Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

8cases from 4 jurisdictions
€464,702Total of monetary amounts (7 cases with an amount)
€336,066Largest single case: Santander Bank Polska S.A.
€18,331Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€23,362
Q1 20242€354,397
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20253€80,870
Q4 20251€4,938
Q1 20260—
Q2 20261€1,135
Q3 20260—

8 cases

12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported PolandIncident reporting obligations €336,066

A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.

What organisations can take from it

Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.

Relevance to training and awareness

Risk assessment and notification of data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Repeat case
yes
Published
2 Apr 2024

Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified PolandIncident reporting obligations €1,135

Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.

What organisations can take from it

Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.

Relevance to training and awareness

Recognising misdirected mail as a data breach – including at service providers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Construction and real estate

Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified PolandIncident reporting obligations €4,938

In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.

What organisations can take from it

Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.

Relevance to training and awareness

Checking postal mailings; notifying data breaches involving identification numbers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers SloveniaSecurity measures and risk management Reprimand or warning

After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).

What organisations can take from it

Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.

Relevance to training and awareness

Security testing for software releases of interfaces

Authority / court
Banka Slovenije
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance
Liability of senior managers
Reprimand also issued to the responsible Director of IT Development (Dejan Pust).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam AustriaIncident reporting obligations €870

Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.

What organisations can take from it

External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.

Relevance to training and awareness

Recognising and escalating alerts about security gaps

Missing or inadequate training played a role in the decision.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert ItalyIncident reporting obligations €80,000

A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.

What organisations can take from it

Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.

Relevance to training and awareness

Identity verification for customer requests by e-mail (social engineering)

Authority / court
Garante per la protezione dei dati personali
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years PolandIncident reporting obligations €18,331

The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.

What organisations can take from it

Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.

Relevance to training and awareness

Recognising misdirected mail and reporting it internally

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
2 Apr 2024

Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator PolandIncident reporting obligations €23,362

The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.

What organisations can take from it

Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.

Relevance to training and awareness

Avoiding misdirected e-mails; reporting data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
intentional
Repeat case
yes
Published
23 Nov 2023

Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial