Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- HSBC Bank plc €267.5m 26 % · 1 case
- Anonymised companies €214.3m 21 % · 49 cases
- Crédit Agricole Corporate and Investment Bank (Crédit Agricole CIB) €88.2m 9 % · 1 case
- J.P. Morgan SE €57.2m 6 % · 2 cases
- Klarna Bank AB €43.4m 4 % · 1 case
- Saxo Bank A/S €41.9m 4 % · 1 case
- Deutsche Bank AG €23.1m 2 % · 1 case
- Banco Santander, S.A. €22.5m 2 % · 1 case
- Coinbase Europe Limited €21.5m 2 % · 1 case
- Svea Bank AB €15.5m 2 % · 1 case
- 150 more€216.4m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €4m |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Dec 2024 Versicherer, Spanien (anonymisiert)AEPD: EUR 4m fine for an insurer after access via a broker account €4m
Following several complaints about a data breach, the Spanish data protection authority AEPD found that an attacker using an insurance broker's credentials was able to access extensive data held by an insurer, including on former customers, because basic security measures, separation of datasets and an impact assessment were lacking. Fines of 1,000,000 EUR (Art. 5(1)(f)), 1,000,000 EUR (Art. 32), 2,000,000 EUR (Art. 25) and 1,000,000 EUR (Art. 35) were set, 5,000,000 EUR in total; after voluntary payment without admission of liability, 4,000,000 EUR became payable.
External accounts such as those of brokers need strong authentication and must only reach the data that is actually required.
Securing intermediary and partner accounts
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, 25, 32, 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- 20% reduction for voluntary payment (Art. 85 LPACAP), without admission of liability.
- Published
- 13 May 2025
- AEPD, Resoluciones (Übersicht) (Entscheidung 2024) Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link