Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

5cases from 3 jurisdictions
€457,759Total of monetary amounts (4 cases with an amount)
€336,066Largest single case: Santander Bank Polska S.A.
€51,681Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€23,362
Q1 20242€354,397
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20252€80,000
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20260—

5 cases

22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers SloveniaSecurity measures and risk management Reprimand or warning

After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).

What organisations can take from it

Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.

Relevance to training and awareness

Security testing for software releases of interfaces

Authority / court
Banka Slovenije
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance
Liability of senior managers
Reprimand also issued to the responsible Director of IT Development (Dejan Pust).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert ItalyIncident reporting obligations €80,000

A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.

What organisations can take from it

Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.

Relevance to training and awareness

Identity verification for customer requests by e-mail (social engineering)

Authority / court
Garante per la protezione dei dati personali
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported PolandIncident reporting obligations €336,066

A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.

What organisations can take from it

Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.

Relevance to training and awareness

Risk assessment and notification of data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Repeat case
yes
Published
2 Apr 2024

Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years PolandIncident reporting obligations €18,331

The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.

What organisations can take from it

Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.

Relevance to training and awareness

Recognising misdirected mail and reporting it internally

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
2 Apr 2024

Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator PolandIncident reporting obligations €23,362

The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.

What organisations can take from it

Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.

Relevance to training and awareness

Avoiding misdirected e-mails; reporting data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
intentional
Repeat case
yes
Published
23 Nov 2023

Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial