Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine 5 cases 100 % · €924.5m
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €290m |
| Q4 2024 | 1 | €4,000 |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €530m |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €4.5m |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €100m |
| Q3 2026 | 0 | — |
5 cases
1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia €100m
Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.
Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses €4.5m
The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.
Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 14 Nov 2025
- AZOP: Administrative Fine of EUR 4.5 Million Imposed on a Telecommunications Operator (14.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China €530m
TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.
Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 46 Abs. 1, Art. 13 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 2 May 2025
- Irish Data Protection Commission fines TikTok €530 million and orders corrective measures Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 CMC Certus Management Consultants LtdCyprus: 4,000 EUR against visa service provider CMC Certus – client documents on Scribd €4,000
Without informing them, the residence permit consultancy sent a client couple’s marriage certificate and proof of salary to a sister company in Georgia for translation; the documents subsequently appeared publicly on the Scribd platform. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 2,000 EUR each for an impermissible transfer to a third country and for lack of security measures, as well as a reprimand for insufficient cooperation.
Translation by a group company in a third country is also a data transfer – requiring safeguards, information and confidentiality rules.
Passing client documents on to translators and group companies
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 31, Art. 44 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Decision – Complaint against CMC Certus Management Consultants Ltd (26.11.2024) Decision of an authority
- 28/03/2025 Αποφάσεις: Οκτώβριος – Δεκέμβριος 2024 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2024 Uber Technologies Inc. und Uber B.V.Uber: 290 million EUR – driver data sent to the USA for two years without a transfer tool €290m
Uber stored sensitive data of European drivers – including location, payment and identity document data, and in some cases criminal and health data – on servers in the USA and from August 2021 no longer used any transfer tool. Following complaints from more than 170 French drivers, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 290 million EUR; it was the AP’s third fine against Uber.
Intra-group transfers to headquarters are third-country transfers – anyone who lets a transfer tool lapse transfers data without a legal basis.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 26 Aug 2024
- AP legt Uber boete op van 290 miljoen euro om doorgifte data chauffeurs naar VS (26.08.2024) Press release of an authority
- AP, Besluit boete Uber doorgifte naar VS vom 22.07.2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link