Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
€21.8mTotal of monetary amounts
€21.5mLargest single case: Coinbase Europe Limited
€277,500Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Central Bank of Ireland €21.5m 99 % · 2 cases
  2. Data Protection Commission (DPC) €277,500 1 % · 1 case

What for?

by area of law

All areas of law

  1. Money laundering and terrorist financing €21.5m 99 % · 2 cases
  2. Data protection €277,500 1 % · 1 case

Who?

by company
  1. Coinbase Europe Limited €21.5m 99 % · 1 case
  2. Permanent TSB plc €277,500 1 % · 1 case
  3. Swilly Mulroy Credit Union Limited €36,273 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20251€36,273
Q4 20251€21.5m
Q1 20260—
Q2 20261€277,500
Q3 20260—

3 cases

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Nov 2025 Coinbase Europe LimitedIreland: 21.5 million EUR against Coinbase Europe – 30 million transactions unchecked IrelandInternal controls €21.5m

In a settlement of 5 November 2025, the Central Bank of Ireland imposed a reprimand and 21,464,734 EUR (after a 30% discount on 30,663,906 EUR) for breaches of transaction monitoring obligations between April 2021 and March 2025: because of configuration errors in the monitoring system, more than 30 million transactions worth over 176 billion EUR – around 31% of all transactions – were not properly monitored over a period of twelve months. The subsequent review took almost three years and led to 2,708 suspicious transaction reports; the High Court confirmed the sanction on 12 January 2026, and it is the Central Bank's first enforcement action in the crypto sector.

What organisations can take from it

Test monitoring rules regularly for complete coverage – a silent configuration error can go undetected for years.

Authority / court
Central Bank of Ireland
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Published
6 Nov 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Swilly Mulroy Credit Union LimitedIreland: small credit union accepted cash from non-members without checks IrelandCustomer due diligence €36,273

Between 2014 and 2021, the credit union solicited cash from persons without an account and accepted 2,329 cash deposits totalling 8.75 million EUR without the required anti-money laundering checks; the board had known about the risk since 2015, and there was no self-reporting. The Central Bank of Ireland imposed a reprimand and 36,273 EUR (after a 30% discount on 51,819 EUR).

What organisations can take from it

Even small cooperative banks must identify cash from non-customers – and would do better to self-report known risks.

Relevance to training and awareness

Identification for cash deposits by non-customers

Authority / court
Central Bank of Ireland
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010; Credit Union Act 1997
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Liability of senior managers
The board had known about the risks since 2015 without taking remedial action
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial