Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- AS "Latvijas valsts meži" €7.86m 55 % · 1 case
- France Travail €5m 35 % · 1 case
- Health Service Executive (HSE) €645,000 4 % · 1 case
- Department of Social Protection (DSP) €550,000 4 % · 1 case
- Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences) €175,000 1 % · 1 case
- Hvidovre Kommune €26,803 0 % · 1 case
- Comune di Curtarolo €15,000 0 % · 1 case
- Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik) €12,350 0 % · 1 case
- Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr) €10,000 0 % · 1 case
- Užimtumo tarnyba prie Lietuvos Respublikos socialinės apsaugos ir darbo ministerijos €9,000 0 % · 1 case
- 12 more€49,138
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | — |
| Q1 2024 | 1 | €7,000 |
| Q2 2024 | 1 | €26,803 |
| Q3 2024 | 0 | — |
| Q4 2024 | 3 | €11,000 |
| Q1 2025 | 2 | €9,200 |
| Q2 2025 | 3 | €562,000 |
| Q3 2025 | 2 | €6,000 |
| Q4 2025 | 3 | €194,938 |
| Q1 2026 | 2 | €5.01m |
| Q2 2026 | 0 | — |
| Q3 2026 | 4 | €8.52m |
22 cases
4 Aug 2026 AS "Latvijas valsts meži"7.86 million EUR against Latvijas valsts meži for breach of competitive neutrality €7.86m
From 2020 to April 2026, on the basis of old long-term logging contracts, the state forestry group supplied six wood processors with guaranteed quantities of roundwood outside public auctions, while all others could only buy through auctions. In its first decision on the competitive neutrality of public undertakings, the Konkurences padome (Latvian Competition Council) imposed 7,859,606.89 EUR and required equal sales conditions for all qualified bidders.
State-owned companies must allocate resources without discrimination – review historical special contracts regularly for competitive neutrality.
- Authority / court
- Konkurences padome (Lettischer Wettbewerbsrat)
- Area of law
- Competition law
- Legal basis
- Art. 14.1 Konkurences likums (Wettbewerbsneutralität)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 13 Aug 2026
- Konkurences padome konstatē konkurences neitralitātes pārkāpumu AS „Latvijas valsts meži“ darbībā (13.08.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker €12,350
In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.
External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.
Conflicts of interest of external advisers in procurement procedures
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Other
- Legal basis
- Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Published
- 15 Sep 2026
Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.
- ÚOHS uložil pokutu 300 tisíc korun resortu životního prostředí kvůli neošetření možného střetu zájmů Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator €8,000
Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.
Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante – Provvedimento n. 619 del 3 settembre 2026 [10294255] (ASIS Trento) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack €5m
In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.
Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.
Social engineering and account takeover
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 29 Jan 2026
- Violation de données : sanction de 5 millions d'euros à l'encontre de FRANCE TRAVAIL Press release of an authority
- CNIL – Les sanctions prononcées par la CNIL (Eintrag 22/01/2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log €10,000
In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.
Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.
Confidential handling of employees’ health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Απόφαση 1/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack €175,000
In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.
Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
- Published
- 17 Dec 2025
- HAN krijgt boete van 175.000 euro voor onvoldoende beveiliging van persoonsgegevens Press release of an authority
- Boete HAN Decision of an authority
- AP: Besluit tot oplegging van een bestuurlijke boete aan Stichting Hogeschool van Arnhem en Nijmegen Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees €15,000
The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).
Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.
Purpose limitation in video surveillance and employee data
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 5, 6, 12, 13, 35, 88
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Provvedimento del 23 ottobre 2025 [10196164] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified €4,938
In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.
Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.
Checking postal mailings; notifying data breaches involving identification numbers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.
- UODO, Decyzja DKN.5131.17.2024 vom 23.10.2025 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB —
The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.
Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-413/23 P
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Verordnung (EU) 2018/1725 (Informationspflicht)
- Status of proceedings
- under appeal
- Sector
- Public sector
- Published
- 4 Sep 2025
- Press Release No 107/25: Judgment of the Court in Case C-413/23 P EDPS v SRB Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jul 2025 Slovenský pozemkový fondSlovak Land Fund: 6,000 EUR for late examination of a whistleblower report €6,000
The state land fund examined a report from September 2022 only after 128 days and, until November 2024, did not sufficiently inform employees about the reporting procedure, protection options and the responsible person. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 6,000 EUR.
Whistleblower reports are subject to statutory examination deadlines – anyone who misses them and does not publicise the procedure will be sanctioned.
Deadlines and transparency in the internal reporting system
- Authority / court
- Úrad na ochranu oznamovateľov (Slowakei)
- Area of law
- Whistleblower protection · Missing or inadequate reporting channel
- Legal basis
- § 10 Abs. 5 und 8, § 19 Gesetz Nr. 54/2019 über den Schutz von Hinweisgebern (UOO-277/2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Culpability
- negligent
- Rozhodnutie ÚOO z 24. 7. 2025, UOO-277/2025 (Slovenský pozemkový fond) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jun 2025 Ústredie práce, sociálnych vecí a rodinyCentral Office ÚPSVaR: 5,000 EUR – reporting office for children’s homes not operated €5,000
For months, the central authority failed to perform the tasks of the reporting office for three centres for children and families under its authority and did not make the responsible person known to employees. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 5,000 EUR; the appeal decision of 12 September 2025 reworded the operative part but left the fine at 5,000 EUR.
Anyone running the reporting office for subordinate units must also make it visible there and handle reports from those units.
- Authority / court
- Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
- Area of law
- Whistleblower protection · Missing or inadequate reporting channel
- Legal basis
- Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 3 und 5, § 19 Abs. 3
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- ÚOO, Rozhodnutie vom 16.06.2025 (UOO-104/2025), ÚPSVaR Decision of an authority
- ÚOO, Berufungsentscheidung vom 12.09.2025 Decision of an authority
- Úrad na ochranu oznamovateľov: Rozhodnutia úradu (Liste der Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2025 Department of Social Protection (DSP)DPC: 550,000 EUR against Irish social protection ministry over facial matching without legal basis €550,000
For registration for the Public Services Card, the ministry created biometric facial templates of a large part of the population without a sufficiently clear legal basis, with deficient information and an incomplete data protection impact assessment. Ireland's Data Protection Commission (DPC) issued a reprimand, imposed 550,000 EUR and ordered the biometric processing to be stopped within nine months if no valid legal basis is found.
Biometric procedures require a precise statutory basis and a complete impact assessment before they are rolled out widely.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und e, Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 Abs. 7 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Mitigating circumstances
- No deficiencies were found in the technical and organisational security measures.
- Published
- 12 Jun 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2025 Slovenské národné múzeumSlovak National Museum: 7,000 EUR – employees not informed about reporting system €7,000
The museum published no information on the protection options or on the external reporting channel and could not prove that employees were familiar with the internal reporting rules – there were no signature lists and no proof of intranet access. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 7,000 EUR.
Informing employees about the reporting system must be documented – without proof, it is deemed not to have taken place.
Informing employees about internal and external reporting channels
Missing or inadequate training played a role in the decision.
- Authority / court
- Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
- Area of law
- Whistleblower protection · Missing or inadequate reporting channel
- Legal basis
- Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 5, § 19 Abs. 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- ÚOO, Rozhodnutie vom 09.04.2025 (UOO-195/2025), Slovenské národné múzeum Decision of an authority
- Úrad na ochranu oznamovateľov: Rozhodnutia úradu (Liste der Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Feb 2025 Obec SološnicaMunicipality of Sološnica: 200 EUR – contradictory reporting rules and missing information on protection €200
The municipality did not publish any information on the protection available to whistleblowers and at times had two valid, contradictory sets of rules on the internal reporting procedure online without stating which applied. The Office imposed a fine of 200 EUR.
Reporting rules must be unambiguous and up to date – remove outdated versions from the internet.
