Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by levelWhat for?
by topicWho?
by company- Anonymised companies — 0 % · 1 case
- GoDaddy Inc. — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
2 cases
21 May 2025 GoDaddy Inc.FTC: GoDaddy must set up an information security programme after hosting security gaps Order
According to the Federal Trade Commission (FTC, the US consumer protection authority), the web host did not use multi-factor authentication for its hosting services, monitored security threats inadequately and did not secure connections to customer data, yet advertised “award-winning security”. The final order prohibits false statements about security and requires a comprehensive information security programme and regular reviews by independent assessors.
Be able to prove basics such as MFA and threat monitoring before advertising security – otherwise the advertising promise itself becomes the violation.
MFA, monitoring and honest security promises
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Section 5 FTC Act
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 21 May 2025
- FTC Finalizes Order with GoDaddy over Data Security Failures Press release of an authority
- FTC Takes Action Against GoDaddy for Alleged Lax Data Security for Its Website Hosting Services Press release of an authority
Checked against the official source on 28 Sep 2026 · Direct link
Report an error
20 May 2024 a US data services providerFTC: US data services provider must delete legacy data and strengthen security after hacker attack Order
According to the complaint of the Federal Trade Commission (FTC, the US consumer protection authority), an attacker exploited weaknesses in the network of the data services provider for companies and non-profit organisations in early 2020 and stole large amounts of unencrypted data, including Social Security and bank account numbers of millions of people; the attack went undetected for three months, the provider informed its customers only after almost two months and misrepresented the extent. The final order requires a comprehensive security programme, a data retention schedule, deletion of data no longer needed and notification of future reportable incidents to the FTC.
Set retention periods and deletion routines as security measures – data that is no longer needed is pure risk in an attack.
Data minimisation, encryption and honest incident communication
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Section 5 FTC Act
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 20 May 2024
- FTC, Pressemitteilungen (Übersicht) (Entscheidung 2024) Press release of an authority
Checked against the official source on 28 Sep 2026 · Version 3 · Company name anonymised since 20 May 2026 · Direct link