Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Anonymised companies 23 cases 25 % · €473.8m
- AliExpress 2 cases 2 % · €550m
- "MAXIMA Latvija" SIA 1 case 1 % · €1.87m
- „Билла България“ ЕООД (Billa Bulgaria) 1 case 1 % · €207,555
- „Кауфланд България ЕООД енд Ко“ КД 1 case 1 % · €255,650
- Amazon 1 case 1 % ·
- Amazon Europe Core S.à r.l. 1 case 1 % ·
- Amazon.com, Inc. 1 case 1 % · €2.13bn
- AS Watson (Health & Beauty Continental Europe) B.V. 1 case 1 % · €50,000
- Betreibergesellschaft des Onlineshops About You (Sitz Hamburg; in der Mitteilung nicht namentlich genannt) 1 case 1 % · €1.32m
- 59 more59 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €3.2m |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
1 case
14 Mar 2025 Centros Comerciales Carrefour, S.A.AEPD: €3.2m fine for Carrefour Spain over access to customer accounts €3.2m
Between January and April 2023 Carrefour notified several personal data breaches involving unauthorised access to customer profiles; according to the notifications 118,895 people were affected in total. The AEPD imposed 2,000,000 EUR (Art. 5(1)(f)), 1,000,000 EUR (Art. 32) and 200,000 EUR for failing to inform data subjects (Art. 34), 3,200,000 EUR in total, and ordered the data subjects to be informed within one month.
Repeated access to customer accounts requires effective account protection and informing those affected, not just notifying the authority.
Protecting customer accounts against account takeover
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, 32, 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- AEPD, Resolución PS/00128/2024 (EXP202305979), Centros Comerciales Carrefour Decision of an authority
- AEPD, Memoria 2025 (Tabelle der 2025 unterzeichneten Bußgelder über 1 Mio. Euro) Official register or notice
Checked against the official source on 28 Sep 2026 · Direct link