- Authority / court
- Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
- Area of law
- Whistleblower protection · Missing or inadequate reporting channel
- Legal basis
- Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 5, § 19 Abs. 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- ÚOO, Rozhodnutie vom 14.02.2025 (UOO-178/2025), Obec Sološnica Decision of an authority
- Úrad na ochranu oznamovateľov: Rozhodnutia úradu (Liste der Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jan 2025 Užimtumo tarnyba prie Lietuvos Respublikos socialinės apsaugos ir darbo ministerijosEmployment service sends Excel file with data of 29,636 clients – 9,000 EUR €9,000
An employee accidentally attached an Excel file containing data of 29,636 clients, including health data, to an e-mail sent to 292 clients. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that measures to prevent data leakage had not been sufficiently tested and that the employee had not been involved in data classification and had been insufficiently instructed; fine of 9,000 EUR. Date = publication; source: archived copy.
One wrong attachment is enough for a mass data breach – DLP tools only help if all employees are trained and involved.
Checking e-mail attachments, data classification
Missing or inadequate training played a role in the decision.
- Authority / court
- Valstybinė duomenų apsaugos inspekcija (VDAI)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 21 Jan 2025
- VDAI, Užimtumo tarnybai skirta bauda, 2025-01-21 (Archivkopie web.archive.org von vdai.lrv.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts Other
At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.
Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.
Offboarding, access rights and multi-factor authentication
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 27 Nov 2024
- Datatilsynet anmelder Lyngby-Taarbæk Kommune til politiet Decision of an authority
- Datatilsynet: Bødesager (Lyngby-Taarbæk Kommune unter „Sager, der fortsat verserer“) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Nov 2024 Správa účelových zariadeníState body SÚZ: 2,000 EUR – no reporting office of its own, channels not published €2,000
Instead of designating its own responsible person, the body subordinate to the Ministry of Foreign Affairs, with at least 50 employees, had named the ministry’s secretary general and had not published the reporting channels in a way accessible to all employees. The Office imposed 2,000 EUR.
Every obliged organisation needs its own reporting office that is known internally – the responsibility of the parent body is not sufficient.
- Authority / court
- Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
- Area of law
- Whistleblower protection · Missing or inadequate reporting channel
- Legal basis
- Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 1 und 5, § 19 Abs. 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- ÚOO, Rozhodnutie vom 11.11.2024 (UOO-404/2024), Správa účelových zariadení Decision of an authority
- Úrad na ochranu oznamovateľov: Rozhodnutia úradu (Liste der Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Oct 2024 Vilniaus rajono savivaldybės administracijaRansomware attack on Vilnius district administration – data protection fine of 9,000 EUR €9,000
Following a break-in into the district administration’s servers in which data were encrypted, services failed and social benefits were delayed. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found insufficient malware protection, deficient management of rights and passwords, a lack of recovery and insufficient information of data subjects and imposed 9,000 EUR. Date = publication; source: archived copy.
Backups, patch management and password rules are a data protection duty for public authorities too – and data subjects must receive specific advice on protecting themselves.
Password security, ransomware preparedness
- Authority / court
- Valstybinė duomenų apsaugos inspekcija (VDAI)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. b, c und d, Art. 34 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 18 Oct 2024
- VDAI, Vilniaus rajono savivaldybės administracijai skirta bauda, 2024-10-18 (Archivkopie web.archive.org) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2024 Hvidovre KommuneHvidovre Kommune: 200,000 DKK after disclosing protected addresses of children to parents €26,803
Following a system change, both parents with custody gained access to letters from the municipal dental care service and automatically received letters containing, in some cases, protected addresses of the children – without any check as to whether the disclosure was permissible. The Danish Data Protection Agency (Datatilsynet) criticised the lack of change management; the municipality accepted a fine notice of 200,000 DKK.
Whenever access rights or automated mailing processes are changed, check in advance who will see which data afterwards.
Change management for IT systems holding sensitive data
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
Original amount 200,000 DKK, converted at the ECB reference rate of 27 May 2024.
- Datatilsynet – Hvidovre Kommune indstilles til bøde (Opdatering: afgjort 27. maj 2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link