Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
—Total of monetary amounts (0 cases with an amount)
—Largest single case
—Median per case with an amount

Click a bar to drill down one level.

Where?

by region

All jurisdictions

  1. USA — 0 % · 2 cases

What for?

by action
  1. Order — 0 % · 2 cases

Who?

by company
  1. Anonymised companies — 0 % · 1 case
  2. GoDaddy Inc. — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20251—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20260—

2 cases

21 May 2025 GoDaddy Inc.FTC: GoDaddy must set up an information security programme after hosting security gaps USASecurity measures and risk management Order

According to the Federal Trade Commission (FTC, the US consumer protection authority), the web host did not use multi-factor authentication for its hosting services, monitored security threats inadequately and did not secure connections to customer data, yet advertised “award-winning security”. The final order prohibits false statements about security and requires a comprehensive information security programme and regular reviews by independent assessors.

What organisations can take from it

Be able to prove basics such as MFA and threat monitoring before advertising security – otherwise the advertising promise itself becomes the violation.

Relevance to training and awareness

MFA, monitoring and honest security promises

Authority / court
Federal Trade Commission (FTC)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Section 5 FTC Act
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Published
21 May 2025

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 May 2024 a US data services providerFTC: US data services provider must delete legacy data and strengthen security after hacker attack USASecurity measures and risk managementanonymised Order

According to the complaint of the Federal Trade Commission (FTC, the US consumer protection authority), an attacker exploited weaknesses in the network of the data services provider for companies and non-profit organisations in early 2020 and stole large amounts of unencrypted data, including Social Security and bank account numbers of millions of people; the attack went undetected for three months, the provider informed its customers only after almost two months and misrepresented the extent. The final order requires a comprehensive security programme, a data retention schedule, deletion of data no longer needed and notification of future reportable incidents to the FTC.

What organisations can take from it

Set retention periods and deletion routines as security measures – data that is no longer needed is pure risk in an attack.

Relevance to training and awareness

Data minimisation, encryption and honest incident communication

Authority / court
Federal Trade Commission (FTC)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Section 5 FTC Act
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 May 2024

Checked against the official source on 28 Sep 2026 · Version 3 · Company name anonymised since 20 May 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial