Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

16cases from 5 jurisdictions
€2.5bnTotal of monetary amounts (8 cases with an amount)
€890mLargest single case: Google
€200mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€30.5m
Q3 20240—
Q4 20242—
Q1 20252—
Q2 20254€705m
Q3 20250—
Q4 20253€120m
Q1 20260—
Q2 20262€200m
Q3 20262€1.44bn

16 cases

23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering EU levelPlatform obligations €890m

In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.

What organisations can take from it

Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products EU levelPlatform obligations €550m

AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.

What organisations can take from it

The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked DenmarkPlatform obligations Order

After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.

What organisations can take from it

Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products EU levelPlatform obligations €200m

Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.

What organisations can take from it

Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
28 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository EU levelPlatform obligations €120m

First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.

What organisations can take from it

Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
5 Dec 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository EU levelPlatform obligations Order

Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.

What organisations can take from it

Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Oct 2025 WhatsApp Ireland Limited (Dienst „Channels“) und PinterestWhatsApp (Channels) and Pinterest: designated as ‘exposed to terrorist content’ IrelandPlatform obligations Order

After both hosting services had received at least two final removal orders from EU authorities within twelve months, Coimisiún na Meán (Ireland’s media and online safety regulator) designated them as exposed to terrorist content under the TCO Regulation. They must take specific protective measures and report on them within three months; the regulator assesses their effectiveness.

What organisations can take from it

Repeated removal orders trigger additional, monitored prevention obligations for platforms – content moderation must be prepared for this.

Authority / court
Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2025 AliExpressAliExpress: DSA commitments on illegal products and trader transparency made binding EU levelPlatform obligations Order

The European Commission declared binding commitments by AliExpress relating, among other things, to the detection of illegal products such as medicines and food supplements (including via hidden links and affiliate programmes), the notice and complaint system, the transparency of advertising and recommender systems, the traceability of traders and data access for researchers; an independent monitoring trustee oversees implementation. In parallel, it made a preliminary finding of a breach of the obligation to carry out a risk assessment.

What organisations can take from it

Marketplaces must systematically detect illegal products – including where they are offered via detours such as affiliate links.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Art. 71 Digital Services Act (Verordnung (EU) 2022/2065)
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2025 AppleDMA: 500 million EUR against Apple over anti-steering in the App Store EU levelPlatform obligations €500m

In one of the first non-compliance decisions under the Digital Markets Act (DMA), the European Commission found that Apple prevents app developers from informing customers free of charge about cheaper offers outside the App Store and steering them there. In addition to a fine of 500 million EUR, the removal of the restrictions within 60 days was ordered, failing which periodic penalty payments may be imposed.

What organisations can take from it

Gatekeepers must allow business users to communicate freely with their customers; technical or commercial hurdles are treated as circumvention.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Apr 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2025 MetaDMA: 200 million EUR against Meta over ‘consent or pay’ model EU levelPlatform obligations €200m

Between March and November 2024, Meta offered users of Facebook and Instagram only the choice between consenting to the combination of their data for personalised advertising and a paid subscription. The European Commission saw this as a breach of the obligation under the Digital Markets Act (DMA) to offer an equivalent, less data-intensive alternative, and imposed 200 million EUR.

What organisations can take from it

A binary ‘consent or pay’ is not sufficient where the law requires an equivalent option involving less data processing.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Einwilligung zur Datenzusammenführung
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
23 Apr 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Apr 2025 Luka Inc.Garante: 5 million EUR against Replika operator Luka over lack of legal basis ItalyAI systems €5m

The US operator of the Replika chatbot had not determined a legal basis for the processing, had an inadequate privacy notice and, despite declaring that minors were excluded, had no age verification. Italy's data protection authority (Garante per la protezione dei dati personali) imposed 5 million EUR and opened further proceedings concerning the training of the underlying language model.

What organisations can take from it

A declared exclusion of minors is worthless without effective age verification at registration and during use.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO (Rechtmäßigkeit, Transparenz, Schutz Minderjähriger)
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Published
19 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2025 AppleApple: Commission sets out specific interoperability obligations for iOS by DMA decision EU levelPlatform obligations Order

In two specification decisions under the Digital Markets Act, the European Commission set out which interoperability measures Apple must take: access for manufacturers of connected devices to nine iOS features (such as notifications on smartwatches, peer-to-peer Wi-Fi, NFC, pairing) and a more transparent and faster procedure for developers’ interoperability requests.

What organisations can take from it

Gatekeepers must actively open interfaces – anyone handling third-party requests sluggishly risks detailed regulatory requirements.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Markets Act (Verordnung (EU) 2022/1925): Interoperabilitätspflicht, Spezifizierungsbeschlüsse
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jan 2025 Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; Beijing DeepSeek Artificial Intelligence Co., Ltd.Garante blocks DeepSeek: immediate limitation of processing for Italian users ItalyAI systems Order

After the Chinese providers had declared that they did not operate in Italy and were not subject to the GDPR, Italy's data protection authority (Garante per la protezione dei dati personali) ordered, as a matter of urgency and with immediate effect, the limitation of the processing of Italian users' data and opened an investigation.

What organisations can take from it

Companies that offer AI services to European users are subject to the GDPR – regardless of where they are headquartered.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO, Art. 58 Abs. 2 lit. f (Beschränkung der Verarbeitung)
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
30 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Nov 2024 TikTok, X und Meta (Instagram)TikTok, X and Instagram: Irish regulator requires measures against terrorist content IrelandPlatform obligations Order

Coimisiún na Meán (Ireland’s media and online safety regulator) determined that the services of TikTok, X and Meta (Instagram) are exposed to terrorist content after they had received at least two final removal orders from EU authorities within twelve months. The providers must take specific measures against the dissemination of terrorist content and report on them.

What organisations can take from it

Platforms should record removal orders centrally – from the second within twelve months, additional obligations monitored by the regulator loom.

Authority / court
Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Nov 2024 OpenAIGarante: 15 million EUR against OpenAI over ChatGPT – later annulled by the court ItalyAI systems overturned

Italy's data protection authority (Garante per la protezione dei dati personali) imposed 15 million EUR because OpenAI trained ChatGPT with user data without an appropriate legal basis, breached transparency obligations, failed to report a data breach from March 2023 and did not provide for age verification; in addition, a six-month information campaign was ordered. The Rome Court (Tribunale di Roma) upheld OpenAI's action in judgment no. 4153/2026 (published on 18 March 2026); the Garante subsequently removed the decision from its website.

What organisations can take from it

Companies that train AI models with personal data need a documented legal basis and age verification in advance.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO (Rechtsgrundlage, Transparenz, Meldung von Datenpannen, Schutz Minderjähriger)
Action
Fine
Status of proceedings
overturned
Sector
Telecoms, IT and software
Published
20 Dec 2024

Amount in EUR; no ECB reference rate is available for this currency.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 May 2024 Clearview AI Inc.Dutch AP: 30.5 million EUR against Clearview AI over facial database NetherlandsAI systems €30.5m

Clearview processes biometric data of people in the Netherlands without a legal basis for a facial recognition database compiled from the internet, did not inform data subjects, did not respond to access requests and did not designate an EU representative. In addition to a fine of 30.5 million EUR, the Dutch data protection authority (Autoriteit Persoonsgegevens, AP) imposed four orders subject to penalty payments.

What organisations can take from it

Publicly accessible photos are no licence for biometric analysis – users of such services risk fines of their own.

Authority / court
Autoriteit Persoonsgegevens
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, 6 Abs. 1, 9 Abs. 1, 12, 14, 15, 27
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
3 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial