Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

31cases from 15 jurisdictions
€1.96bnTotal of monetary amounts (22 cases with an amount)
€530mLargest single case: TikTok Technology Limited
€3.19mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20232€499,215
Q1 20240—
Q2 20240—
Q3 20243€506.6m
Q4 20244€255.8m
Q1 20251€13,604
Q2 20252€730m
Q3 20253€325m
Q4 20256€128.3m
Q1 20264€17.5m
Q2 20263€140,706
Q3 20263€500

31 cases

26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants DenmarkAbuse of market power Order

In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.

What organisations can take from it

Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
Competition law · Abuse of market power
Legal basis
Konkurrenceloven; AEUV Art. 102
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Published
26 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 WH Media GmbHKommAustria penalises person responsible for W24 over advertising in news programme AustriaMisleading advertising and pricing €500

On 29 May 2024, the Vienna broadcaster W24 aired advertising in split screen within the programme ‘24 Stunden Wien’, did not adequately separate advertising from programming and, at around 50 minutes, significantly exceeded the permitted 12 minutes of advertising per hour. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) imposed fines totalling 500 EUR (plus 50 EUR in costs) on the body authorised to represent the company externally; the GmbH is jointly and severally liable under § 9 (7) VStG (Austrian Administrative Penal Act).

What organisations can take from it

Advertising time limits and the separation requirement also apply to small regional broadcasters – management is personally liable via § 9 VStG.

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 64 Abs. 2 Z 9 i. V. m. §§ 43 Abs. 2, 44 Abs. 1, 45 Abs. 1 AMD-G; § 9 VStG
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous record, duration of proceedings, remorseful confession and remedial measures initiated.
Liability of senior managers
Fine imposed on the body responsible externally (§ 9 (1) VStG); the company is jointly and severally liable.
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 Österreichischer Rundfunk (ORF)KommAustria finds unlabelled product placement in ORF's ‘Sport aktuell’ AustriaMisleading advertising and pricing Order

In the programme ‘Sport aktuell’ on ORF 1 on 29 July 2025, a logo wall was visible as product placement without being labelled. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) found, with final effect, a violation of the ORF Act (ORF-Gesetz).

What organisations can take from it

Product placements must be identified and labelled by the editorial team – including logo walls in the background.

Relevance to training and awareness

Labelling of advertising and product placement

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 16 Abs. 5 Z 4 ORF-G
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked DenmarkPlatform obligations Order

After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.

What organisations can take from it

Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters HungaryData protection €140,706

On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.

What organisations can take from it

Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.

Relevance to training and awareness

Handling leaked personal data in newsrooms

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection
Legal basis
DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
intentional
Published
26 May 2026

Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years DenmarkData protection Fine

The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.

What organisations can take from it

‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Mar 2026 Trustpilot Group Plc, Trustpilot A/S, Trustpilot S.r.l.Trustpilot: 4 million EUR fine for inadequate verification of the authenticity of reviews ItalyFake reviews €4m

According to the AGCM, the review platform did not adequately check whether reviews – including those labelled as "verified" – were genuine, and allowed companies to invite specifically selected customers to leave reviews via paid services, which undermined the representativeness of the star ratings. In addition, information on how the platform works and on paid services was lacking; the authority also saw dark pattern elements in this.

What organisations can take from it

Anyone who advertises with verified reviews must actually carry out the verification and disclose the selective collection of reviews.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Artt. 20, 21, 22 e 23, comma 1, lett. bb-ter Codice del Consumo
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
23 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 SIA "SS"Classifieds portal ss.lv blocked users of competitor – fine of 186,781 EUR LatviaAbuse of market power €186,781

From March 2020 to May 2021, the operator of ss.lv/ss.com (market share over 60%) deleted advertisements and blocked accounts of users – mainly car dealers and estate agents – who also advertised on the competing platform pp.lv; anyone wishing to register with an inbox.lv address additionally had to provide a different e-mail address. The Konkurences padome (Latvian Competition Council) considered this an abuse of a dominant position (Art. 102 TFEU), imposed 186,780.65 EUR and required objective criteria for dealing with customers.

What organisations can take from it

Market-leading platforms must not punish users for multi-homing – internal moderation rules need objective criteria.

