Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- TikTok Technology Limited €530m 27 % · 1 case
- Booking.com €413.2m 21 % · 1 case
- Meta Platforms Ireland Limited €342m 17 % · 3 cases
- Google LLC und Google Ireland Limited €325m 17 % · 1 case
- Meta €200m 10 % · 1 case
- X €120m 6 % · 1 case
- DPG Media nv; Mediahuis nv; PPP Belgium bv; bpost nv (Kronzeuge) €11.9m 1 % · 1 case
- MM Grupp OÜ €7.51m 0 % · 1 case
- Netflix International B.V. €4.75m 0 % · 1 case
- Trustpilot Group Plc, Trustpilot A/S, Trustpilot S.r.l. €4m 0 % · 1 case
- 18 more€5.37m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €870 |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
1 case
4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam €870
Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.
External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.
Recognising and escalating alerts about security gaps
Missing or inadequate training played a role in the decision.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- negligent
- Mitigating circumstances
- No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.
- DSB, Straferkenntnis GZ 2025-0.699.550 vom 04.09.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link