Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine 5 cases 71 % · €35.9m
- Order 2 cases 29 % ·
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | — |
| Q1 2024 | 2 | €367,242 |
| Q2 2024 | 1 | €30.5m |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | — |
| Q1 2025 | 1 | — |
| Q2 2025 | 1 | €5m |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
7 cases
10 Apr 2025 Luka Inc.Garante: 5 million EUR against Replika operator Luka over lack of legal basis €5m
The US operator of the Replika chatbot had not determined a legal basis for the processing, had an inadequate privacy notice and, despite declaring that minors were excluded, had no age verification. Italy's data protection authority (Garante per la protezione dei dati personali) imposed 5 million EUR and opened further proceedings concerning the training of the underlying language model.
A declared exclusion of minors is worthless without effective age verification at registration and during use.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO (Rechtmäßigkeit, Transparenz, Schutz Minderjähriger)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
- Published
- 19 May 2025
- AI: Il Garante sanziona la società che gestisce il chatbot “Replika” Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jan 2025 Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; Beijing DeepSeek Artificial Intelligence Co., Ltd.Garante blocks DeepSeek: immediate limitation of processing for Italian users Order
After the Chinese providers had declared that they did not operate in Italy and were not subject to the GDPR, Italy's data protection authority (Garante per la protezione dei dati personali) ordered, as a matter of urgency and with immediate effect, the limitation of the processing of Italian users' data and opened an investigation.
Companies that offer AI services to European users are subject to the GDPR – regardless of where they are headquartered.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO, Art. 58 Abs. 2 lit. f (Beschränkung der Verarbeitung)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 30 Jan 2025
- Intelligenza artificiale: il Garante privacy blocca DeepSeek Press release of an authority
- Garante, Provvedimento del 30 gennaio 2025 [10098477] (DeepSeek) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Nov 2024 OpenAIGarante: 15 million EUR against OpenAI over ChatGPT – later annulled by the court overturned
Italy's data protection authority (Garante per la protezione dei dati personali) imposed 15 million EUR because OpenAI trained ChatGPT with user data without an appropriate legal basis, breached transparency obligations, failed to report a data breach from March 2023 and did not provide for age verification; in addition, a six-month information campaign was ordered. The Rome Court (Tribunale di Roma) upheld OpenAI's action in judgment no. 4153/2026 (published on 18 March 2026); the Garante subsequently removed the decision from its website.
Companies that train AI models with personal data need a documented legal basis and age verification in advance.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO (Rechtsgrundlage, Transparenz, Meldung von Datenpannen, Schutz Minderjähriger)
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Telecoms, IT and software
- Published
- 20 Dec 2024
Amount in EUR; no ECB reference rate is available for this currency.
- ChatGPT, il Garante privacy chiude l’istruttoria Press release of an authority
- OpenAI, annullata la sanzione del Garante privacy Additional reference (not official)
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 May 2024 Clearview AI Inc.Dutch AP: 30.5 million EUR against Clearview AI over facial database €30.5m
Clearview processes biometric data of people in the Netherlands without a legal basis for a facial recognition database compiled from the internet, did not inform data subjects, did not respond to access requests and did not designate an EU representative. In addition to a fine of 30.5 million EUR, the Dutch data protection authority (Autoriteit Persoonsgegevens, AP) imposed four orders subject to penalty payments.
Publicly accessible photos are no licence for biometric analysis – users of such services risk fines of their own.
- Authority / court
- Autoriteit Persoonsgegevens
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, 6 Abs. 1, 9 Abs. 1, 12, 14, 15, 27
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 3 Sep 2024
- Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection for facial recognition Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Mar 2024 Delphia (USA) Inc.SEC ‘AI washing’: Delphia pays 225,000 US dollars for fabricated AI use €206,574
From 2019 to 2023, the investment adviser claimed to use AI and machine learning to analyse client data for investment decisions but did not have these capabilities. In a settlement with the U.S. Securities and Exchange Commission (SEC) (without admission), Delphia paid 225,000 US dollars.
Statements about the use of AI in marketing and investor information must be technically verifiable.
Permissible advertising claims about AI capabilities
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- Investment Advisers Act of 1940; Marketing Rule
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 18 Mar 2024
Original amount 225,000 USD, converted at the ECB reference rate of 18 Mar 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Mar 2024 Global Predictions Inc.SEC ‘AI washing’: Global Predictions pays 175,000 US dollars for AI advertising promises €160,668
In 2023, the investment adviser falsely advertised itself as the ‘first regulated AI financial advisor’ offering AI-driven expert forecasts, misrepresented tax-loss harvesting and used impermissible liability clauses. In a settlement with the U.S. Securities and Exchange Commission (SEC), the company paid 175,000 US dollars.
Superlatives such as ‘first AI adviser’ are statements of fact and must be checked before publication.
Permissible advertising claims about AI capabilities
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- Investment Advisers Act of 1940; Marketing Rule
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 18 Mar 2024
Original amount 175,000 USD, converted at the ECB reference rate of 18 Mar 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Dec 2023 Rite Aid CorporationFTC: five-year ban on AI facial recognition for Rite Aid after false alerts Order
According to the U.S. Federal Trade Commission (FTC), the pharmacy chain used AI facial recognition in hundreds of stores from 2012 to 2020, which falsely flagged customers – particularly women and people of colour – as shoplifters; accuracy was neither tested in advance nor monitored, and employees were not adequately trained. Under the proposed settlement order (subject to approval by the bankruptcy court and the federal court), Rite Aid may not use the technology for surveillance for five years and must delete images and algorithms developed from them; in addition, the FTC alleges a violation of its 2010 data security order.
AI systems with consequences for people need testing for error rates, ongoing monitoring and trained staff who critically review matches.
Training on handling AI matches and false alerts
Missing or inadequate training played a role in the decision.
- Authority / court
- Federal Trade Commission
- Area of law
- AI and digital regulation · AI systems
- Legal basis
- FTC Act Section 5; Verstoß gegen FTC-Datensicherheitsanordnung von 2010
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 19 Dec 2023
Checked against the official source on 25 Sep 2026 · Direct link