Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 2 | €936,521 |
| Q1 2024 | 2 | €354,397 |
| Q2 2024 | 1 | €9.23m |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €789,284 |
| Q1 2025 | 2 | €12.9m |
| Q2 2025 | 0 | — |
| Q3 2025 | 4 | €1.79m |
| Q4 2025 | 3 | €4.35m |
| Q1 2026 | 0 | — |
| Q2 2026 | 2 | €1.92m |
| Q3 2026 | 2 | €717,989 |
19 cases
22 Sep 2026 OTC Link LLCOTC Link: 575,000 USD – security policies never completed despite examination findings €501,614
From 2016 to 2025, the operator of the OTC Link ATS trading system lacked complete policies on systems security, access control and vulnerability management as required under Regulation SCI. Although the examiners of the U.S. Securities and Exchange Commission (SEC) had criticised the gaps in several examinations, drafts remained unfinished; the SEC issued a censure and imposed 575,000 USD.
Track supervisory examination findings with a deadline and a responsible person – points that remain open repeatedly become expensive.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Regulation SCI, Rule 1001(a)(1)–(3)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
Original amount 575,000 USD, converted at the ECB reference rate of 22 Sep 2026.
- SEC Censures OTC Link LLC for Repeated Compliance Failures Related to Regulation SCI (22.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies €216,375
The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.
Even small financial service providers must keep documented patch policies and regular risk assessments.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
- Published
- 5 Aug 2026
Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification €1.92m
In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.
Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 30 Apr 2026
Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.
- DFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental Press release of an authority
- Consent Order to Delta Dental 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified €1,135
Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.
Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.
Recognising misdirected mail as a data breach – including at service providers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.
- UODO, Decyzja DKN.5131.16.2025 vom 07.04.2026 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified €4,938
In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.
Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.
Checking postal mailings; notifying data breaches involving identification numbers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.
- UODO, Decyzja DKN.5131.17.2024 vom 23.10.2025 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools €2.4m
Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.
Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 14 Oct 2025
Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- DFS Secures More than $19 Million from Auto Insurance Companies over Data Breaches Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers Reprimand or warning
After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).
Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.
Security testing for software releases of interfaces
- Authority / court
- Banka Slovenije
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Liability of senior managers
- Reprimand also issued to the responsible Director of IT Development (Dejan Pust).
- Razkritje informacij o izrečeni sankciji pravni in odgovorni osebi – Nova Ljubljanska banka d. d. Decision of an authority
- Banka Slovenije – Informacije o izrečenih ukrepih Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam €870
Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.
External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.
Recognising and escalating alerts about security gaps
Missing or inadequate training played a role in the decision.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- negligent
- Mitigating circumstances
- No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.
- DSB, Straferkenntnis GZ 2025-0.699.550 vom 04.09.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert €80,000
A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.
Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.
Identity verification for customer requests by e-mail (social engineering)
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.
- Garante privacy, Provvedimento del 10 luglio 2025 [10154110] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2025 The London Metal Exchange (LME)London Metal Exchange: 9.2 million GBP – controls and escalation failed in nickel turmoil €11m
When the nickel price rose to over 100,000 USD within just over an hour on 8 March 2022, only junior staff were on duty during Asian trading hours, and they had not been trained to recognise a disorderly market; they did not escalate and even switched off price bands. The Financial Conduct Authority (FCA) imposed a fine on the recognised investment exchange for the first time: 9.2 million GBP after a 30% discount.
Critical infrastructure needs trained staff around the clock and clear escalation paths – including at night and at off-peak times.
Escalation of unusual market conditions; training of shift staff
Missing or inadequate training played a role in the decision.
- Authority / court
- Financial Conduct Authority (FCA)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- FCA REC 2.5.1 (Recognition Requirements); Art. 18 RTS 7 (MiFID II)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Early settlement (30% discount); improvements since March 2022.
Original amount 9,200,000 GBP, converted at the ECB reference rate of 20 Mar 2025.
- FCA: First FCA enforcement action and fine against Recognised Investment Exchange (20.03.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA €1.92m
When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.
Anyone changing data flows must know the security processes – training development teams is part of cyber defence.
Secure software development and change processes
Missing or inadequate training played a role in the decision.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- PayPal has since remedied the deficiencies.
- Published
- 23 Jan 2025
Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.
- DFS-Pressemitteilung vom 23.01.2025: Cybersecurity-Vergleich mit PayPal, Inc. (2 Mio. $) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Tradition SEF LLCTradition SEF: 875,000 USD – emergency and security tests not brought before the board €789,284
The swap trading platform did not fully inform its board of the results of emergency, technology risk and penetration tests, did not regularly test its business continuity and disaster recovery capabilities and had no adequate risk management. It also failed to produce documents requested during an examination on time despite extensions of deadlines; the Commodity Futures Trading Commission (CFTC) imposed 875,000 USD.
Contingency plans only count if they are tested regularly and the results are noted by the entire governing body.
- Authority / court
- Commodity Futures Trading Commission (CFTC)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Commodity Exchange Act; CFTC-Regeln zu System Safeguards für Swap Execution Facilities
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
Original amount 875,000 USD, converted at the ECB reference rate of 1 Oct 2024.
- CFTC Orders Tradition SEF LLC to Pay $875,000 for System Safeguards Violations … (01.10.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC €9.23m
In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.
Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.
Internal escalation of cyber incidents to compliance
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported €336,066
A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.
Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.
Risk assessment and notification of data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 2 Apr 2024
Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.59.2022 vom 12.03.2024 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years €18,331
The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.
Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.
Recognising misdirected mail and reporting it internally
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 2 Apr 2024
Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.28.2023 vom 12.03.2024 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2023 First American Title Insurance CompanyNYDFS: $1 million against First American over open document links €913,159
The EaglePro application generated links to transaction documents without login and without an expiry date; according to a journalist, by changing the sequential document number, 885 million documents containing, among other things, social security and bank data could be retrieved. Users were told not to send sensitive data, but there were no technical barriers. The penalty was imposed by the New York State Department of Financial Services (NYDFS).
Instructions to users do not replace technical controls – sharing links need authentication and an expiry date.
Classification and sending of sensitive documents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR §§ 500.3, 500.7 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 1,000,000 USD, converted at the ECB reference rate of 27 Nov 2023.
- Consent Order to First American Title Insurance Company Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator €23,362
The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.
Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.
Avoiding misdirected e-mails; reporting data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- intentional
- Repeat case
- yes
- Published
- 23 Nov 2023
Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.
- UODO: Kolejna administracyjna kara pieniężna za niezgłoszenie naruszenia ochrony danych osobowych (23.11.2023) Press release of an authority
- UODO, Decyzja DKN.5131.55.2022 vom 18.10.2023 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link