Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,828 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC) €54.3m 100 % · 2 cases
- Office of the Australian Information Commissioner (OAIC) – 0 % · 2 cases
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | – |
| Q4 2025 | 1 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €20.6m |
| Q3 2026 | 1 | €33.7m |
| Q4 2026 | 0 | – |
4 cases
28 Jul 2026 Harvey Norman Holdings Ltd; Latitude Finance AustraliaHarvey Norman and Latitude: AUD 55m penalties for misleading interest-free advertising €33.7m
A national advertising campaign from January 2020 to August 2021 promised purchases at Harvey Norman with 60 months interest free and no deposit, but concealed that a credit card such as the Latitude GO Mastercard was required, with monthly account fees and, until March 2021, establishment fees. After liability was established in 2024 and upheld on appeal in 2025, the Court set penalties of AUD 35 million against Harvey Norman and AUD 20 million against Latitude and ordered corrective notices on the home pages for 90 days. It based the higher penalty for Harvey Norman on its lower level of contrition.
Anyone advertising finance offers must disclose the credit products required and their costs as clearly as the headline offer.
Transparent advertising of instalment and credit offers
- Authority / court
- Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- ss 12DB(1)(a), (g), (i), 12DF(1) ASIC Act 2001 (Cth); Haftungsfeststellung auch zu s 12DA(1)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- In the Court’s view Latitude showed contrition; the advertising complained of had ceased.
- Liability of senior managers
- The Court regarded public statements by Harvey Norman’s board chair as showing disregard for potential harm to consumers and therefore considered a higher penalty necessary.
- Published
- 28 Jul 2026
Original amount 55,000,000 AUD, converted at the ECB reference rate of 28 Jul 2026.
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
18 May 2026 Walker Stores Pty Ltd (in Liquidation), Handelsname SnaffleSnaffle operator Walker Stores: AUD 33.5m penalty for overcharging credit interest €20.6m
The online retailer sold household appliances and electronics on instalments and, between September 2021 and February 2025, calculated interest in more than 38,000 credit contracts on the total contract amount instead of the unpaid balance; customers paid almost AUD 20 million too much as a result. Sample contracts also exceeded the statutory annual cost rate cap of 48%. The Court imposed AUD 32 million for the interest calculation and AUD 1.5 million for exceeding the cap, and ordered publication of a notice.
Anyone selling goods on instalments must have interest calculations and cost caps technically checked before thousands of contracts are affected.
Correct interest calculation and compliance with cost caps in instalment credit
- Authority / court
- Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC)
- Area of law
- Consumer protection and online retail
- Legal basis
- s 24(1) National Credit Code (Anhang 1 zum National Consumer Credit Protection Act 2009 (Cth)) i. V. m. ss 23(1), 28, 32A(1)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 18 May 2026
Original amount 33,500,000 AUD, converted at the ECB reference rate of 18 May 2026.
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
17 Oct 2025 Vinomofo Pty LtdVinomofo: privacy breach after unauthorised data access during a data migration Order
In 2022, during a large data migration project, the online wine retailer suffered unauthorised access to a database holding data on around 928,760 customers and members (identity, contact and financial information). The Privacy Commissioner found that Vinomofo had not taken reasonable steps to protect the data, although it had been aware of deficiencies in its security governance at least two years before the incident, and ordered it not to repeat these practices, together with specified remedial steps.
Data migrations to the cloud need their own security concept, and known weaknesses in security governance must not be put off.
Data security in migration projects and cloud services; privacy culture and training
Missing or inadequate training played a role in the decision.
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- APP 11.1 (Privacy Act 1988 (Cth))
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 29 Oct 2025
- OAIC: Vinomofo did not protect personal information from security risks, Privacy Commissioner finds (29 October 2025) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025) Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
26 Aug 2025 Kmart Australia LimitedKmart: facial recognition used against refund fraud breached the Privacy Act Order
From June 2020 to July 2022, Kmart Australia used facial recognition in 28 stores to record the face of every person who came in and of every customer at the returns counters, with the aim of uncovering refund fraud, without informing them or obtaining their consent. The Privacy Commissioner rejected the exception for addressing unlawful activity, because the indiscriminate collection of sensitive biometric information was disproportionate given less intrusive alternatives and its limited benefit, and ordered that the conduct must not be continued or repeated. The decision is currently under review before the Administrative Review Tribunal; hearings are scheduled for early 2027. The decision is not final.
Before deploying facial recognition, organisations must assess and document whether less intrusive means would suffice and whether the intrusion into the privacy of everyone captured is proportionate.
Facial recognition in retail: proportionality, notice and consent
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Privacy Act 1988 (Cth), APP 1.3, 1.4, 3.3, 3.4, 5.1, 5.2
- Action
- Order
- Status of proceedings
- under appeal
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Kmart stopped using the system in July 2022 when the investigation began and cooperated with the regulator throughout.
- Published
- 18 Sep 2025
- OAIC: Kmart’s use of facial recognition to tackle refund fraud unlawful, Privacy Commissioner finds (18.09.2025) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Kmart Australia Limited (Privacy) [2025] AICmr 155 (26 August 2025) Enforcement database of an authority
- OAIC: Privacy Commissioner publishes updated guidance on facial recognition in retail spaces (29.07.2026) Press release of an authority
Checked against the official source on 3 Oct 2026 · Direct link