Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by action- Fine €20.3m 100 % · 10 cases
- Order — 0 % · 1 case
- Reprimand or warning — 0 % · 1 case
Who?
by sectorAll sectors
- Transport, logistics and shipping €20m 99 % · 4 cases
- Food and agriculture €120,000 1 % · 1 case
- Other €71,474 0 % · 1 case
- Healthcare €25,000 0 % · 2 cases
- Automotive €14,997 0 % · 1 case
- Public sector €10,000 0 % · 1 case
- Energy and utilities €6,000 0 % · 1 case
- Financial services and insurance — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 2 | €5m |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €6,801 |
| Q3 2025 | 1 | €1,000 |
| Q4 2025 | 2 | €15.1m |
| Q1 2026 | 2 | €24,997 |
| Q2 2026 | 2 | €77,474 |
| Q3 2026 | 2 | €24,000 |
12 cases
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles Order
The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.
Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.
Consent and proportionality in employee monitoring
- Authority / court
- Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 7 Jul 2026
- Upravno sodišče znova potrdilo prakso IP: sistematično GPS sledenje zaposlenim ni dopustno brez tehtnega razloga Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles €6,000
A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.
GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.
GPS tracking and employee data protection
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Liability of senior managers
- Additional fine of 600 EUR on the responsible person.
- Published
- 15 Apr 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware €71,474
An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.
Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.
Permissible monitoring of employees and IT use
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- Liability of senior managers
- Additional fine of 4,000 EUR on the responsible person.
- Published
- 9 Apr 2026
- Delodajalcu, ki je prikrito nadzoroval vse aktivnosti zaposlenih na računalnikih, izrečena globa več kot 70.000 EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR €14,997
An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.
Handling employees’ health data, e-mail distribution lists
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 19 Jan 2026
Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.
- ANSPDCP – Comunicat de presă 19.01.2026 (Continental Automotive Products SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log €10,000
In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.
Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.
Confidential handling of employees’ health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Απόφαση 1/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR €15m
In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.
Store employee performance metrics only for as long and in as much detail as their specific purpose requires.
- Authority / court
- Conseil d'État
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Conseil d'État, décision n° 492830 du 23 décembre 2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style €120,000
At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.
Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.
Employee monitoring through telematics
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- Mitigating circumstances
- Small number of data subjects (five employees), immediate suspension of the processing.
- Provvedimento del 18 dicembre 2025 [10213711] (Reg. 755/2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Aug 2025 Fachärztliche Ordination (Kardiologie, anonymisiert)Cardiologist pays 1,000 EUR for unauthorised ELGA access to a former employee's data €1,000
On 1 August 2024, a doctor accessed e-prescriptions and medication data of a former employee twelve times in the ELGA electronic health record without any treatment relationship. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 1,000 EUR (plus 100 EUR in costs); confession and a clean record were mitigating factors.
Access to health records is only permitted where there is a treatment relationship – and it is logged.
Access to health data only where there is a treatment relationship
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 1, Art. 9 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- No previous record, negligence, full cooperation and confession.
- Datenschutzbehörde, Straferkenntnis 2025-0.625.944 vom 21.08.2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2025 Waxholms Ångfartygs AktiebolagWaxholmsbolaget: fine for processing a captain’s breathalyser test results €6,801
The shipping company processed results of on-board breath alcohol tests that could be attributed to a complainant employed as a captain. The Swedish Authority for Privacy Protection (IMY) regarded this as processing without a legal basis and as unlawful processing of health data and imposed 75,000 SEK.
Monitoring data such as alcohol test results are employees’ health data – access, storage and legal basis must be settled before such tests are introduced.
Employee health data (alcohol tests)
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 6, Art. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 18 Jun 2025
Original amount 75,000 SEK, converted at the ECB reference rate of 18 Jun 2025.
- IMY – Tillsyn Waxholms Ångfartygs AB (WÅAB) Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2024-1520 (18.06.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father Reprimand or warning
A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.
HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.
Confidential delivery of HR correspondence
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση – Παράπονο vs Eurolife Ltd (23.12.2024) Decision of an authority
- 28/03/2025 Αποφάσεις: Οκτώβριος – Δεκέμβριος 2024 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 Foodinho S.r.l. (Glovo-Gruppe)Garante: 5 million EUR against Glovo subsidiary Foodinho over monitoring of riders €5m
The delivery platform unlawfully processed data on more than 35,000 riders: facial recognition for identity verification, location tracking even outside working hours and automated assessments without human review. Foodinho had already been sanctioned with 2.6 million EUR in 2021; in addition to 5 million EUR, the Italian data protection authority (Garante per la protezione dei dati personali) prohibited the biometric processing.
Algorithmic management of workers requires transparency and human review, and must not include tracking outside working hours.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO (u. a. Transparenz, biometrische Daten, automatisierte Entscheidungen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Repeat case
- yes
- Published
- 22 Nov 2024
- Rider, Garante privacy: no all'algoritmo incontestabile dai lavoratori Press release of an authority
- Garante – Rider: Sanzione di 2,6 milioni di euro a una piattaforma del gruppo Glovo (2021) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link