Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

5cases from 3 jurisdictions
€7.98mTotal of monetary amounts (3 cases with an amount)
€4.21mLargest single case: Telenor Norge AS
€2.25mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20242€2.25m
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20251—
Q3 20251€4.21m
Q4 20251€1.52m
Q1 20260—
Q2 20260—
Q3 20260—

5 cases

3 Jul 2025 Telenor Norge ASTelenor Norge: 50 million NOK after four disruptions to emergency numbers in autumn 2024 NorwayCritical infrastructure €4.21m

The Nasjonal kommunikasjonsmyndighet (Nkom, Norwegian Communications Authority) imposed an administrative penalty (overtredelsesgebyr) of 50,000,000 NOK on Telenor Norge because, on four occasions in autumn 2024 (29 August, 16 September, 17/18 October, 13 November), emergency calls over its network failed entirely or intermittently or were misrouted. The inspection found 22 breaches of ekomloven (Electronic Communications Act), sikkerhetsloven (National Security Act) and several regulations, including inadequate risk assessments, planned work not carried out securely, insufficient redundancy, inadequate auditing of a subcontractor and late notification of the authority. In its final decision Nkom maintained the amount announced in February 2025; the deadline for an administrative appeal ran until 8 September 2025.

What organisations can take from it

Operators that carry emergency call services must safeguard planned network changes with a risk analysis and working redundancy, audit their suppliers and report disruptions on time.

Relevance to training and awareness

Planned work on critical networks: risk analysis, a working fallback and notifying the regulator within 30 minutes

Authority / court
Nasjonal kommunikasjonsmyndighet (Nkom)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
ekomloven (lov 4. juli 2003 nr. 83), sikkerhetsloven (lov 1. juni 2018 nr. 24), ekomforskriften, nummerforskriften, klassifiseringsforskriften, virksomhetssikkerhetsforskriften
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
1,000 to 9,999
Published
3 Jul 2025

Original amount 50,000,000 NOK, converted at the ECB reference rate of 3 Jul 2025.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Oct 2025 Odido Netherlands B.V.Netherlands: 1.52 million EUR against Odido – interception system without security plan and staff screening NetherlandsCritical infrastructure €1.52m

In inspections in 2021/22, the RDI (Rijksinspectie Digitale Infrastructuur, the Dutch Authority for Digital Infrastructure) found that the mobile operator had no mandatory security plan for its system for lawful interception of telecommunications, that employees with access had not been adequately screened (missing job descriptions, confidentiality declarations, certificates of conduct), that unauthorised persons had access to interception data and that suppliers could access the system digitally. The RDI imposed 1,518,750 EUR; Odido has since renewed the system.

What organisations can take from it

Treat the security plan, staff screening and strictly limited supplier access for highly sensitive systems as the core of the obligation, not a formality.

Relevance to training and awareness

Access rights, staff screening and supplier access for sensitive systems

Authority / court
Rijksinspectie Digitale Infrastructuur (RDI)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Telecommunicatiewet Art. 15.4; Besluit beveiliging gegevens telecommunicatie (Bbgt) Art. 2, 3, 4
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
System renewed, risk of unauthorised access eliminated.
Published
17 Oct 2025

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 May 2025 GoDaddy Inc.FTC: GoDaddy must set up an information security programme after hosting security gaps USASecurity measures and risk management Order

According to the Federal Trade Commission (FTC, the US consumer protection authority), the web host did not use multi-factor authentication for its hosting services, monitored security threats inadequately and did not secure connections to customer data, yet advertised “award-winning security”. The final order prohibits false statements about security and requires a comprehensive information security programme and regular reviews by independent assessors.

What organisations can take from it

Be able to prove basics such as MFA and threat monitoring before advertising security – otherwise the advertising promise itself becomes the violation.

Relevance to training and awareness

MFA, monitoring and honest security promises

Authority / court
Federal Trade Commission (FTC)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Section 5 FTC Act
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Published
21 May 2025

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 May 2024 a Dutch telecommunications providerNetherlands: 2.25 million EUR against a telecommunications provider over inadequately secured interception system NetherlandsCritical infrastructureanonymised €2.25m

According to the Dutch Authority for Digital Infrastructure (RDI), a Dutch telecommunications provider did not take the necessary measures from October 2021 to December 2022 to protect data from lawful interception of telecommunications against unauthorised persons: the security plan was inadequate, staff with access had not been sufficiently screened (missing job descriptions, confidentiality declarations, certificates of conduct), and logical and physical access controls were deficient. No actual unauthorised access was found; the fine amounts to 2.25 million EUR.

What organisations can take from it

Treat interfaces for access by authorities as high-risk systems; document access controls and staff screening completely.

Relevance to training and awareness

Access control and staff screening for interception interfaces

Authority / court
Rijksinspectie Digitale Infrastructuur (RDI)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Telecommunicatiewet Art. 15.4; Besluit beveiliging gegevens telecommunicatie (Bbgt) Art. 2, 3, 4, 8
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Deficiencies remedied after they were identified; no actual unauthorised access found.
Published
22 Oct 2024
Sources

Checked against the official source on 28 Sep 2026 · Version 4 · Company name anonymised since 21 May 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 May 2024 a US data services providerFTC: US data services provider must delete legacy data and strengthen security after hacker attack USASecurity measures and risk managementanonymised Order

According to the complaint of the Federal Trade Commission (FTC, the US consumer protection authority), an attacker exploited weaknesses in the network of the data services provider for companies and non-profit organisations in early 2020 and stole large amounts of unencrypted data, including Social Security and bank account numbers of millions of people; the attack went undetected for three months, the provider informed its customers only after almost two months and misrepresented the extent. The final order requires a comprehensive security programme, a data retention schedule, deletion of data no longer needed and notification of future reportable incidents to the FTC.

What organisations can take from it

Set retention periods and deletion routines as security measures – data that is no longer needed is pure risk in an attack.

Relevance to training and awareness

Data minimisation, encryption and honest incident communication

Authority / court
Federal Trade Commission (FTC)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Section 5 FTC Act
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 May 2024

Checked against the official source on 28 Sep 2026 · Version 3 · Company name anonymised since 20 May 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial