Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

83cases from 24 jurisdictions
€144.9mTotal of monetary amounts (74 cases with an amount)
€45mLargest single case: J.P. Morgan SE
€246,769Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20235€7.25m
Q1 20244€4.23m
Q2 20241€9.2m
Q3 20241€950,490
Q4 20245€1.66m
Q1 20256€530,000
Q2 20258€3.18m
Q3 202513€6.55m
Q4 202514€72.7m
Q1 20267€3.48m
Q2 202610€17.3m
Q3 20269€17.9m

83 cases

16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers SwedenOrganisational requirements €177,187

As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.

What organisations can take from it

Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.

Authority / court
Finansinspektionen (FI)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
No established damage to investors; remedial measures already taken during the investigation.
Published
16 Sep 2026

Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies EstoniaInternal controls Order

Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.

What organisations can take from it

Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance
Published
16 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection ItalyMarketing and consent €5.51m

For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).

What organisations can take from it

An objection to advertising must take effect immediately and reliably across all channels – including app messages.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports MaltaMoney laundering and terrorist financing €97,622

The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.

What organisations can take from it

Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction
Published
4 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination MaltaCustomer due diligence €160,099

At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.

What organisations can take from it

A customer risk assessment belongs before business starts, not in a later remediation project.

Relevance to training and awareness

Risk-based customer profiles and source of funds

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction; remediation demonstrated
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect CzechiaCartels and collusion €11.5m

From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.

What organisations can take from it

Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.

Relevance to training and awareness

Coordination of terms and conditions among competitors

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Published
17 Aug 2026

Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps GermanyCustomer due diligence €210,000

Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.

What organisations can take from it

Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.

Relevance to training and awareness

Ongoing monitoring of business relationships and suspicious activity reporting

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time GermanyDisclosure and reporting obligations €187,500

The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.

What organisations can take from it

Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.

Relevance to training and awareness

Threshold monitoring and notification deadlines for shareholdings

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 33 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
22 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR EU levelOrganisational requirements €2.15m

The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.

What organisations can take from it

Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR LithuaniaDisclosure and reporting obligations €362,000

Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.

What organisations can take from it

Running daily fines make every delay expensive – supervisory orders need top-management priority.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Published
30 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options BelgiumOrganisational requirements €1m

In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.

What organisations can take from it

Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies ItalyCustomer due diligence €40,000

Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.

What organisations can take from it

Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.

Relevance to training and awareness

Customer due diligence and suspicious transaction reports

Authority / court
Banca d'Italia
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Corrective measures initiated

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence SwedenCustomer due diligence €12.9m

For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.

What organisations can take from it

The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.

Relevance to training and awareness

Enhanced due diligence for high-risk customers

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Jun 2026

Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients CyprusOrganisational requirements €100,000

For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.

What organisations can take from it

When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.

Relevance to training and awareness

Appropriateness assessment when selling complex products

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Aug 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists FinlandMarket abuse and insider dealing €400,000

The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.

What organisations can take from it

Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.

Relevance to training and awareness

Insider lists and handling of inside information

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
Published
15 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary BelgiumOrganisational requirements €150,000

One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.

What organisations can take from it

Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.

Relevance to training and awareness

Care in master data maintenance / register reconciliation

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 4 avril 2014 relative aux assurances, Art. 259
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
IT adjustments to prevent recurrence.
Published
5 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection MaltaMarketing and consent €1,000

Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.

What organisations can take from it

An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.

Relevance to training and awareness

Passing marketing objections on to service providers (suppression lists)

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions FinlandDisclosure and reporting obligations €70,000

Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.

What organisations can take from it

Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.

Relevance to training and awareness

Regulatory reporting

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Admission of the failures / cooperation.
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register MaltaMoney laundering and terrorist financing €69,000

Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.

What organisations can take from it

Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The bank continuously attempted to upload reports
Published
6 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 BVwG reduces FMA penalty against private bank over unclarified beneficial owners AustriaCustomer due diligence €356,000

From 2017 to 2020, an Austrian bank specialising in private and investment banking had not adequately examined the ownership and control structure of an offshore holding client despite the lack of evidence on shareholders, trust arrangements and beneficial owners. The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the infringement but reduced the additional penalty imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 17 December 2024 from 476,000 to 356,000 EUR (total penalty 436,000 EUR less FMA penalties already paid), because the FMA had taken the seriousness of the offence into account twice and the bank had cooperated, admitted its errors and terminated the client relationship; an appeal on points of law has been permitted.

What organisations can take from it

For offshore holdings with trustees, prove the beneficial owner with supporting documents – a self-declaration is not enough.

Relevance to training and awareness

Identifying beneficial owners in holding and trust structures

Authority / court
Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 17.12.2024
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 9 Abs. 1 erster Satz i. V. m. § 6 Abs. 1 Z 2 FM-GwG; § 35 Abs. 1 und 3 i. V. m. § 34 Abs. 1 Z 2 und Abs. 2 FM-GwG; § 22 Abs. 9 FMABG (Zusatzstrafe)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Reduction by the court because the wrongfulness of the offence had been counted twice, cooperation, admission of the facts and of guilt, and termination of the client relationship

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR EU levelOrganisational requirements €1.37m

The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.

What organisations can take from it

Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2026 BVwG upholds 588,000 EUR FMA penalty against major bank over incorrect risk classification AustriaCustomer due diligence €588,000

The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) dismissed the appeal of a listed major Austrian bank and upheld the fine of 588,000 EUR (plus 58,800 EUR in procedural costs) imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 19 November 2024. From 2017 to 2020, the bank had not adequately risk-classified three business relationships and had disregarded sector risks such as gambling and precious metals trading as well as cash intensity; an appeal on points of law has been permitted.

What organisations can take from it

Customers from gambling or precious metals trading with a high share of cash belong in a higher risk class – otherwise the enhanced obligations are missing.

Relevance to training and awareness

Risk classification of cash-intensive high-risk sectors

Authority / court
Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 19.11.2024
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 6 Abs. 5 i. V. m. § 34 Abs. 1 Z 2 und § 35 Abs. 1–3 FM-GwG
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jan 2026 CCV Group B.V.Netherlands: payment institution CCV without integrity risk analysis – 406,125 EUR fine NetherlandsInternal controls €406,125

Until March 2018, the payment institution had no systematic integrity risk analysis (SIRA) and therefore no systematic identification and analysis of integrity risks for its gatekeeper function. The Dutch central bank (De Nederlandsche Bank, DNB) imposed the fine in 2020; following objection and appeal proceedings, it was fixed at the reduced amount of 406,125 EUR by the decision of 28 January 2026 and was published in July 2026.

What organisations can take from it

Without a documented integrity risk analysis, any money laundering prevention lacks its foundation – and that alone is subject to fines.

Authority / court
De Nederlandsche Bank (DNB)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 3:10 Wet op het financieel toezicht (Wft); Art. 10 Besluit prudentiële regels Wft (Bpr)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Mitigating circumstances
Fine reduced in the objection and appeal proceedings
Published
21 Jul 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2026 Cardif Lux Vie S.A.Cardif Lux Vie: 615,000 EUR over deficiencies in money laundering questionnaires and customer files LuxembourgCustomer due diligence €615,000

An on-site inspection in 2023 revealed that the life insurer in some cases did not handle the mandatory money laundering risk assessment questionnaires in compliance with the rules, that the employees responsible lacked sufficiently precise instructions and that customer files contained many incorrect answers. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 615,000 EUR.

What organisations can take from it

Risk questionnaires are only as good as the guidance given to those who complete them – clear work instructions and training are part of this.

Relevance to training and awareness

Money laundering risk assessment by employees

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 8-4, 8-5; Règlement CAA 20/03
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Close cooperation with the CAA during and after the inspection; remediation plan for all deficiencies submitted promptly.
Published
1 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Dec 2025 „ЗП Либра“ ООДZP Libra: 44,205 leva for poaching customers using competitor’s trade secrets BulgariaCompetition law €22,602

With the help of an employee of its competitor I&G Insurance Brokers who later moved to ZP Libra, the broker unfairly concluded a brokerage agreement to the detriment of the competitor and used the competitor’s trade secrets to poach customers. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) imposed 29,470 leva (1% of 2024 turnover, Art. 36(1) ZZK – Bulgarian Protection of Competition Act) and 14,735 leva (0.5%, Art. 37(1) ZZK); fines totalling 1,000 leva were also imposed on the employee.

What organisations can take from it

When hiring employees from competitors, make sure they do not bring customer lists or secrets with them – otherwise both the company and the individual are liable.

Relevance to training and awareness

Taking customer data and trade secrets when changing employer

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 36 Abs. 1, Art. 37 Abs. 1 ZZK
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Fines on the employee involved (1,000 leva in total)
Published
16 Dec 2025

Original amount 44,205 BGN, converted at the ECB reference rate of 11 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Dec 2025 Invest in OÜLender Invest in OÜ pays 16,000 EUR for failing to submit annual accounts EstoniaDisclosure and reporting obligations €16,000

The lender did not submit its 2024 annual report, together with the audit report, the resolution on the appropriation of profits and the minutes of the shareholders’ meeting, to the financial supervisory authority on time. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed a fine of 16,000 EUR; the maximum is 1 million EUR or 10% of annual turnover. Date = publication.

What organisations can take from it

Even small supervised lenders need a reliable deadline calendar for mandatory supervisory reports.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 56 Abs. 3, § 96 Abs. 2 KAVS (Gesetz über Kreditgeber und -vermittler)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
10 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ FranceCookies and tracking €1.5m

When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.

What organisations can take from it

Cookie settings must apply across all domains of a service – including when users move to affiliated sites.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Corrections during the proceedings, cooperation.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Nov 2025 Avida Finans ABAvida Finans: 20 million SEK for loans to consumers unable to repay SwedenConsumer protection and online retail €1.82m

The Swedish financial supervisory authority Finansinspektionen (FI) examined consumer loans granted by the lender over four weeks in summer 2024 and found at least around 30 cases in which consumers without the ability to repay received loans. FI issued a remark and imposed 20 million SEK.

What organisations can take from it

Carry out credit checks consistently even under sales pressure and verify them internally through sample checks.

Relevance to training and awareness

Creditworthiness assessment in sales

Authority / court
Finansinspektionen (FI)
Area of law
Consumer protection and online retail
Legal basis
Konsumentkreditlagen (2010:1846), Kreditprüfung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Nov 2025

Original amount 20,000,000 SEK, converted at the ECB reference rate of 11 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Nov 2025 Coinbase Europe LimitedIreland: 21.5 million EUR against Coinbase Europe – 30 million transactions unchecked IrelandInternal controls €21.5m

In a settlement of 5 November 2025, the Central Bank of Ireland imposed a reprimand and 21,464,734 EUR (after a 30% discount on 30,663,906 EUR) for breaches of transaction monitoring obligations between April 2021 and March 2025: because of configuration errors in the monitoring system, more than 30 million transactions worth over 176 billion EUR – around 31% of all transactions – were not properly monitored over a period of twelve months. The subsequent review took almost three years and led to 2,708 suspicious transaction reports; the High Court confirmed the sanction on 12 January 2026, and it is the Central Bank's first enforcement action in the crypto sector.

What organisations can take from it

Test monitoring rules regularly for complete coverage – a silent configuration error can go undetected for years.

Authority / court
Central Bank of Ireland
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Published
6 Nov 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Oct 2025 Landesbank Hessen-Thüringen Girozentrale (Helaba)BaFin: fine against Helaba over inadequate monitoring systems for money laundering prevention GermanyInternal controls €20,000

By decision of 28 October 2025 (final since 7 November 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 20,000 EUR because, from October 2022 to September 2023, the Landesbank operated data processing systems for money laundering prevention that were only partially adequate. Under the German Banking Act (KWG), the criteria by which monitoring identifies suspicious transactions must be documented, and the systems must be checked regularly by an independent auditor.

What organisations can take from it

Transaction monitoring needs documented indicators and a regular independent quality review – the mere existence of software is not enough.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
§ 56 Abs. 2 Nr. 11b KWG (Betrieb angemessener Datenverarbeitungssysteme zur Geldwäscheprävention)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
10 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login FinlandData breaches and data security €865,000

Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.

What organisations can take from it

Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
28 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Oct 2025 Taxshelter.be SATaxshelter.be: 75,000 EUR for missing prospectus supplement on guarantee risks BelgiumDisclosure and reporting obligations €75,000

After the tax authority had refused the tax shelter certificates for a financed show and the insurer left cover open, the provider failed to inform investors of this material risk in good time by means of a prospectus supplement. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 75,000 EUR with publication by name.

What organisations can take from it

New material risks for investors trigger an immediate obligation to publish a supplement – not only in the next annual prospectus.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Verordnung (EU) 2017/1129 Art. 23; Loi du 11 juillet 2018 (Loi Prospectus)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
21 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Oct 2025 Zimpler ABZimpler: 3 million SEK over anti-money laundering deficiencies at gambling-related payment service SwedenCustomer due diligence €272,245

Between July 2023 and April 2024, the payment service provider, a substantial part of whose business is linked to the gambling sector, had gaps in its general risk assessment (including a missing assessment of its currency exchange service), in its customer risk assessment and in customer due diligence. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 3 million SEK.

What organisations can take from it

Include every new product – even an ancillary service such as currency exchange – in the money laundering risk assessment before launch.

Relevance to training and awareness

Money laundering risks in the gambling environment

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
15 Oct 2025

Original amount 3,000,000 SEK, converted at the ECB reference rate of 15 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Oct 2025 AS Inbank FinanceOrder against Inbank Finance over deficiencies in creditworthiness assessment EstoniaConsumer protection and online retail Order

During an inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) found that Inbank Finance’s internal rules on assessing the creditworthiness of consumers did not fully comply with the law and that the assessment itself showed deficiencies. It issued an order requiring the company to remedy the deficiencies by mid-December. Date = publication.

What organisations can take from it

Creditworthiness assessments must be documented, rule-based and actually applied in day-to-day business.

Relevance to training and awareness

Responsible lending in sales

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail
Legal basis
Gesetz über Kreditgeber und -vermittler (KAVS), verantwortungsvolle Kreditvergabe
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance
Published
14 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 J.P. Morgan SEBaFin: 45 million EUR against J.P. Morgan SE over late suspicious activity reports GermanySuspicious activity reports €45m

By decision of 13 October 2025 (final since 30 October 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 45 million EUR on J.P. Morgan SE because the institution had culpably breached its duty of supervision in the internal processes for filing money laundering suspicious activity reports; from 4 October 2021 to 30 September 2022, suspicious activity reports were systematically not filed on time. BaFin points out that, in the case of systematic infringements, the amount of the fine can be based on the institution's total turnover.

What organisations can take from it

File suspicious activity reports without delay – systematic backlogs in the reporting process are themselves an infringement, and the fine can then be calculated on the basis of the institution's total turnover.

Relevance to training and awareness

Filing money laundering suspicious activity reports without delay

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
§ 130 Abs. 1 OWiG (Aufsichtspflichtverletzung) i. V. m. Pflichten nach dem GwG (Verdachtsmeldungen); Bekanntmachung nach § 57 Abs. 1 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Published
6 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Wonderinterest Trading LtdCyprus: 100,000 EUR against Wonderinterest Trading over misleading client information CyprusOrganisational requirements €100,000

For 2022 to 2024, the Cyprus Securities and Exchange Commission (CySEC) found that the investment firm had no adequate compliance procedures, did not define target markets for its financial instruments, did not act in the best interests of clients and did not inform clients in a fair, clear and not misleading manner. It imposed fines of 50,000, 30,000 and 20,000 EUR; a judicial review of the decision has been recorded.

What organisations can take from it

Advertising statements by financial service providers must present risks in a balanced way – marketing belongs in the compliance approval process.

Relevance to training and awareness

Fair and not misleading marketing communications

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Sec. 17(2), 17(3)(c), 22(1), 25(1), 25(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 22, 44 Delegierte VO (EU) 2017/565
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Finamore S.A.Finamore: licence of insurance broker withdrawn over serious deficiencies LuxembourgOrganisational requirements Other

The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broking firm’s licence (effective from 1 December 2025), among other things for using unregistered intermediaries, lacking internal expertise, insufficiently protected confidential data, economically unexplained payment flows with affiliated companies, incomplete or false information provided to the supervisory authority and deficient customer information.

What organisations can take from it

False information to the supervisory authority and unregistered distribution partners can cost the business its existence – not just a fine.

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 303 Abs. 3 lit. c
Action
Other
Status of proceedings
unknown
Sector
Financial services and insurance
Published
29 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers SloveniaSecurity measures and risk management Reprimand or warning

After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).

What organisations can take from it

Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.

Relevance to training and awareness

Security testing for software releases of interfaces

Authority / court
Banka Slovenije
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance
Liability of senior managers
Reprimand also issued to the responsible Director of IT Development (Dejan Pust).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2025 Go West Invest SAGo West Invest: 10,000 EUR for outdated information note in tax shelter offering BelgiumDisclosure and reporting obligations €10,000

From June 2021 to October 2024, the company, which raises tax shelter funds through public offerings, kept a public offering on its website with an information note from 2020 without publishing an updated note and filing it with the Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA); several dozen investors with an investment volume of under 5 million EUR were affected. The FSMA accepted a settlement of 10,000 EUR.

What organisations can take from it

Investor information has an expiry date – a deadline calendar for mandatory documents prevents infringements.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Loi du 11 juillet 2018 (Loi Prospectus), Art. 10, 11
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
16 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service FinlandData breaches and data security €1.8m

After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.

What organisations can take from it

Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
Published
10 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Sep 2025 „Paysera LT“, UABPaysera took over e-money institution Contis without approval – 400,000 EUR LithuaniaOrganisational requirements €400,000

Paysera acquired 100% of the shares in UAB ‘Finansinės paslaugos „Contis“’ before the assessment period had expired and without a non-objection from the supervisory authority; in April 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) objected to the acquisition owing to a lack of documents on reputation, financial soundness and money laundering risks. In addition, the annual financial statements and other reports were not approved and submitted on time. Fine of 400,000 EUR and obligation to remedy by 30 September 2025. Source: archived copy of the press release.

What organisations can take from it

Complete acquisitions of holdings in supervised institutions only after approval – otherwise voting rights are suspended and fines loom.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Elektroninių pinigų ir elektroninių pinigų įstaigų įstatymas (Inhaberkontrolle, Berichtspflichten)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Blacktower Financial Management (Cyprus) LtdCyprus: Blacktower Financial Management pays 70,000 EUR over conflicts of interest CyprusOrganisational requirements €70,000

For the period November 2020 to May 2025, the Cyprus Securities and Exchange Commission (CySEC) investigated the investment firm’s handling of conflicts of interest and its general conduct of business and information obligations towards clients. The proceedings ended with a settlement of 70,000 EUR, which the company has paid.

What organisations can take from it

Conflicts of interest must be identified, documented and managed vis-à-vis clients – adviser training is the basis for this.

Relevance to training and awareness

Recognising conflicts of interest in investment advice

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 24(1), 25(1) Gesetz über Wertpapierdienstleistungen 2017; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Aug 2025 Varengold Bank AGBaFin: 3.3 million EUR fine and penalty payment against Varengold Bank GermanySuspicious activity reports €3.8m

By decision of 22 August 2025, Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 3.3 million EUR because the bank systematically filed suspicious activity reports late from June 2023 to March 2025; in February 2025, a penalty payment of 500,000 EUR had already been imposed for failure to comply with a 2023 order concerning Iran-related transactions (total 3.8 million EUR). In addition, in July 2025 BaFin ordered comprehensive remediation of the deficiencies in money laundering prevention, with an action plan and reporting obligations.

What organisations can take from it

Failing to implement a supervisory order risks penalty payments and a comprehensive package of measures in addition to the fine.

Relevance to training and awareness

Suspicious activity reports and handling of high-risk transactions

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Bußgeld: § 56 Abs. 1 S. 1 Nr. 69, Abs. 3 GwG; Anordnung: § 51 Abs. 2 GwG, § 44 Abs. 1 KWG; Zwangsgeld: § 14 VwVG i. V. m. § 17 FinDAG; Bekanntmachung nach § 57 Abs. 1 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Published
16 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR RomaniaData breaches and data security €2,990

A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.

What organisations can take from it

Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.

Relevance to training and awareness

Identity verification and fraud detection in remote applications

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
12 Aug 2025

Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers EstoniaData subject rights and transparency Order

The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.

What organisations can take from it

Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2025 Condor Courtiers & Conseillers S.à r.l.Condor Courtiers & Conseillers: licence withdrawn for using unlicensed introducers LuxembourgOrganisational requirements Other

Following an on-site inspection in 2024, the Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broker’s licence (effective 15 September 2025): there was no effective management by approved managers, unlicensed ‘introducers’ were de facto selling insurance, and the broker’s licence, together with its sub-intermediary network, was improperly made available to third parties.

What organisations can take from it

A distribution licence is not transferable – anyone who ‘rents it out’ to third parties or lets introducers sell risks having it withdrawn.

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 273, 274, 283, 286, 303
Action
Other
Status of proceedings
unknown
Sector
Financial services and insurance
Published
16 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert ItalyIncident reporting obligations €80,000

A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.

What organisations can take from it

Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.

Relevance to training and awareness

Identity verification for customer requests by e-mail (social engineering)

Authority / court
Garante per la protezione dei dati personali
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jul 2025 Barents Reinsurance S.A.Barents Reinsurance: maximum fine of 250,000 EUR over governance deficiencies LuxembourgOrganisational requirements €250,000

The reinsurer breached the principle of specialisation in reinsurance business, its approved manager was not effectively present on site and had insufficient powers, the governance system including oversight of outsourced functions was inadequate, and orders from a 2019 inspection had not been implemented or only partially. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed the statutory maximum of 250,000 EUR; the company cooperated.

What organisations can take from it

On-site substance is a supervisory requirement: management, powers and oversight of outsourced functions must genuinely be located in the home country.

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 49, 71, 81, 274, 303
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cooperation with the CAA during and after the inspection.
Published
8 Aug 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data CroatiaData breaches and data security €101,000

Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.

Relevance to training and awareness

Access control and deletion periods for register data

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cap due to public tasks (Art. 44 of the Implementing Act).
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Swilly Mulroy Credit Union LimitedIreland: small credit union accepted cash from non-members without checks IrelandCustomer due diligence €36,273

Between 2014 and 2021, the credit union solicited cash from persons without an account and accepted 2,329 cash deposits totalling 8.75 million EUR without the required anti-money laundering checks; the board had known about the risk since 2015, and there was no self-reporting. The Central Bank of Ireland imposed a reprimand and 36,273 EUR (after a 30% discount on 51,819 EUR).

What organisations can take from it

Even small cooperative banks must identify cash from non-customers – and would do better to self-report known risks.

Relevance to training and awareness

Identification for cash deposits by non-customers

Authority / court
Central Bank of Ireland
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010; Credit Union Act 1997
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Liability of senior managers
The board had known about the risks since 2015 without taking remedial action
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2025 Banca Privata Leasing SpaBanca d'Italia: 60,000 EUR against Banca Privata Leasing over deficiencies in AML organisation ItalyInternal controls €60,000

An on-site inspection from February to May 2024 revealed deficiencies in organisation and internal controls relating to customer profiling, due diligence obligations and active cooperation (suspicious transaction reports). The Bank of Italy (Banca d'Italia) imposed an administrative fine of 60,000 EUR, taking into account the corrective measures taken.

What organisations can take from it

Sound customer profiling is the basis for risk-appropriate due diligence and reporting.

Authority / court
Banca d'Italia
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–20, 24, 25, 35, 36 d.lgs. 231/2007
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Corrective measures taken

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2025 C2D Payment Solutions LimitedMalta: 243,537 EUR against C2D Payment Solutions for ignoring cash risks MaltaCustomer due diligence €243,537

The financial institution did not take into account its customers’ significant cash exposure in its customer risk assessment, so that almost all customers were rated low risk – even with cash deposits of over 100,000 EUR. The Financial Intelligence Analysis Unit (FIAU) imposed 243,537 EUR and a follow-up directive; the fine was open to appeal at the time of publication.

What organisations can take from it

Cash is an explicit high-risk factor – a risk model that ignores it is worthless.

Relevance to training and awareness

Recognising cash as a risk factor

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 7(1)(c), 7(1)(d), 7(2)(a), 21 PMLFTR
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
23 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Jun 2025 Svea Finance AS200,000 EUR fine against Svea Finance over deficient creditworthiness assessment EstoniaConsumer protection and online retail €200,000

Between December 2023 and February 2024, Svea Finance’s internal rules on consumer lending did not comply with the law (50,000 EUR), and the company concluded credit agreements without assessing all prescribed creditworthiness components (150,000 EUR). Fines totalling 200,000 EUR for two misdemeanours. Date = publication.

What organisations can take from it

Creditworthiness assessments must cover all factors prescribed by law – gaps in internal policies are sanctioned separately.

Relevance to training and awareness

Responsible lending

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail
Legal basis
§ 98 Abs. 2 und § 99 Abs. 2 KAVS
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2025 CaixaBank, S.A.AEPD: 200,000 EUR against CaixaBank over continued storage of a non-customer's data SpainMarketing and consent €200,000

A person who was not (or no longer) a customer received a letter from CaixaBank about an update to its privacy statement, announcing that she would be contacted about her advertising preferences. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) considered the continued storage of her data to be an infringement of the principle of storage limitation and imposed 200,000 EUR; the bank's request for reconsideration was dismissed as inadmissible.

