Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
€3.77mTotal of monetary amounts
€2.25mLargest single case: a Dutch telecommunications provider
€1.88mMedian per case with an amount

Click a bar to drill down one level.

Where?

by country
  1. Netherlands €3.77m 100 % · 2 cases

What for?

by topic
  1. Critical infrastructure €3.77m 100 % · 2 cases

Who?

by company
  1. Anonymised companies €2.25m 60 % · 1 case
  2. Odido Netherlands B.V. €1.52m 40 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€2.25m
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20251€1.52m
Q1 20260—
Q2 20260—
Q3 20260—

2 cases

17 Oct 2025 Odido Netherlands B.V.Netherlands: 1.52 million EUR against Odido – interception system without security plan and staff screening NetherlandsCritical infrastructure €1.52m

In inspections in 2021/22, the RDI (Rijksinspectie Digitale Infrastructuur, the Dutch Authority for Digital Infrastructure) found that the mobile operator had no mandatory security plan for its system for lawful interception of telecommunications, that employees with access had not been adequately screened (missing job descriptions, confidentiality declarations, certificates of conduct), that unauthorised persons had access to interception data and that suppliers could access the system digitally. The RDI imposed 1,518,750 EUR; Odido has since renewed the system.

What organisations can take from it

Treat the security plan, staff screening and strictly limited supplier access for highly sensitive systems as the core of the obligation, not a formality.

Relevance to training and awareness

Access rights, staff screening and supplier access for sensitive systems

Authority / court
Rijksinspectie Digitale Infrastructuur (RDI)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Telecommunicatiewet Art. 15.4; Besluit beveiliging gegevens telecommunicatie (Bbgt) Art. 2, 3, 4
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
System renewed, risk of unauthorised access eliminated.
Published
17 Oct 2025

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 May 2024 a Dutch telecommunications providerNetherlands: 2.25 million EUR against a telecommunications provider over inadequately secured interception system NetherlandsCritical infrastructureanonymised €2.25m

According to the Dutch Authority for Digital Infrastructure (RDI), a Dutch telecommunications provider did not take the necessary measures from October 2021 to December 2022 to protect data from lawful interception of telecommunications against unauthorised persons: the security plan was inadequate, staff with access had not been sufficiently screened (missing job descriptions, confidentiality declarations, certificates of conduct), and logical and physical access controls were deficient. No actual unauthorised access was found; the fine amounts to 2.25 million EUR.

What organisations can take from it

Treat interfaces for access by authorities as high-risk systems; document access controls and staff screening completely.

Relevance to training and awareness

Access control and staff screening for interception interfaces

Authority / court
Rijksinspectie Digitale Infrastructuur (RDI)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Telecommunicatiewet Art. 15.4; Besluit beveiliging gegevens telecommunicatie (Bbgt) Art. 2, 3, 4, 8
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Deficiencies remedied after they were identified; no actual unauthorised access found.
Published
22 Oct 2024
Sources

Checked against the official source on 28 Sep 2026 · Version 4 · Company name anonymised since 21 May 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial