Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €429.9m 100 % · 43 cases
- Other — 0 % · 4 cases
- Order — 0 % · 2 cases
- Reprimand or warning — 0 % · 2 cases
Who?
by sectorAll sectors
- Media and online platforms €342m 80 % · 4 cases
- Telecoms, IT and software €46.4m 11 % · 10 cases
- Other €16.2m 4 % · 4 cases
- Financial services and insurance €10.5m 2 % · 11 cases
- Public sector €6.76m 2 % · 11 cases
- Healthcare €3.47m 1 % · 6 cases
- Transport, logistics and shipping €3m 1 % · 1 case
- Energy and utilities €1.44m 0 % · 3 cases
- Food and agriculture €55,102 0 % · 1 case
- Construction and real estate — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 2 | €5.47m |
| Q1 2024 | 2 | €3m |
| Q2 2024 | 2 | €81,905 |
| Q3 2024 | 4 | €93m |
| Q4 2024 | 6 | €252m |
| Q1 2025 | 6 | €157,578 |
| Q2 2025 | 3 | €3.01m |
| Q3 2025 | 5 | €2.52m |
| Q4 2025 | 4 | €18.5m |
| Q1 2026 | 4 | €47.6m |
| Q2 2026 | 6 | €3.11m |
| Q3 2026 | 8 | €1.44m |
52 cases
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Jul 2026 Metropolitan Police ServiceICO: order and reprimand against London's Met Police after disclosure of sensitive data Order
The Metropolitan Police handed a defendant unredacted documents containing the new address and telephone number of a stalking victim, and in a circular e-mail disclosed 18 people with a parliamentary connection in an open recipient list. The UK Information Commissioner's Office (ICO) ordered improvements within 3 and 12 months, including in data protection training completion rates.
Policies are not enough if mandatory training goes uncompleted for years – monitor and enforce training completion rates.
Redacting documents, e-mail distribution lists (BCC), data protection training
Missing or inadequate training played a role in the decision.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Data Protection Act 2018, Section 40
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Culpability
- negligent
- Published
- 5 Aug 2026
- Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures Press release of an authority
- ICO Enforcement notice: Metropolitan Police Service Enforcement database of an authority
- ICO Reprimand: Metropolitan Police Service Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function Fine
In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.
Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.
- Authority / court
- Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5, Art. 25 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Liability of senior managers
- According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
- Published
- 10 Jun 2026
- Landgericht Berlin bestätigt Verstoß der Deutsche Wohnen SE gegen die DSGVO Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students Order
According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.
Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- FTC Act (Verbot unlauterer und irreführender Praktiken)
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 5 Jun 2026
- FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students' Personal Data Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack €1.12m
In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.
Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.
Recognising phishing
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- 40% reduction for early admission of liability; payment agreed without appeal.
- Published
- 11 May 2026
Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.
- Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach Press release of an authority
- ICO Enforcement: South Staffordshire Plc and South Staffordshire Water Plc Enforcement database of an authority
- ICO Monetary Penalty Notice: South Staffordshire Plc and South Staffordshire Water Plc Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers Other
Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.
Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.
- Authority / court
- Office of the Privacy Commissioner of Canada (OPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Privacy Act (Kanada)
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 7 May 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Other
Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.
Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.
Unauthorised viewing of patient records (snooping)
- Authority / court
- Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
- Published
- 18 Feb 2026
- Investigation reveals 71 snooping incidents by 36 healthcare workers following Lapu Lapu Day tragedy Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data €564,626
The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).
Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
- Published
- 26 Jan 2026
Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.
- IMY – Tillsyn Sportadmin i Skandinavien AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2025-7801 (26.01.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack €5m
In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.
Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.
Social engineering and account takeover
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 29 Jan 2026
- Violation de données : sanction de 5 millions d'euros à l'encontre de FRANCE TRAVAIL Press release of an authority
- CNIL – Les sanctions prononcées par la CNIL (Eintrag 22/01/2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts €42m
Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.
Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
- Published
- 14 Jan 2026
- Violation de données : sanction de 42 millions d'euros à l'encontre des sociétés FREE MOBILE et FREE Press release of an authority
- Délibération SAN-2026-001 du 8 janvier 2026 (FREE MOBILE) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack €175,000
In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.
Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
- Published
- 17 Dec 2025
- HAN krijgt boete van 175.000 euro voor onvoldoende beveiliging van persoonsgegevens Press release of an authority
- Boete HAN Decision of an authority
- AP: Besluit tot oplegging van een bestuurlijke boete aan Stichting Hogeschool van Arnhem en Nijmegen Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database €1.39m
In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.
Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.
Separation of personal and work devices and credentials
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 11 Dec 2025
Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.
- Password manager provider fined £1.2m by ICO for data breach Press release of an authority
- ICO Enforcement: LastPass UK Ltd Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login €865,000
Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.
Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 28 Oct 2025
- Finlex – Tietosuojavaltuutettu 23.10.2025 (pankin tunnistamispalvelun muutosprosessi) Decision of an authority
- Tietosuojavaltuutettu – Aktialle seuraamusmaksu tietoturvapuutteista vahvan sähköisen tunnistamisen palvelussa (28.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Oct 2025 Capita plc und Capita Pension Solutions LimitedICO: £14 million against Capita after ransomware attack affecting 6.6 million people €16.1m
In March 2023, an employee unintentionally downloaded malicious files; although an alert was triggered after ten minutes, the device was only isolated after 58 hours. Attackers stole around one terabyte of data on 6.6 million people (including pension data and criminal record information). Fines imposed by the UK Information Commissioner's Office (ICO): £8 million against Capita plc and £6 million against Capita Pension Solutions.
Security alerts need binding response times and an adequately staffed SOC – known vulnerabilities must be remedied across the group.
Handling malicious downloads and security alerts
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- £45 million had provisionally been proposed; reduced, among other things, for security improvements, credit monitoring for those affected and cooperation with authorities and the NCSC.
- Published
- 15 Oct 2025
Original amount 14,000,000 GBP, converted at the ECB reference rate of 15 Oct 2025.
- Capita fined £14m for data breach affecting over 6m people Press release of an authority
- ICO Enforcement: Capita plc Enforcement database of an authority
- ICO Monetary Penalty Notice: Capita plc and Capita Pension Solutions Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service €1.8m
After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.
Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
- Published
- 10 Sep 2025
- Finlex – Tietosuojavaltuutettu 8.9.2025, TSV/3606/2024 (pankin tunnistuspalvelu) Decision of an authority
- Tietosuojavaltuutettu – S-Pankille seuraamusmaksu S-mobiilin tietoturvahaavoittuvuudesta (10.09.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor €300,000
Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.
Processors are also independently liable for the security of the systems they operate.
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
- DVI – Zusammenfassung der Entscheidung zu SIA „ZZ Dats“ (08.09.2025) Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR €2,990
A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.
Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.
Identity verification and fraud detection in remote applications
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 12 Aug 2025
Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.
- ANSPDCP – Comunicat de presă 12.08.2025 (Asociația Casa de Ajutor Reciproc „FLEXICREDIT”) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords €320,000
The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).
Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.
Secure password storage in software development
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 31, Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 22 Jul 2025
- Izrečene dvije upravne novčane kazne u iznosu od 370.000 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data €101,000
Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).
Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.
Access control and deletion periods for register data
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Cap due to public tasks (Art. 44 of the Implementing Act).
- Published
- 2 Jul 2025
- Izrečeno osam upravnih novčanih kazni u ukupnom iznosu od 350.500,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data €2.74m
From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.
Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- negligent
- Published
- 17 Jun 2025
Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.
- 23andMe fined for failing to protect UK users' genetic data Press release of an authority
- ICO Penalty Notice: 23andMe, Inc. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 May 2025 Xfera Móviles, S.A.U.AEPD: 200,000 EUR against Xfera (MásMóvil) over number porting without consent €200,000
A customer's mobile number was ported to MásMóvil without the customer having requested it; the new SIM card was handed over to a third party who did not identify themselves. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found processing without a legal basis, imposed 200,000 EUR and ordered measures against such incidents; the company's request for reconsideration was unsuccessful.
Issue SIM cards and carry out porting only after robust identity verification – couriers and sales partners must comply with this too.
Identity verification for porting and SIM handover (SIM swapping)
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- AEPD Resolución PS/00170/2024 (EXP202301365) Decision of an authority
- AEPD Resolución recurso de reposición PS/00170/2024 (Datum der Ausgangsentscheidung 30.05.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2025 DPP Law LtdICO: £60,000 against law firm DPP Law over hack and late notification €69,458
In 2022, attackers used brute force to penetrate the law firm's network via a rarely used administrator account without MFA and stole 32 GB of highly sensitive data, which appeared on the dark web. The firm only learned of this from the National Crime Agency and reported the incident to the UK Information Commissioner's Office (ICO) only 43 days later.
Even small law firms need MFA on admin accounts and a reporting process that meets the 72-hour deadline.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2, Art. 33 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- negligent
- Published
- 16 Apr 2025
Original amount 60,000 GBP, converted at the ECB reference rate of 14 Apr 2025.
- Law firm fined £60,000 following cyber attack Press release of an authority
- ICO Enforcement: DPP Law Ltd Enforcement database of an authority
- ICO Monetary Penalty Notice: DPP Law Ltd Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Mar 2025 Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC)Cyprus: reprimand for electricity supplier EAC over insecure app registration Reprimand or warning
A customer denied having registered in the EAC Mobile App and having changed his billing address there; the supplier could not prove that the mobile number used for identification originated from the customer himself. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) found breaches of accountability and data security, issued a reprimand and ordered the delivery address to be clarified with the customer in writing.
