Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | €30.5m |
| Q3 2024 | 0 | — |
| Q4 2024 | 2 | — |
| Q1 2025 | 2 | — |
| Q2 2025 | 4 | €705m |
| Q3 2025 | 0 | — |
| Q4 2025 | 3 | €120m |
| Q1 2026 | 0 | — |
| Q2 2026 | 2 | €200m |
| Q3 2026 | 2 | €1.44bn |
16 cases
23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering €890m
In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.
Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Jul 2026
- Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
- IP/26/1670: Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products €550m
AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.
The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
- Published
- 20 Jul 2026
- Commission fines AliExpress €550 million for breaching the Digital Services Act Press release of an authority
- IP/26/1654: Commission fines AliExpress €550 million for breaching the Digital Services Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked Order
After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.
Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.
- Authority / court
- Konkurrencerådet (Danish Competition Council)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 24 Jun 2026
- KFST – The Competition Council rules against Meta (24.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products €200m
Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.
Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 28 May 2026
- Commission fines Temu €200 million for breaching the Digital Services Act Press release of an authority
- IP/26/1178 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository €120m
First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.
Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 5 Dec 2025
- Commission fines X €120 million under the Digital Services Act Press release of an authority
- IP/25/2934 (Druckfassung) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository Order
Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.
Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
- Action
- Order
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Oct 2025 WhatsApp Ireland Limited (Dienst „Channels“) und PinterestWhatsApp (Channels) and Pinterest: designated as ‘exposed to terrorist content’ Order
After both hosting services had received at least two final removal orders from EU authorities within twelve months, Coimisiún na Meán (Ireland’s media and online safety regulator) designated them as exposed to terrorist content under the TCO Regulation. They must take specific protective measures and report on them within three months; the regulator assesses their effectiveness.
Repeated removal orders trigger additional, monitored prevention obligations for platforms – content moderation must be prepared for this.
- Authority / court
- Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Coimisiún na Meán: Further determinations made under Terrorist Content Online Regulation (TCOR) (17.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2025 AliExpressAliExpress: DSA commitments on illegal products and trader transparency made binding Order
The European Commission declared binding commitments by AliExpress relating, among other things, to the detection of illegal products such as medicines and food supplements (including via hidden links and affiliate programmes), the notice and complaint system, the transparency of advertising and recommender systems, the traceability of traders and data access for researchers; an independent monitoring trustee oversees implementation. In parallel, it made a preliminary finding of a breach of the obligation to carry out a risk assessment.
Marketplaces must systematically detect illegal products – including where they are offered via detours such as affiliate links.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Art. 71 Digital Services Act (Verordnung (EU) 2022/2065)
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Apr 2025 AppleDMA: 500 million EUR against Apple over anti-steering in the App Store €500m
In one of the first non-compliance decisions under the Digital Markets Act (DMA), the European Commission found that Apple prevents app developers from informing customers free of charge about cheaper offers outside the App Store and steering them there. In addition to a fine of 500 million EUR, the removal of the restrictions within 60 days was ordered, failing which periodic penalty payments may be imposed.
Gatekeepers must allow business users to communicate freely with their customers; technical or commercial hurdles are treated as circumvention.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Apr 2025
- Commission finds Apple and Meta in breach of the Digital Markets Act Press release of an authority
- IP/25/1085 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Apr 2025 MetaDMA: 200 million EUR against Meta over ‘consent or pay’ model €200m
Between March and November 2024, Meta offered users of Facebook and Instagram only the choice between consenting to the combination of their data for personalised advertising and a paid subscription. The European Commission saw this as a breach of the obligation under the Digital Markets Act (DMA) to offer an equivalent, less data-intensive alternative, and imposed 200 million EUR.
A binary ‘consent or pay’ is not sufficient where the law requires an equivalent option involving less data processing.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Einwilligung zur Datenzusammenführung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 23 Apr 2025
- Commission finds Apple and Meta in breach of the Digital Markets Act Press release of an authority
- IP/25/1085 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Apr 2025 Luka Inc.Garante: 5 million EUR against Replika operator Luka over lack of legal basis €5m
The US operator of the Replika chatbot had not determined a legal basis for the processing, had an inadequate privacy notice and, despite declaring that minors were excluded, had no age verification. Italy's data protection authority (Garante per la protezione dei dati personali) imposed 5 million EUR and opened further proceedings concerning the training of the underlying language model.
A declared exclusion of minors is worthless without effective age verification at registration and during use.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO (Rechtmäßigkeit, Transparenz, Schutz Minderjähriger)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
- Published
- 19 May 2025
- AI: Il Garante sanziona la società che gestisce il chatbot “Replika” Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Mar 2025 AppleApple: Commission sets out specific interoperability obligations for iOS by DMA decision Order
In two specification decisions under the Digital Markets Act, the European Commission set out which interoperability measures Apple must take: access for manufacturers of connected devices to nine iOS features (such as notifications on smartwatches, peer-to-peer Wi-Fi, NFC, pairing) and a more transparent and faster procedure for developers’ interoperability requests.
Gatekeepers must actively open interfaces – anyone handling third-party requests sluggishly risks detailed regulatory requirements.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Digital Markets Act (Verordnung (EU) 2022/1925): Interoperabilitätspflicht, Spezifizierungsbeschlüsse
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jan 2025 Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; Beijing DeepSeek Artificial Intelligence Co., Ltd.Garante blocks DeepSeek: immediate limitation of processing for Italian users Order
After the Chinese providers had declared that they did not operate in Italy and were not subject to the GDPR, Italy's data protection authority (Garante per la protezione dei dati personali) ordered, as a matter of urgency and with immediate effect, the limitation of the processing of Italian users' data and opened an investigation.
Companies that offer AI services to European users are subject to the GDPR – regardless of where they are headquartered.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO, Art. 58 Abs. 2 lit. f (Beschränkung der Verarbeitung)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 30 Jan 2025
- Intelligenza artificiale: il Garante privacy blocca DeepSeek Press release of an authority
- Garante, Provvedimento del 30 gennaio 2025 [10098477] (DeepSeek) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 TikTok, X und Meta (Instagram)TikTok, X and Instagram: Irish regulator requires measures against terrorist content Order
Coimisiún na Meán (Ireland’s media and online safety regulator) determined that the services of TikTok, X and Meta (Instagram) are exposed to terrorist content after they had received at least two final removal orders from EU authorities within twelve months. The providers must take specific measures against the dissemination of terrorist content and report on them.
Platforms should record removal orders centrally – from the second within twelve months, additional obligations monitored by the regulator loom.
- Authority / court
- Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Coimisiún na Meán: Determination made under Terrorist Content Online Regulation (TCOR) (13.11.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Nov 2024 OpenAIGarante: 15 million EUR against OpenAI over ChatGPT – later annulled by the court overturned
Italy's data protection authority (Garante per la protezione dei dati personali) imposed 15 million EUR because OpenAI trained ChatGPT with user data without an appropriate legal basis, breached transparency obligations, failed to report a data breach from March 2023 and did not provide for age verification; in addition, a six-month information campaign was ordered. The Rome Court (Tribunale di Roma) upheld OpenAI's action in judgment no. 4153/2026 (published on 18 March 2026); the Garante subsequently removed the decision from its website.
Companies that train AI models with personal data need a documented legal basis and age verification in advance.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO (Rechtsgrundlage, Transparenz, Meldung von Datenpannen, Schutz Minderjähriger)
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Telecoms, IT and software
- Published
- 20 Dec 2024
Amount in EUR; no ECB reference rate is available for this currency.
- ChatGPT, il Garante privacy chiude l’istruttoria Press release of an authority
- OpenAI, annullata la sanzione del Garante privacy Additional reference (not official)
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 May 2024 Clearview AI Inc.Dutch AP: 30.5 million EUR against Clearview AI over facial database €30.5m
Clearview processes biometric data of people in the Netherlands without a legal basis for a facial recognition database compiled from the internet, did not inform data subjects, did not respond to access requests and did not designate an EU representative. In addition to a fine of 30.5 million EUR, the Dutch data protection authority (Autoriteit Persoonsgegevens, AP) imposed four orders subject to penalty payments.
Publicly accessible photos are no licence for biometric analysis – users of such services risk fines of their own.
- Authority / court
- Autoriteit Persoonsgegevens
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, 6 Abs. 1, 9 Abs. 1, 12, 14, 15, 27
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 3 Sep 2024
- Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection for facial recognition Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link