Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €98m 100 % · 9 cases
- Order — 0 % · 2 cases
- Other — 0 % · 1 case
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €79.1m |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €200,000 |
| Q3 2025 | 1 | — |
| Q4 2025 | 3 | €123,275 |
| Q1 2026 | 1 | — |
| Q2 2026 | 3 | €13m |
| Q3 2026 | 2 | €5.56m |
12 cases
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising Order
Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.
An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.
Handling objections to advertising and deletion requests
- Authority / court
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Published
- 26 Jun 2026
- Verfügung des EDÖB gegen Cream della Cream Switzerland GmbH und Philipp Plein International AG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements overturned
In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.
Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.
- Authority / court
- Cour administrative (Luxemburg); Verfahren der CNPD
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
- Action
- Order
- Status of proceedings
- overturned
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Mitigating circumstances
- Amazon had implemented the compliance order before the hearing.
- La CNPD obtient la mise en conformité effective des traitements d'Amazon (Arrêt de la Cour administrative du 12 mars 2026) Press release of an authority
- Décision concernant Amazon Europe Core S.À R.L. (Tribunal administratif, 18 mars 2025) Press release of an authority
- Justice Luxembourg – Arrêt de la Cour administrative du 12 mars 2026 (n° 52757C du rôle), Amazon/CNPD Court press release
- Justice Luxembourg – Jugement du tribunal administratif du 18 mars 2025, Amazon/CNPD Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier €80,000
Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).
Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.
Checking consent before telemarketing
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5, 6, 7, 29, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Απόφαση 44/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Dec 2025 Rickenbacher Data LLC (Datamasters)CPPA: $45,000 against data broker Datamasters over failure to register €38,275
Without registering as a data broker, the Texas reseller traded in the names and contact details of millions of people, sorted by illnesses such as Alzheimer's or addiction, by age, presumed ethnicity and political views. In addition to the fine, the California Privacy Protection Agency (CPPA) requires it to stop selling data on all Californians.
Companies that buy or sell address lists for advertising must check registration obligations – health-related lists are particularly risky.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- California Delete Act (Registrierungspflicht für Datenhändler)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Published
- 8 Jan 2026
Original amount 45,000 USD, converted at the ECB reference rate of 30 Dec 2025.
- CalPrivacy Data Broker Enforcement Strike Force: enforcement actions Press release of an authority
- CPPA Order of Decision: Rickenbacher Data LLC d/b/a Datamasters (ENF25-172-D-DA) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis €5,000
The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.
Data brokers must be able to prove for every record on which legal basis it was collected and resold.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Sep 2025 TikTok Pte. Ltd.Canadian regulators: TikTok inadequately protected children's data Other
The joint investigation by the Office of the Privacy Commissioner of Canada and the supervisory authorities of Québec, British Columbia and Alberta found that every year hundreds of thousands of children used the platform despite the minimum age of 13, and that TikTok processed data without valid consent, including for profiling and advertising. TikTok undertook to improve age verification and make privacy notices easier to understand, and already during the investigation largely stopped targeted advertising to under-18s (except by broad categories such as language and approximate location).
Age limits in the terms of use are not enough – platforms need effective age verification and child-appropriate transparency.
- Authority / court
- Office of the Privacy Commissioner of Canada gemeinsam mit den Aufsichten von Québec, British Columbia und Alberta
- Area of law
- Data protection · Marketing and consent
- Legal basis
- PIPEDA und Datenschutzgesetze für den Privatsektor von Québec, British Columbia und Alberta
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 23 Sep 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2025 CaixaBank, S.A.AEPD: 200,000 EUR against CaixaBank over continued storage of a non-customer's data €200,000
A person who was not (or no longer) a customer received a letter from CaixaBank about an update to its privacy statement, announcing that she would be contacted about her advertising preferences. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) considered the continued storage of her data to be an infringement of the principle of storage limitation and imposed 200,000 EUR; the bank's request for reconsideration was dismissed as inadmissible.
Before mass mailings, check whether the recipients' data may still be stored at all – former customers should be deleted, not written to.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- AEPD Resolución PS/00140/2024 (EXP202302270) Decision of an authority
- AEPD Resolución recurso de reposición PS/00140/2024 (Datum der Ausgangsentscheidung 05.06.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Feb 2024 Enel Energia S.p.A.Garante: record fine of 79 million EUR against Enel Energia over illegal telemarketing €79.1m
Unauthorised intermediaries exploited security gaps in Enel's customer and activation systems for illegal telemarketing; over several years, at least 9,300 contracts were activated, 978 of which were purchased from companies outside the sales network. The Italian data protection authority (Garante per la protezione dei dati personali) imposed 79,107,101 EUR; the Rome court (Tribunale di Roma) upheld the decision on 18 September 2025, and an appeal is pending.
Companies that organise sales through partners must secure their systems against third-party access and reject contracts from unknown sources.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO; Codice privacy (Telemarketing)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- Employees
- 10,000 or more
- Published
- 29 Feb 2024
- Telemarketing: il Garante privacy sanziona Enel Energia Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link