Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,918 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- Groupe SEB, Darty, Boulanger u. a. (12 Unternehmen) €611m 27 % · 1 case
- AliExpress €550m 25 % · 2 cases
- Delivery Hero SE, Glovoapp23 SA €329m 15 % · 1 case
- Temu €200m 9 % · 1 case
- Infinite Styles Services Co. Limited (Shein) €150m 7 % · 1 case
- Anonymised companies €136.9m 6 % · 16 cases
- Gucci €119.7m 5 % · 1 case
- Morellato S.p.A. €25.9m 1 % · 1 case
- Jeronimo Martins Polska (Biedronka) €24.7m 1 % · 1 case
- Jura Poland sp. z o.o., Terg S.A., Euro-net sp. z o.o. u. a. (5 Unternehmen) €15.9m 1 % · 1 case
- 49 more€63.6m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €3.5m |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
30 Dec 2025 Einzelhandelskette mit Kundenprogramm (anonymisiert)CNIL: €3.5m fine for retail chain over sharing customer data with a social network €3.5m
The CNIL (French data protection authority) fined an unnamed retail chain EUR 3,500,000 (EUR 2,500,000 under Art. 6(1)(a), 13, 32 and 35 GDPR and EUR 1,000,000 under Art. 82 of the Loi Informatique et Libertés, the French Data Protection Act). Since 2018 the company had transferred e-mail addresses and telephone numbers of members of its loyalty programme to a social network without valid consent in order to show them targeted advertising there; more than 10.5 million people were affected. In addition, there was inadequate information, weak password rules with SHA-256 hashing, no data protection impact assessment, and cookies that were set before any choice and continued to be read after a refusal.
Anyone transferring customer data to platforms for audience targeting needs a separate, clearly worded consent and a prior data protection impact assessment.
Using customer data for advertising on social networks
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 6 Abs. 1 lit. a, 13, 32 und 35 DSGVO; Art. 82 Loi n° 78-17 du 6 janvier 1978 (Loi Informatique et Libertés)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Published
- 22 Jan 2026
- CNIL: Transmission de données à un réseau social à des fins publicitaires : la CNIL prononce une sanction de 3,5 millions d'euros (22.01.2026) Press release of an authority
- Délibération de la formation restreinte n° SAN-2025-017 du 30 décembre 2025 concernant la société X Decision of an authority
- CNIL: Les sanctions prononcées par la CNIL (Liste, Stand 14.04.2026) Enforcement database of an authority
Checked against the official source on 2 Oct 2026 · Direct link