Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €28.6m 100 % · 28 cases
- Order — 0 % · 4 cases
- Other — 0 % · 1 case
Who?
by sectorAll sectors
- Telecoms, IT and software €14m 49 % · 3 cases
- Media and online platforms €8.53m 30 % · 4 cases
- Financial services and insurance €2.41m 8 % · 7 cases
- Retail and e-commerce €2.15m 8 % · 6 cases
- Automotive €582,573 2 % · 1 case
- Public sector €550,000 2 % · 2 cases
- Energy and utilities €196,000 1 % · 2 cases
- Construction and real estate €100,000 0 % · 1 case
- Other €67,629 0 % · 5 cases
- Healthcare €21,274 0 % · 3 cases
- 1 more€0
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €157,176 |
| Q2 2024 | 1 | €13.9m |
| Q3 2024 | 1 | €2.39m |
| Q4 2024 | 3 | €4.76m |
| Q1 2025 | 5 | €768,073 |
| Q2 2025 | 4 | €1.3m |
| Q3 2025 | 4 | €1.35m |
| Q4 2025 | 4 | €1.52m |
| Q1 2026 | 8 | €1.54m |
| Q2 2026 | 4 | €988,639 |
| Q3 2026 | 0 | — |
35 cases
22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data Order
The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.
Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.
- Authority / court
- Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 6, Art. 19, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 20 Aug 2026
- Bundesverwaltungsgericht bestätigt Entscheid des EDÖB Press release of an authority
- Urteil des Bundesverwaltungsgerichts A-3891/2025 vom 22. Juni 2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit €792,639
The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.
Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.
- Authority / court
- Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Retail and e-commerce
- Published
- 18 Jun 2026
- Supreme Administrative Court upholds the administrative fine imposed on Verkkokauppa.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency €86,000
The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.
Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.
Recording of customer calls
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- APD – Décision quant au fond n° 102/2026 du 12 mai 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2026 Loblaw Companies LimitedOPC: Loblaw must change retention of PC Optimum data after account deletion Other
During a wave of boycotts in 2024, Loblaw did not process deletion requests in time and retained purchase and usage data from the loyalty programme (more than 17 million members) even after accounts were closed, without demonstrating effective anonymisation. Loblaw undertook to the Office of the Privacy Commissioner of Canada (OPC) to have the anonymisation independently reviewed and to carry out annual deletions.
Companies that continue to use data as anonymous after account deletion must be able to demonstrate the re-identification risk – IP addresses are often enough to link data to a person.
- Authority / court
- Office of the Privacy Commissioner of Canada (OPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- PIPEDA
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 5 Mar 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy €5,000
Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.
Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.
Right of access to call recordings
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15 Abs. 1 und 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 25 Mar 2026
- Finlex – Tietosuojavaltuutettu 2.3.2026 (puhelutallenteet) Decision of an authority
- Tietosuojavaltuutettu – Suomen Numerokeskukselle seuraamusmaksu puutteista puhelutallenteiden antamisessa (25.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files €100,000
An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).
Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.
Data minimisation for ID copies, retention periods
Missing or inadequate training played a role in the decision.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- No damage to data subjects was found.
- Published
- 19 Feb 2026
- Agenciji za nekretnine izrečena kazna u iznosu od 100.000,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers €1.5m
The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).
Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Dec 2025
- Banci izrečena upravna novčana kazna u iznosu od 1,5 milijuna eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers €17,600
The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.
New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Mitigating circumstances
- Partial immediate payment (20% reduction under Art. 85 LPACAP).
- AEPD Resolución PS/00160/2024 (EXP202308414) Decision of an authority
- AEPD Resolución recurso de reposición PS/00160/2024 (Datum der Ausgangsentscheidung 13.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests €195,000
A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).
Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.
Timely handling of access requests
- Authority / court
- Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Betroffenenrechte)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 30 Sep 2025
- Zwischenbilanz 2025: HmbBfDI verhängt Bußgelder von insgesamt 775.000 Euro Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2025 Tractor Supply CompanyCPPA: $1.35 million against Tractor Supply over missing opt-out mechanisms €1.16m
The rural retail giant inadequately informed consumers and job applicants about their rights, offered no effective means of opting out of the sale and sharing of data (including no Global Privacy Control) and passed data on to third parties without the required contracts. An officer must certify compliance annually for four years, as required by the California Privacy Protection Agency (CPPA).
Privacy notices must also cover job applicants, and browser opt-out signals such as GPC must be implemented technically.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 30 Sep 2025
Original amount 1,350,000 USD, converted at the ECB reference rate of 26 Sep 2025.
- CPPA: Tractor Supply Company enforcement decision Press release of an authority
- CPPA Order of Decision and Stipulated Final Order: Tractor Supply Company (ENF24-M-TR-04) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB —
The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.
Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-413/23 P
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Verordnung (EU) 2018/1725 (Informationspflicht)
- Status of proceedings
- under appeal
- Sector
- Public sector
- Published
- 4 Sep 2025
- Press Release No 107/25: Judgment of the Court in Case C-413/23 P EDPS v SRB Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers Order
The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.
Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Ettekirjutus-hoiatus nr 2.1-1/24/1048-2575-22 (ESTO AS), 23.07.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2025 Department of Social Protection (DSP)DPC: 550,000 EUR against Irish social protection ministry over facial matching without legal basis €550,000
For registration for the Public Services Card, the ministry created biometric facial templates of a large part of the population without a sufficiently clear legal basis, with deficient information and an incomplete data protection impact assessment. Ireland's Data Protection Commission (DPC) issued a reprimand, imposed 550,000 EUR and ordered the biometric processing to be stopped within nine months if no valid legal basis is found.
Biometric procedures require a precise statutory basis and a complete impact assessment before they are rolled out widely.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und e, Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 Abs. 7 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Mitigating circumstances
- No deficiencies were found in the technical and organisational security measures.
- Published
- 12 Jun 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Apr 2025 Dante International SADante International fails to act on erasure requests – 10,000 EUR €10,000
Although the platform operator had repeatedly confirmed to a customer that his e-mail addresses had been deleted, he continued to receive feedback requests; in addition, certain partners could see the address. The Romanian data protection authority (ANSPDCP) found breaches of transparency and erasure obligations, imposed 49,770 lei (10,000 EUR) and ordered, among other things, training of the staff responsible.
A confirmed erasure must actually be implemented in all systems – including feedback and partner tools.
Handling erasure requests in customer service
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 12 Abs. 1 i. V. m. Art. 17 und 19 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 24 Apr 2025
Original amount 49,770 RON, converted at the ECB reference rate of 24 Apr 2025.
- ANSPDCP – Comunicat de presă 24.04.2025 (Dante International SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2025 Iberinform Internacional, S.A.AEPD: 720,000 EUR against business information agency Iberinform for purchased data on entrepreneurs €720,000
Since 2008, Iberinform had obtained data on sole traders through a supply contract with Camerdata and used it to enrich its own files for commercial information services. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found no legal basis for this and no information of the data subjects, and imposed 360,000 EUR for each (720,000 EUR in total) as well as an order to bring the processing into compliance; the request for reconsideration (recurso de reposición) was rejected.
Companies that purchase personal data from third parties need their own legal basis and must actively inform the data subjects.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 14 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- AEPD Resolución PS/00150/2024 (EXP202404645) Decision of an authority
- AEPD Resolución recurso de reposición PS/00150/2024 (Datum der Ausgangsentscheidung 14.04.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO €20,000
Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.
Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.
Implementing rectification requests promptly
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- IDPC Decision CDP/COMP/282/2024 Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long €10,000
The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.
Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση – Διατήρηση δεδομένων πέραν της νόμιμης περιόδου (ΟΧΣ, 10.03.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Mar 2025 American Honda Motor Co., Inc.CPPA: $632,500 against Honda over obstructed privacy requests €582,573
Honda required excessive information for opt-out requests, used a cookie tool without equivalent choices, made it harder to appoint authorised agents and passed data on to ad-tech firms without the required contracts. The order of the California Privacy Protection Agency (CPPA) requires, among other things, a simplified procedure and training for employees.
Do not undermine data subject rights through form hurdles or asymmetric consent dialogues.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Automotive
- Employees
- 10,000 or more
- Published
- 12 Mar 2025
Original amount 632,500 USD, converted at the ECB reference rate of 7 Mar 2025.
- CPPA: Enforcement action against American Honda Motor Co. Press release of an authority
- CPPA Order of Decision: American Honda Motor Co., Inc. (ENF23-V-HO-2) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2025 SIA "VSV ZOO"Pet shop VSV ZOO fails to respond to review of privacy policy – 500 EUR €500
As part of a preventive review of the privacy policy on zoopasaule.lv, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) repeatedly asked the online pet retailer for information from July 2024 onwards. The company let the first deadlines lapse, later twice asked for an extension citing the absence of its programmer, and still did not deliver thereafter. The DVI imposed 500 EUR for failure to cooperate with the supervisory authority.
A preventive request from the supervisory authority is also binding – anyone who does not respond is sanctioned before the actual deficiency is even addressed.
Handling letters from the data protection authority
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. d und e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „VSV ZOO“), 06.03.2025 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms Order
From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.
Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.
Handling access requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
- Action
- Order
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 1 Jul 2025
- Verfügung des EDÖB gegen die Cembra Money Bank AG Press release of an authority
- Verfügung des EDÖB vom 29. Januar 2025 gegen Cembra Money Bank AG Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Jan 2025 Luxembourg credit institution: 175,000 EUR for late responses to data subject requests €175,000
Following 47 complaints, the Commission nationale pour la protection des données (Luxembourg data protection authority, CNPD) found that a Luxembourg credit institution (pseudonymised in the decision as ‘Société A’) had not responded to data subjects’ requests on time; the CNPD did not accept the reference to the COVID-19 pandemic. It issued a reprimand (rappel à l’ordre) and imposed 175,000 EUR.
Data subject requests require deadline tracking and a monitored DPO mailbox – staff shortages are no excuse.
Deadlines for data subject requests
- Authority / court
- Commission nationale pour la protection des données (CNPD) – formation restreinte
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 12 Abs. 3 und 4
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- CNPD – Délibération n° 1FR/2025 du 6 janvier 2025 (Société A) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 Netflix International B.V.AP: 4.75 million EUR against Netflix over insufficient privacy information €4.75m
Between 2018 and 2020, Netflix did not adequately inform customers about what happens to their data, and the information available was partly unclear. The Dutch supervisory authority (Autoriteit Persoonsgegevens, AP) imposed 4.75 million EUR; Netflix has since revised its privacy statement.
Privacy notices must be complete and comprehensible – and responses to customer requests must also be specific rather than generic.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a i. V. m. Art. 12 Abs. 1, Art. 13 Abs. 1 lit. c, e, f und Abs. 2 lit. a, Art. 15 Abs. 1 lit. a, c, d und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- The privacy statement and the information provided were subsequently improved.
- Published
- 18 Dec 2024
- Boete Netflix (Besluit van 26 november 2024) Decision of an authority
- AP – Boete Netflix voor niet goed informeren klanten Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 Posti Jakelu OyPosti: 2.4 million EUR for automatically created e-mailboxes – court annuls fine overturned
Customers who ordered, for example, mail forwarding automatically received an electronic OmaPosti mailbox that could not be deselected separately; they were also informed insufficiently and in part incorrectly about the activation. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found no contractual legal basis for this bundling and imposed 2.4 million EUR together with a reprimand and an order to rectify the situation. On 3 November 2025 the Helsinki Administrative Court upheld the reprimand and the order on account of the insufficient information but annulled the fine, as it considered the processing necessary for the contract on Posti’s electronic services.
Do not sell add-on services on the back of the contractual legal basis – anything not necessary for the main contract requires a separate choice.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 6 Abs. 1 lit. b, Art. 13, Art. 25
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Transport, logistics and shipping
- Published
- 15 Nov 2024
Amount in EUR; no ECB reference rate is available for this currency.
- Tietosuojavaltuutettu – Postille seuraamusmaksu OmaPosti-palvelun tietosuojapuutteista (15.11.2024) Press release of an authority
- Finlex – Tietosuojavaltuutettu 13.11.2024 (sähköinen postilaatikko) Decision of an authority
- Helsingin hallinto-oikeus – kumosi Posti Jakelu Oy:lle määrätyn 2,4 miljoonan euron seuraamusmaksun (03.11.2025) Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Oct 2024 Untold SRLUntold SRL fails to answer access and erasure request – 15,000 EUR €14,998
Untold SRL left an access request and an erasure request from a data subject unanswered, even though the data subject had provided all contact details. The Romanian data protection authority (ANSPDCP) imposed 49,741 lei (10,000 EUR) in respect of access and 24,870.5 lei (5,000 EUR) in respect of erasure and ordered staff training. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Data subject requests need a ticketing system with the one-month deadline – seasonal event organisers included.
Timely handling of data subject requests
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 12 Abs. 3 und 4, Art. 15, Art. 17 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 30 Oct 2024
Original amount 74,611.5 RON, converted at the ECB reference rate of 30 Oct 2024.
- ANSPDCP – Comunicat de presă 30.10.2024 (Untold SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2024 Vinted, UABVinted pays 2.39 million EUR over ‘shadow banning’ and handling of erasure requests €2.39m
Acting on complaints from France and Poland, the Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that the second-hand platform rejected erasure requests when users did not state a ‘specific reason’ under Art. 17 GDPR, throttled users without their knowledge through ‘shadow banning’ and could not demonstrate how it handled access requests. Fine of 2,385,276 EUR. Source: archived copy of the press release.
Covert restrictions on users are non-transparent – and erasure requests must not fail on formalities such as a requirement to give reasons.
- Authority / court
- Valstybinė duomenų apsaugos inspekcija (VDAI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 5 Abs. 2, Art. 12 Abs. 1 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 3 Jul 2024
- VDAI, Pranešimas 2024-07-03 (Archivkopie web.archive.org von vdai.lrv.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2024 Avast Software s.r.o.Avast: 351 million CZK for passing browsing histories to Jumpshot €13.9m
In 2019, the antivirus manufacturer passed pseudonymised browsing histories of around 100 million users to its subsidiary Jumpshot, which sold insights into online behaviour to marketing clients. The data declared as anonymous allowed re-identification and users were misinformed; the Úřad pro ochranu osobních údajů (Czech data protection authority, ÚOOÚ) imposed a final fine of 351 million CZK.
Pseudonymised data are not anonymous data – anyone passing on usage data must assess re-identification risks and inform users honestly.
- Authority / court
- Úřad pro ochranu osobních údajů (ÚOOÚ)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (unrechtmäßige Verarbeitung, Transparenz), One-Stop-Shop-Verfahren
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 15 Apr 2024
Original amount 351,000,000 CZK, converted at the ECB reference rate of 15 Apr 2024.
- ÚOOÚ uložil pokutu 351 mil. Kč za porušení GDPR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jan 2024 Black Tiger Belgium (vormals Bisnode Belgium)Black Tiger Belgium: fine for non-transparent data trading, reduced by 10% in court €157,176
The data broker processed data obtained from third-party sources (including the companies register) on a large scale and over a long period without proactively informing the data subjects; access requests were answered incompletely and the record of processing activities had gaps. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed three fines totalling 174,640 EUR and prohibited, among other things, the ‘Data Quality’ service until data subjects had been informed; on 4 September 2024 the Brussels Market Court set aside the orders and reduced the fines by 10% to a total of 157,176 EUR.
Anyone collecting data indirectly must actively inform data subjects – legitimate interest does not hold where laws prohibit further use.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO – Rechtmäßigkeit, Fairness und Transparenz, Auskunftsrecht, Verzeichnis von Verarbeitungstätigkeiten
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Discontinuation of the ‘Data Delivery’ service and destruction of the CMX consumer database.
- Published
- 16 Jan 2024
Checked against the official source on 25 Sep 2026 · Direct link