Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Telenor Norge AS €4.21m 53 % · 1 case
- Anonymised companies €2.25m 28 % · 2 cases
- Odido Netherlands B.V. €1.52m 19 % · 1 case
- GoDaddy Inc. — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 2 | €2.25m |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | — |
| Q3 2025 | 1 | €4.21m |
| Q4 2025 | 1 | €1.52m |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
5 cases
17 Oct 2025 Odido Netherlands B.V.Netherlands: 1.52 million EUR against Odido – interception system without security plan and staff screening €1.52m
In inspections in 2021/22, the RDI (Rijksinspectie Digitale Infrastructuur, the Dutch Authority for Digital Infrastructure) found that the mobile operator had no mandatory security plan for its system for lawful interception of telecommunications, that employees with access had not been adequately screened (missing job descriptions, confidentiality declarations, certificates of conduct), that unauthorised persons had access to interception data and that suppliers could access the system digitally. The RDI imposed 1,518,750 EUR; Odido has since renewed the system.
Treat the security plan, staff screening and strictly limited supplier access for highly sensitive systems as the core of the obligation, not a formality.
Access rights, staff screening and supplier access for sensitive systems
- Authority / court
- Rijksinspectie Digitale Infrastructuur (RDI)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Telecommunicatiewet Art. 15.4; Besluit beveiliging gegevens telecommunicatie (Bbgt) Art. 2, 3, 4
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- System renewed, risk of unauthorised access eliminated.
- Published
- 17 Oct 2025
- RDI legt Odido boete op van ruim 1,5 miljoen vanwege onvoldoende beveiligd aftapsysteem Press release of an authority
- Beschikking tot oplegging bestuurlijke boete Odido (Publieksversie) Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
3 Jul 2025 Telenor Norge ASTelenor Norge: 50 million NOK after four disruptions to emergency numbers in autumn 2024 €4.21m
The Nasjonal kommunikasjonsmyndighet (Nkom, Norwegian Communications Authority) imposed an administrative penalty (overtredelsesgebyr) of 50,000,000 NOK on Telenor Norge because, on four occasions in autumn 2024 (29 August, 16 September, 17/18 October, 13 November), emergency calls over its network failed entirely or intermittently or were misrouted. The inspection found 22 breaches of ekomloven (Electronic Communications Act), sikkerhetsloven (National Security Act) and several regulations, including inadequate risk assessments, planned work not carried out securely, insufficient redundancy, inadequate auditing of a subcontractor and late notification of the authority. In its final decision Nkom maintained the amount announced in February 2025; the deadline for an administrative appeal ran until 8 September 2025.
Operators that carry emergency call services must safeguard planned network changes with a risk analysis and working redundancy, audit their suppliers and report disruptions on time.
Planned work on critical networks: risk analysis, a working fallback and notifying the regulator within 30 minutes
- Authority / court
- Nasjonal kommunikasjonsmyndighet (Nkom)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- ekomloven (lov 4. juli 2003 nr. 83), sikkerhetsloven (lov 1. juni 2018 nr. 24), ekomforskriften, nummerforskriften, klassifiseringsforskriften, virksomhetssikkerhetsforskriften
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 1,000 to 9,999
- Published
- 3 Jul 2025
Original amount 50,000,000 NOK, converted at the ECB reference rate of 3 Jul 2025.
- Nkom – Opprettholder millionbot mot Telenor (03.07.2025) Press release of an authority
- Nkom – Tilsynsrapporten mot Telenor er klar: Varsler bot på 50 millioner kroner (27.02.2025) Press release of an authority
- Nkom – Tilsynsrapport Telenor, offentlig sammendrag av sikkerhetsgradert tilsynsrapport (foreløpig), 27.02.2025 Decision of an authority
- Brønnøysundregistrene, Enhetsregisteret – Telenor Norge AS (org.nr. 976967631), antall ansatte Official register or notice
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
21 May 2025 GoDaddy Inc.FTC: GoDaddy must set up an information security programme after hosting security gaps Order
According to the Federal Trade Commission (FTC, the US consumer protection authority), the web host did not use multi-factor authentication for its hosting services, monitored security threats inadequately and did not secure connections to customer data, yet advertised “award-winning security”. The final order prohibits false statements about security and requires a comprehensive information security programme and regular reviews by independent assessors.
Be able to prove basics such as MFA and threat monitoring before advertising security – otherwise the advertising promise itself becomes the violation.
MFA, monitoring and honest security promises
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Section 5 FTC Act
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 21 May 2025
- FTC Finalizes Order with GoDaddy over Data Security Failures Press release of an authority
- FTC Takes Action Against GoDaddy for Alleged Lax Data Security for Its Website Hosting Services Press release of an authority
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
21 May 2024 a Dutch telecommunications providerNetherlands: 2.25 million EUR against a telecommunications provider over inadequately secured interception system €2.25m
According to the Dutch Authority for Digital Infrastructure (RDI), a Dutch telecommunications provider did not take the necessary measures from October 2021 to December 2022 to protect data from lawful interception of telecommunications against unauthorised persons: the security plan was inadequate, staff with access had not been sufficiently screened (missing job descriptions, confidentiality declarations, certificates of conduct), and logical and physical access controls were deficient. No actual unauthorised access was found; the fine amounts to 2.25 million EUR.
Treat interfaces for access by authorities as high-risk systems; document access controls and staff screening completely.
Access control and staff screening for interception interfaces
- Authority / court
- Rijksinspectie Digitale Infrastructuur (RDI)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Telecommunicatiewet Art. 15.4; Besluit beveiliging gegevens telecommunicatie (Bbgt) Art. 2, 3, 4, 8
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Deficiencies remedied after they were identified; no actual unauthorised access found.
- Published
- 22 Oct 2024
- RDI, Nachrichten (Übersicht) (Entscheidung 2024) Press release of an authority
Checked against the official source on 28 Sep 2026 · Version 4 · Company name anonymised since 21 May 2026 · Direct link
Report an error
20 May 2024 a US data services providerFTC: US data services provider must delete legacy data and strengthen security after hacker attack Order
According to the complaint of the Federal Trade Commission (FTC, the US consumer protection authority), an attacker exploited weaknesses in the network of the data services provider for companies and non-profit organisations in early 2020 and stole large amounts of unencrypted data, including Social Security and bank account numbers of millions of people; the attack went undetected for three months, the provider informed its customers only after almost two months and misrepresented the extent. The final order requires a comprehensive security programme, a data retention schedule, deletion of data no longer needed and notification of future reportable incidents to the FTC.
Set retention periods and deletion routines as security measures – data that is no longer needed is pure risk in an attack.
Data minimisation, encryption and honest incident communication
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Section 5 FTC Act
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 20 May 2024
- FTC, Pressemitteilungen (Übersicht) (Entscheidung 2024) Press release of an authority
Checked against the official source on 28 Sep 2026 · Version 3 · Company name anonymised since 20 May 2026 · Direct link