What organisations can take from it

Before mass mailings, check whether the recipients' data may still be stored at all – former customers should be deleted, not written to.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jun 2025 LocalBitcoins OyLocalBitcoins: 500,000 EUR for failing to identify customers when opening accounts FinlandCustomer due diligence €500,000

During an inspection in 2024, the Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) found that the crypto trading platform had not identified and verified its customers when establishing permanent business relationships. Taking the company’s financial situation into account, it imposed 500,000 EUR; LocalBitcoins has appealed to the Helsinki Administrative Court.

What organisations can take from it

KYC is a prerequisite for every business relationship – not an obligation to be met retrospectively once volumes grow.

Relevance to training and awareness

Customer identification (KYC)

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Finnisches Geldwäschegesetz – Identifizierung und Verifizierung von Kunden
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Apr 2025 Bondora ASBondora must pay 200,000 EUR for breaching responsible lending rules EstoniaConsumer protection and online retail €200,000

From 6 December 2023 to 24 February 2024, Bondora concluded consumer credit agreements without assessing all criteria provided for by law and satisfying itself of the borrowers’ ability to repay. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed 200,000 EUR. Date = publication.

What organisations can take from it

Automated credit decisions do not release lenders from the full statutory creditworthiness assessment.

Relevance to training and awareness

Responsible lending

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail
Legal basis
§ 99 Abs. 2 KAVS
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
30 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2025 Iberinform Internacional, S.A.AEPD: 720,000 EUR against business information agency Iberinform for purchased data on entrepreneurs SpainData subject rights and transparency €720,000

Since 2008, Iberinform had obtained data on sole traders through a supply contract with Camerdata and used it to enrich its own files for commercial information services. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found no legal basis for this and no information of the data subjects, and imposed 360,000 EUR for each (720,000 EUR in total) as well as an order to bring the processing into compliance; the request for reconsideration (recurso de reposición) was rejected.

What organisations can take from it

Companies that purchase personal data from third parties need their own legal basis and must actively inform the data subjects.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 14 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Apr 2025 OKCoin Europe LimitedMalta: 1.05 million EUR against crypto exchange OKCoin Europe over anti-money laundering deficiencies MaltaInternal controls €1.05m

During an on-site examination in 2023, the Financial Intelligence Analysis Unit (FIAU) found deficiencies at the crypto service provider in its business risk assessment (including product risks), customer risk assessment, customer profiles, ongoing monitoring, suspicious transaction reporting and record-keeping. It imposed 1,054,269 EUR and a follow-up directive; the fine was open to appeal at the time of publication.

What organisations can take from it

Crypto providers are held to the same due diligence standards as banks – the risk assessment must cover their own products.

Relevance to training and awareness

Anti-money laundering for crypto-assets

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Reg. 5(1), 5(4), 5(5), 7, 11, 15(3), 21 PMLFTR; FIAU Implementing Procedures
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
3 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Mar 2025 FXNET LimitedCyprus: FXNET pays 225,000 EUR under settlement over organisational and CFD breaches CyprusOrganisational requirements €225,000

The investigation covering 2021 to 2022 concerned compliance organisation, product governance, record-keeping obligations, safeguarding of client funds, client information, suitability and appropriateness assessments and the CFD restrictions for retail investors. Following board resolutions of 17 and 31 March 2025, the Cyprus Securities and Exchange Commission (CySEC) concluded a settlement of 225,000 EUR, which has been paid.

What organisations can take from it

Safeguarding client funds and keeping proper records are basic duties of every investment firm – gaps quickly add up in a settlement.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 17, 22(1), 25, 26(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
11 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long CyprusData subject rights and transparency €10,000

The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.

What organisations can take from it

Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Mar 2025 MAKI podjetje za turizem, trgovino in storitve d.o.o. KoperBureau de change MAKI: transaction limit of 1,000 EUR over unresolved anti-money laundering deficiencies SloveniaInternal controls Order

During a follow-up inspection, Banka Slovenije (Bank of Slovenia) found that the company had not remedied the anti-money laundering deficiencies it had been ordered to address in 2023; some infringements are considered serious. It limited transactions to 1,000 EUR per customer per day, ordered monthly reports and set a deadline of 30 June 2025.

What organisations can take from it

Supervisory orders that are not implemented lead to business restrictions – working through them requires responsible persons and deadline control.

Relevance to training and awareness

Anti-money laundering in small financial service providers

Authority / court
Banka Slovenije
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 164 ZPPDFT-2, Art. 280 ZBan-3, Art. 42.a ZBS-1
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent CyprusData breaches and data security Reprimand or warning

An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.

What organisations can take from it

Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.

Relevance to training and awareness

Disclosure of customer data to agents and colleagues in their own matters

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The company implemented the order

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jan 2025 Εθνική Τράπεζα της Ελλάδος Α.Ε. (National Bank of Greece)Greece: 120,000 EUR against National Bank of Greece after misdirected payment via mobile number GreeceData breaches and data security €120,000

An IRIS transfer made by mobile number via the bank’s app ended up with an uninvolved customer instead of the intended recipient because the number had been assigned incorrectly. By Decision 3/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed 100,000 EUR for inaccurate data, insufficient security, lack of data protection by design and failure to notify the data breach, as well as 20,000 EUR for breach of the right of access.

What organisations can take from it

Even a single misdirected payment can be a notifiable data breach – customer complaints must be assessed internally as a possible incident.

Relevance to training and awareness

Recognising and reporting data breaches

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. d und f, Art. 15, 25, 32, 33, 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Jan 2025 Luxembourg credit institution: 175,000 EUR for late responses to data subject requests LuxembourgData subject rights and transparency €175,000

Following 47 complaints, the Commission nationale pour la protection des données (Luxembourg data protection authority, CNPD) found that a Luxembourg credit institution (pseudonymised in the decision as ‘Société A’) had not responded to data subjects’ requests on time; the CNPD did not accept the reference to the COVID-19 pandemic. It issued a reprimand (rappel à l’ordre) and imposed 175,000 EUR.

What organisations can take from it

Data subject requests require deadline tracking and a monitored DPO mailbox – staff shortages are no excuse.

Relevance to training and awareness

Deadlines for data subject requests

Authority / court
Commission nationale pour la protection des données (CNPD) – formation restreinte
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 12 Abs. 3 und 4
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father CyprusEmployee data Reprimand or warning

A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.

What organisations can take from it

HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.

Relevance to training and awareness

Confidential delivery of HR correspondence

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links FinlandData breaches and data security €950,000

On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.

What organisations can take from it

Personal links are not access protection – sensitive customer data requires authentication and regular security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
20 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Dec 2024 Salva Kindlustuse ASSalva Kindlustus: 10,000 EUR for motor insurance advertising without mandatory notice EstoniaMisleading advertising and pricing €10,000

Through Europark Estonia, the insurer placed advertising for motor third-party liability insurance that lacked the statutory notice referring to the insurance terms, and incorrectly stated on policies that the contracts had been concluded through a registered insurance agent. Fine of 10,000 EUR. Date = publication.

What organisations can take from it

Anyone using distribution partners for advertising and concluding contracts must itself check their mandatory disclosures and registration.

Relevance to training and awareness

Mandatory disclosures in financial advertising; management of distribution partners

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 254 Abs. 2 KindlTS (Versicherungstätigkeitsgesetz); Werbegesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
3 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Nov 2024 Banus Port Vagyonkezelő Zrt.Banus Port: 250 million HUF for fictitious trading in 4iG shares HungaryMarket abuse and insider dealing €608,080

From September 2023 to May 2024, the asset management company used transactions worth several billion forints to create false signals about the trading volume of 4iG shares (‘painting the tape’). The Magyar Nemzeti Bank (Central Bank of Hungary, MNB) prohibited any repetition, imposed 250 million HUF and filed a criminal complaint.

What organisations can take from it

Transactions that mainly simulate turnover are market manipulation – even without a price target.

Authority / court
Magyar Nemzeti Bank (MNB)
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Art. 12, 15 MAR (Marktmanipulation), Beschluss H-PJ-III-B-26/2024
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
intentional
Published
22 Nov 2024

Original amount 250,000,000 HUF, converted at the ECB reference rate of 22 Nov 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Nov 2024 Deželna banka Slovenije d. d.Deželna banka Slovenije: 90,000 EUR for deficient credit risk provisioning SloveniaOrganisational requirements €90,000

From 2018 to mid-2023, the bank had no adequate policies for impairments and provisions under IFRS 9 and the EBA guidelines on credit risk. Banka Slovenije (Bank of Slovenia) imposed 90,000 EUR on the bank and 2,500 EUR each on the chair of the management board and a board member.

What organisations can take from it

In Slovenia, governance deficiencies in risk management are also sanctioned personally against board members.

Authority / court
Banka Slovenije
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 171, Art. 396 Abs. 1 Nr. 19 ZBan-3
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Liability of senior managers
Fines of 2,500 EUR each on the chair of the management board, Marko Rozman, and the board member Barbara Cerovšek Zupančič.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing PolandData breaches and data security €950,490

In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.

What organisations can take from it

Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.

Relevance to training and awareness

Misdirected documents and notification of data subjects

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
9 Sep 2024

Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Apr 2024 N26 Bank AGBaFin: 9.2 million EUR against N26 over systematically late suspicious activity reports GermanySuspicious activity reports €9.2m

By final decision of 24 April 2024, Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 9.2 million EUR on the neobank because it had systematically filed money laundering suspicious activity reports late in 2022.

What organisations can take from it

Send suspicious activity reports to the FIU without delay – systematically late reporting risks fines running into millions.

Relevance to training and awareness

Suspicious activity reports without delay

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
§ 56 Abs. 1 Nr. 69, Abs. 3 GwG (verspätete Verdachtsmeldungen, § 43 Abs. 1 GwG); Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
21 May 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2024 Scope Ratings GmbHScope Ratings: conflicts of interest not identified and disclosed – 2.2 million EUR EU levelOrganisational requirements €2.2m

The Berlin-based credit rating agency lacked adequate procedures, internal controls and organisational arrangements to deal with conflicts of interest, did not disclose a potential conflict and concealed ancillary services it had provided to a rated entity. ESMA found negligent infringements and imposed fines of 2,197,500 EUR.