Self-registration in customer portals needs robust identity verification – otherwise invoices and data can be redirected.
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24, Art. 32 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Απόφαση – Γνωστοποίηση παραβίασης, Εφαρμογή EAC Mobile App (11.03.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication €13,604
Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.
Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.
Protection of data subjects in press reports; encryption of storage media
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Published
- 11 Mar 2025
Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.
- Kara dla Polskiego Radia Szczecin za brak procedur chroniących prawa bohaterów publikacji Press release of an authority
- WSA oddalił skargę na decyzję Prezesa UODO w sprawie kary dla Radia Szczecin Press release of an authority
- Decyzja DKN.5112.10.2024 z 6 marca 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent Reprimand or warning
An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.
Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.
Disclosure of customer data to agents and colleagues in their own matters
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The company implemented the order
- Απόφαση – Γνωστοποίηση περιστατικού παραβίασης δεδομένων (Trust International Insurance, 07.02.2025) Decision of an authority
- 11/08/2025 Αποφάσεις: Ιανουάριος – Απρίλιος 2025 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jan 2025 Užimtumo tarnyba prie Lietuvos Respublikos socialinės apsaugos ir darbo ministerijosEmployment service sends Excel file with data of 29,636 clients – 9,000 EUR €9,000
An employee accidentally attached an Excel file containing data of 29,636 clients, including health data, to an e-mail sent to 292 clients. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that measures to prevent data leakage had not been sufficiently tested and that the employee had not been involved in data classification and had been insufficiently instructed; fine of 9,000 EUR. Date = publication; source: archived copy.
One wrong attachment is enough for a mass data breach – DLP tools only help if all employees are trained and involved.
Checking e-mail attachments, data classification
Missing or inadequate training played a role in the decision.
- Authority / court
- Valstybinė duomenų apsaugos inspekcija (VDAI)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 21 Jan 2025
- VDAI, Užimtumo tarnybai skirta bauda, 2025-01-21 (Archivkopie web.archive.org von vdai.lrv.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees €14,974
Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.
BCC, use of messaging apps, sending customer documents
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 20 Jan 2025
Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.
- ANSPDCP – Comunicat de presă 20.01.2025 (Vodafone Romania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jan 2025 Εθνική Τράπεζα της Ελλάδος Α.Ε. (National Bank of Greece)Greece: 120,000 EUR against National Bank of Greece after misdirected payment via mobile number €120,000
An IRIS transfer made by mobile number via the bank’s app ended up with an uninvolved customer instead of the intended recipient because the number had been assigned incorrectly. By Decision 3/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed 100,000 EUR for inaccurate data, insufficient security, lack of data protection by design and failure to notify the data breach, as well as 20,000 EUR for breach of the right of access.
Even a single misdirected payment can be a notifiable data breach – customer complaints must be assessed internally as a possible incident.
Recognising and reporting data breaches
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. d und f, Art. 15, 25, 32, 33, 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση 3/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification €251m
In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).
Make data breach notifications complete, and document every breach internally in a traceable manner.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 17 Dec 2024
- Irish Data Protection Commission fines Meta €251 Million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links €950,000
On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.
Personal links are not access protection – sensitive customer data requires authentication and regular security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 20 Dec 2024
- Tietosuojavaltuutettu – Sambla Groupille seuraamusmaksu (20.12.2024) Press release of an authority
- Finlex – Tietosuojavaltuutettu 17.12.2024 (lainanvertailupalvelu) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts Other
At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.
Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.
Offboarding, access rights and multi-factor authentication
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 27 Nov 2024
- Datatilsynet anmelder Lyngby-Taarbæk Kommune til politiet Decision of an authority
- Datatilsynet: Bødesager (Lyngby-Taarbæk Kommune unter „Sager, der fortsat verserer“) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Nov 2024 Meta Platforms Ireland Ltd.BGH: loss of control after Facebook scraping is compensable damage (VI ZR 10/24) Other
In April 2021, data on around 533 million Facebook users from 106 countries was made public, which unknown persons had previously linked to telephone numbers and harvested via the contact import function. Germany's Federal Court of Justice (Bundesgerichtshof, BGH) ruled that the mere loss of control over data already constitutes non-material damage under Art. 82 GDPR, considered around 100 EUR appropriate and referred the case back to the Higher Regional Court of Cologne (OLG Köln), among other things to examine the default searchability setting in the light of data minimisation.
Data breaches trigger compensation claims even without proven misuse – with millions of data subjects, this adds up to a mass risk.
- Authority / court
- Bundesgerichtshof (VI. Zivilsenat)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 82 Abs. 1 DSGVO
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 18 Nov 2024
- BGH Pressemitteilung Nr. 218/2024 – Leitentscheidung zum Scraping Court press release
Checked against the official source on 25 Sep 2026 · Direct link