Relevance to training and awareness

Competition law limits in dealing with competitors’ customers

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
18 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 DPG Media nv; Mediahuis nv; PPP Belgium bv; bpost nv (Kronzeuge)Press concession: 11.9 million EUR for collusion in newspaper delivery tender BelgiumCartels and collusion €11.9m

So that bpost would obtain the state concession for newspaper delivery for 2023–2027, its competitor PPP refrained from submitting a bid and in return received additional delivery volumes from DPG Media and Mediahuis (bid rigging). In a settlement procedure, the Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (Belgian Competition Authority, BMA) imposed 3,786,574 EUR (DPG Media), 7,788,423 EUR (Mediahuis) and 323,486 EUR (PPP); bpost, as leniency applicant, received full immunity, and two bpost employees involved were fined a total of 6,300 EUR.

What organisations can take from it

Agreements on who participates in a tender are hardcore cartels – individuals are also liable, and leniency applicants benefit.

Relevance to training and awareness

Collusion in public tenders

Authority / court
Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (BMA)
Area of law
Competition law · Cartels and collusion
Legal basis
Code de droit économique Art. IV.1; AEUV Art. 101
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Leniency programme (immunity for bpost; reductions of 50% and 40% for DPG Media and Mediahuis respectively) and 10% settlement reduction.
Liability of senior managers
First-ever fines against two natural persons (employed by bpost), totalling 6,300 EUR.
Published
13 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository EU levelPlatform obligations €120m

First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.

What organisations can take from it

Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
5 Dec 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository EU levelPlatform obligations Order

Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.

What organisations can take from it

Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts EU levelData subject rights and transparency —

On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.

What organisations can take from it

Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.

Authority / court
Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
Status of proceedings
unknown
Sector
Media and online platforms
Published
2 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent FranceCookies and tracking €750,000

On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.

What organisations can take from it

A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Published
27 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Oct 2025 MM Grupp OÜCinema chain MM Grupp (Apollo) took over Forum Cinemas without clearance – 7.5 million EUR LithuaniaMerger control €7.51m

In 2021, the Estonian parent company of Apollo cinemas acquired control of Forum Cinemas Lithuania before the notified merger had been cleared and integrated the cinemas in Vilnius and Kaunas into its network, even though the Konkurencijos taryba (Lithuanian Competition Council) had provisionally expressed competition concerns. Fine of 7,507,930 EUR (0.8% of consolidated worldwide turnover) and obligation to end the infringement within six months. Source: archived copy of the press release.

What organisations can take from it

No implementation before clearance: restructurings and leases can also constitute prohibited early implementation.

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Merger control
Legal basis
Konkurencijos įstatymas (Vollzugsverbot bei Zusammenschlüssen)
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
30 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Oct 2025 WhatsApp Ireland Limited (Dienst „Channels“) und PinterestWhatsApp (Channels) and Pinterest: designated as ‘exposed to terrorist content’ IrelandPlatform obligations Order

After both hosting services had received at least two final removal orders from EU authorities within twelve months, Coimisiún na Meán (Ireland’s media and online safety regulator) designated them as exposed to terrorist content under the TCO Regulation. They must take specific protective measures and report on them within three months; the regulator assesses their effectiveness.

What organisations can take from it

Repeated removal orders trigger additional, monitored prevention obligations for platforms – content moderation must be prepared for this.

Authority / court
Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam AustriaIncident reporting obligations €870

Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.

What organisations can take from it

External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.

Relevance to training and awareness

Recognising and escalating alerts about security gaps

Missing or inadequate training played a role in the decision.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Google LLC und Google Ireland LimitedGoogle: 325 million EUR – advertising cookies at account creation and ads in the Gmail inbox FranceCookies and tracking €325m

When creating a Google account, users were not sufficiently informed that advertising cookies were necessarily placed in the process; in addition, Google displayed advertisements between e-mails in Gmail without prior consent. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 200 million EUR on Google LLC and 125 million EUR on Google Ireland and ordered remedial action within six months, subject to a penalty payment of 100,000 EUR per day.

What organisations can take from it

Do not tacitly tie advertising cookies to account creation – and advertising in the inbox counts as direct marketing requiring consent.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés; Art. L. 34-5 Code des postes et des communications électroniques
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner AustriaCookies and tracking €6,200

In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.

What organisations can take from it

Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China IrelandInternational data transfers €530m

TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.

What organisations can take from it

Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · International data transfers
Legal basis
Art. 46 Abs. 1, Art. 13 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
2 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Load 11 more of 11

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial