catering company after loss of an unencrypted USB stick PolandData breaches and data security €55,102

An employee of the catering company lost a USB stick containing unencrypted data on a colleague, including PESEL number, passport data and salary. The risk analysis had not provided for the mere loss of data carriers, encryption was left to employees with only an instruction video, and the effectiveness of the measures was not tested; the President of the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych, UODO) imposed 238,345 PLN (decision DKN.5131.29.2023, not final).

What organisations can take from it

Encryption of portable data carriers must be technically enforced – a training video alone impermissibly shifts responsibility onto employees.

Relevance to training and awareness

Handling portable data carriers and encryption

Missing or inadequate training played a role in the decision.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 5 Abs. 2, Art. 24 Abs. 1, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Self-reporting of the incident and cooperation in the proceedings substantially reduced the fine.
Published
17 May 2024

Original amount 238,345 PLN, converted at the ECB reference rate of 29 Apr 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial