Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium) €3.62m 79 % · 3 cases
- Finanssivalvonta (FIN-FSA) €970,000 21 % · 3 cases
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €950,000 |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €500,000 |
| Q3 2025 | 1 | €1.8m |
| Q4 2025 | 1 | €865,000 |
| Q1 2026 | 1 | €70,000 |
| Q2 2026 | 1 | €400,000 |
| Q3 2026 | 0 | — |
6 cases
13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists €400,000
The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.
Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.
Insider lists and handling of inside information
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Market abuse and insider dealing
- Legal basis
- Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
- Published
- 15 May 2026
- Finanssivalvonta – Oma Säästöpankki Oyj:lle 400 000 euron yhteinen seuraamusmaksu (15.5.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2026/227 vom 13.05.2026 (Oma Säästöpankki Oyj) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions €70,000
Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.
Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.
Regulatory reporting
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Admission of the failures / cooperation.
- Published
- 25 Mar 2026
- Finanssivalvonta – Familiam Asset Management Oy:lle 70 000 euron yhteinen seuraamusmaksu (25.3.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2025/1838 vom 25.03.2026 (Familiam Asset Management Oy) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login €865,000
Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.
Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 28 Oct 2025
- Finlex – Tietosuojavaltuutettu 23.10.2025 (pankin tunnistamispalvelun muutosprosessi) Decision of an authority
- Tietosuojavaltuutettu – Aktialle seuraamusmaksu tietoturvapuutteista vahvan sähköisen tunnistamisen palvelussa (28.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service €1.8m
After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.
Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
- Published
- 10 Sep 2025
- Finlex – Tietosuojavaltuutettu 8.9.2025, TSV/3606/2024 (pankin tunnistuspalvelu) Decision of an authority
- Tietosuojavaltuutettu – S-Pankille seuraamusmaksu S-mobiilin tietoturvahaavoittuvuudesta (10.09.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jun 2025 LocalBitcoins OyLocalBitcoins: 500,000 EUR for failing to identify customers when opening accounts €500,000
During an inspection in 2024, the Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) found that the crypto trading platform had not identified and verified its customers when establishing permanent business relationships. Taking the company’s financial situation into account, it imposed 500,000 EUR; LocalBitcoins has appealed to the Helsinki Administrative Court.
KYC is a prerequisite for every business relationship – not an obligation to be met retrospectively once volumes grow.
Customer identification (KYC)
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Finnisches Geldwäschegesetz – Identifizierung und Verifizierung von Kunden
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 3 Jun 2025
- Finanssivalvonta – LocalBitcoins Oy:lle 500 000 euron seuraamusmaksu (3.6.2025) Press release of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links €950,000
On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.
Personal links are not access protection – sensitive customer data requires authentication and regular security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 20 Dec 2024
- Tietosuojavaltuutettu – Sambla Groupille seuraamusmaksu (20.12.2024) Press release of an authority
- Finlex – Tietosuojavaltuutettu 17.12.2024 (lainanvertailupalvelu) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link