Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Prezes Urzędu Ochrony Danych Osobowych (UODO) €1.33m 100 % · 4 cases
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €23,362 |
| Q1 2024 | 2 | €354,397 |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €950,490 |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
4 cases
20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing €950,490
In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.
Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.
Misdirected documents and notification of data subjects
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 9 Sep 2024
Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.
- Kara dla mBanku za niezawiadomienie osób poszkodowanych wyciekiem danych Press release of an authority
- Decyzja DKN.5131.1.2024 z 20 sierpnia 2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported €336,066
A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.
Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.
Risk assessment and notification of data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 2 Apr 2024
Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.59.2022 vom 12.03.2024 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years €18,331
The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.
Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.
Recognising misdirected mail and reporting it internally
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 2 Apr 2024
Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.28.2023 vom 12.03.2024 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator €23,362
The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.
Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.
Avoiding misdirected e-mails; reporting data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- intentional
- Repeat case
- yes
- Published
- 23 Nov 2023
Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.
- UODO: Kolejna administracyjna kara pieniężna za niezgłoszenie naruszenia ochrony danych osobowych (23.11.2023) Press release of an authority
- UODO, Decyzja DKN.5131.55.2022 vom 18.10.2023 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link