What organisations can take from it

Systematically record and disclose ancillary services for customers whom you are at the same time rating or auditing.

Relevance to training and awareness

Identifying and disclosing conflicts of interest

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Anhang III
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes
Published
22 Mar 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported PolandIncident reporting obligations €336,066

A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.

What organisations can take from it

Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.

Relevance to training and awareness

Risk assessment and notification of data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Repeat case
yes
Published
2 Apr 2024

Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years PolandIncident reporting obligations €18,331

The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.

What organisations can take from it

Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.

Relevance to training and awareness

Recognising misdirected mail and reporting it internally

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
2 Apr 2024

Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jan 2024 Lombard International Assurance S.A.Lombard International Assurance: 1.68 million EUR over missing overall money laundering risk assessment LuxembourgInternal controls €1.68m

During an inspection in 2021/2022, the Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) found that the life insurer had not prepared an overall assessment of its money laundering risks, that guidance for employees on due diligence obligations (beneficial owners, high-risk countries, PEPs) was inadequate and that it was not checked whether the intermediaries used fulfilled their due diligence obligations. It imposed 1,682,000 EUR.

What organisations can take from it

Without a documented overall risk assessment, a risk-based approach cannot be demonstrated – intermediaries must also be monitored.

Relevance to training and awareness

Due diligence obligations regarding beneficial owners and PEPs

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 2-2, 8-4, 8-5; Règlement CAA 20/03
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
20 Mar 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Nov 2023 UAB „Finansinės paslaugos „Contis““Contis: 840,000 EUR for anti-money laundering delegated to partners without oversight LithuaniaCustomer due diligence €840,000

The e-money institution had delegated anti-money laundering tasks to its distribution partners without monitoring them; customer profiles were often not completed, risks (including from crypto-assets) were not assessed, monitoring was insufficient and the second and third lines of defence for ICT risks were missing. Fine of 840,000 EUR, obligation to remedy the deficiencies and restriction on business expansion. Source: archived copy of the press release.

What organisations can take from it

AML duties can be delegated to distribution partners, responsibility cannot – without oversight of the partners, the institution is liable.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Pinigų plovimo ir teroristų finansavimo prevencijos įstatymas; IKT-Risikomanagement-Anforderungen
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The institution submitted a remediation plan and had initiated first steps.
Published
24 Nov 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Nov 2023 OTP Bank Nyrt.OTP Bank: 49.4 million HUF over late suspicious transaction reports HungarySuspicious activity reports €130,215

The bank did not report several suspicious cases to the financial intelligence unit without delay, its monitoring produced delayed hits owing to incorrectly set filter parameters, and its risk assessment, customer due diligence and documentation of anti-money laundering training showed deficiencies. The Magyar Nemzeti Bank (Central Bank of Hungary, MNB) imposed a total of 49.375 million HUF and set deadlines for remediation by August 2024.

What organisations can take from it

Validate monitoring parameters regularly – and training is expressly among the obligations that are inspected.

Relevance to training and awareness

Recognising and reporting suspected money laundering in good time

Missing or inadequate training played a role in the decision.

Authority / court
Magyar Nemzeti Bank (MNB)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Ungarisches Geldwäschegesetz (Pmt.); Beschluss H-PM-I-B-76/2023
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
The bank had already initiated remedial measures for several of the infringements.
Published
21 Nov 2023

Original amount 49,375,000 HUF, converted at the ECB reference rate of 21 Nov 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator PolandIncident reporting obligations €23,362

The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.

What organisations can take from it

Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.

Relevance to training and awareness

Avoiding misdirected e-mails; reporting data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
intentional
Repeat case
yes
Published
23 Nov 2023

Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Oct 2023 Swiss Life (Luxembourg)Swiss Life (Luxembourg): 790,000 EUR over deficiencies in anti-money laundering LuxembourgInternal controls €790,000

An inspection in 2021 revealed that the life insurer had not carried out an overall assessment of its money laundering risks and that the guidance for employees on due diligence obligations (beneficial owners, high-risk countries, PEPs) was inadequate. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 790,000 EUR.

What organisations can take from it

The overall money laundering risk assessment is the basis of all due diligence obligations and must be in place before new business relationships are entered into.

Relevance to training and awareness

Customer due diligence in insurance distribution

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 2-2, 8-4, 8-5; Règlement CAA 20/03
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
3 Jul 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Oct 2023 EOS Matrix d.o.o.Croatia: 5.47 million EUR against debt collection company EOS Matrix after data leak CroatiaData breaches and data security €5.47m

An anonymous tip-off accompanied by a USB stick proved that data of 181,641 debtors had leaked from the debt collection company’s records; there were no systems for detecting unusual data retrievals. In addition, EOS Matrix stored health data up to and including diagnoses, data of non-debtors and call recordings without a legal basis; the Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 5.47 million EUR.

What organisations can take from it

Employees’ free-text notes can turn into impermissible health data – clear recording rules and monitoring of data retrievals are mandatory.

Relevance to training and awareness

No recording of health data in call notes

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 2, Art. 6 Abs. 1, Art. 9 Abs. 2, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Oct 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial