Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €13.4m 100 % · 10 cases
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €23,362 |
| Q1 2024 | 2 | €354,397 |
| Q2 2024 | 1 | €9.23m |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 3 | €1.79m |
| Q4 2025 | 2 | €1.95m |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €1,135 |
| Q3 2026 | 0 | — |
10 cases
22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC €9.23m
In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.
Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.
Internal escalation of cyber incidents to compliance
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified €1,135
Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.
Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.
Recognising misdirected mail as a data breach – including at service providers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.
- UODO, Decyzja DKN.5131.16.2025 vom 07.04.2026 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified €4,938
In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.
Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.
Checking postal mailings; notifying data breaches involving identification numbers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.
- UODO, Decyzja DKN.5131.17.2024 vom 23.10.2025 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam €870
Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.
External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.
Recognising and escalating alerts about security gaps
Missing or inadequate training played a role in the decision.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- negligent
- Mitigating circumstances
- No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.
- DSB, Straferkenntnis GZ 2025-0.699.550 vom 04.09.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert €80,000
A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.
Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.
Identity verification for customer requests by e-mail (social engineering)
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.
- Garante privacy, Provvedimento del 10 luglio 2025 [10154110] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported €336,066
A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.
Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.
Risk assessment and notification of data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 2 Apr 2024
Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.59.2022 vom 12.03.2024 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years €18,331
The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.
Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.
Recognising misdirected mail and reporting it internally
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 2 Apr 2024
Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.28.2023 vom 12.03.2024 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator €23,362
The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.
Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.
Avoiding misdirected e-mails; reporting data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- intentional
- Repeat case
- yes
- Published
- 23 Nov 2023
Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.
- UODO: Kolejna administracyjna kara pieniężna za niezgłoszenie naruszenia ochrony danych osobowych (23.11.2023) Press release of an authority
- UODO, Decyzja DKN.5131.55.2022 vom 18.10.2023 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link