Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Garante per la protezione dei dati personali €5.59m 98 % · 2 cases
- Banca d'Italia €100,000 2 % · 2 cases
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €60,000 |
| Q3 2025 | 1 | €80,000 |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €40,000 |
| Q3 2026 | 1 | €5.51m |
4 cases
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies €40,000
Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.
Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.
Customer due diligence and suspicious transaction reports
- Authority / court
- Banca d'Italia
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Corrective measures initiated
- Banca Popolare Commerciale Spa – Provvedimento n. 190 del 23 giugno 2026 (AML) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert €80,000
A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.
Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.
Identity verification for customer requests by e-mail (social engineering)
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.
- Garante privacy, Provvedimento del 10 luglio 2025 [10154110] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2025 Banca Privata Leasing SpaBanca d'Italia: 60,000 EUR against Banca Privata Leasing over deficiencies in AML organisation €60,000
An on-site inspection from February to May 2024 revealed deficiencies in organisation and internal controls relating to customer profiling, due diligence obligations and active cooperation (suspicious transaction reports). The Bank of Italy (Banca d'Italia) imposed an administrative fine of 60,000 EUR, taking into account the corrective measures taken.
Sound customer profiling is the basis for risk-appropriate due diligence and reporting.
- Authority / court
- Banca d'Italia
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–20, 24, 25, 35, 36 d.lgs. 231/2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Corrective measures taken
- Banca Privata Leasing Spa – Provvedimento n. 197 del 24 giugno 2025 (AML) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link