Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

Public sector Clear all filters
28cases from 14 jurisdictions
€15.4mTotal of monetary amounts (23 cases with an amount)
€7.86mLargest single case: AS "Latvijas valsts meži"
€12,350Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231—
Q1 20241€7,000
Q2 20241€26,803
Q3 20241€898,979
Q4 20243€11,000
Q1 20252€9,200
Q2 20254€580,979
Q3 20252€6,000
Q4 20253€194,938
Q1 20264€5.17m
Q2 20261—
Q3 20265€8.52m

28 cases

4 Aug 2026 AS "Latvijas valsts meži"7.86 million EUR against Latvijas valsts meži for breach of competitive neutrality LatviaCompetition law €7.86m

From 2020 to April 2026, on the basis of old long-term logging contracts, the state forestry group supplied six wood processors with guaranteed quantities of roundwood outside public auctions, while all others could only buy through auctions. In its first decision on the competitive neutrality of public undertakings, the Konkurences padome (Latvian Competition Council) imposed 7,859,606.89 EUR and required equal sales conditions for all qualified bidders.

What organisations can take from it

State-owned companies must allocate resources without discrimination – review historical special contracts regularly for competitive neutrality.

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law
Legal basis
Art. 14.1 Konkurences likums (Wettbewerbsneutralität)
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
13 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker CzechiaOther €12,350

In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.

What organisations can take from it

External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.

Relevance to training and awareness

Conflicts of interest of external advisers in procurement procedures

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Other
Legal basis
Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Published
15 Sep 2026

Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator ItalyVideo surveillance €8,000

Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.

What organisations can take from it

Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records IrelandData breaches and data security €645,000

In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.

What organisations can take from it

Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.

Relevance to training and awareness

Physical security and retention of paper records

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector
Employees
10,000 or more
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Jul 2026 Metropolitan Police ServiceICO: order and reprimand against London's Met Police after disclosure of sensitive data United KingdomData breaches and data security Order

The Metropolitan Police handed a defendant unredacted documents containing the new address and telephone number of a stalking victim, and in a circular e-mail disclosed 18 people with a parliamentary connection in an open recipient list. The UK Information Commissioner's Office (ICO) ordered improvements within 3 and 12 months, including in data protection training completion rates.

What organisations can take from it

Policies are not enough if mandatory training goes uncompleted for years – monitor and enforce training completion rates.

Relevance to training and awareness

Redacting documents, e-mail distribution lists (BCC), data protection training

Missing or inadequate training played a role in the decision.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Data Protection Act 2018, Section 40
Action
Order
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Culpability
negligent
Published
5 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers CanadaData breaches and data security Other

Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.

What organisations can take from it

Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act (Kanada)
Action
Other
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
7 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack FranceData breaches and data security €5m

In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.

What organisations can take from it

Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.

Relevance to training and awareness

Social engineering and account takeover

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 Derbyshire ConstabularyDerbyshire Constabulary: 60,000 GBP after burn injuries during Molotov cocktail training United KingdomWorkplace safety and accidents €69,196

During a public order training exercise in February 2021, police officers wearing flame-retardant protective clothing had petrol bombs thrown at them; four officers suffered burns with permanent scarring. There was no information on the service life and testing of the PPE, no risk assessment for the manufacture and use of the petrol bombs, and no safe systems of work. The Health and Safety Executive (HSE) prosecution resulted in a fine of 60,000 GBP plus 9,470 GBP in costs.

What organisations can take from it

Realistic operational training also needs a risk assessment and tested protective equipment.

Relevance to training and awareness

Safety in high-risk exercises and PPE testing

Authority / court
Health and Safety Executive (Sheffield Magistrates' Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Health and Safety at Work etc. Act 1974, s. 2(1)
Action
Fine
Status of proceedings
final
Sector
Public sector
Published
20 Jan 2026

Original amount 60,000 GBP, converted at the ECB reference rate of 19 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Glasgow City CouncilGlasgow City Council: 80,000 GBP after collapse of a rusted-through lamp post United KingdomWorkplace safety and accidents €92,092

In June 2023, a lamp post dating from the 1950s/60s, whose steel at the base was at least 60 % rusted through, fell over and seriously injured a pedestrian. The post had been rated as poor in 2022 but was not scheduled for replacement until 2024; the council's visual inspections did not identify the acute risk of collapse. The Health and Safety Executive (HSE) prosecution resulted in a fine of 80,000 GBP.

What organisations can take from it

Inspection regimes for ageing infrastructure must prioritise findings and trigger immediate action where there is acute danger.

Authority / court
Health and Safety Executive (Glasgow Sheriff Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Health and Safety at Work etc. Act 1974, s. 3(1)
Action
Fine
Status of proceedings
final
Sector
Public sector
Published
12 Jan 2026

Original amount 80,000 GBP, converted at the ECB reference rate of 8 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log GreeceEmployee data €10,000

In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.

What organisations can take from it

Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.

Relevance to training and awareness

Confidential handling of employees’ health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack NetherlandsData breaches and data security €175,000

In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.

What organisations can take from it

Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Mitigating circumstances
Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees ItalyVideo surveillance €15,000

The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).

What organisations can take from it

Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.

Relevance to training and awareness

Purpose limitation in video surveillance and employee data

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 5, 6, 12, 13, 35, 88
Action
Fine
Status of proceedings
final
Sector
Public sector
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified PolandIncident reporting obligations €4,938

In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.

What organisations can take from it

Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.

Relevance to training and awareness

Checking postal mailings; notifying data breaches involving identification numbers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB EU levelData subject rights and transparency —

The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.

What organisations can take from it

Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.

Authority / court
Gerichtshof der Europäischen Union, Rs. C-413/23 P
Area of law
Data protection · Data subject rights and transparency
Legal basis
Verordnung (EU) 2018/1725 (Informationspflicht)
Status of proceedings
under appeal
Sector
Public sector
Published
4 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jul 2025 Slovenský pozemkový fondSlovak Land Fund: 6,000 EUR for late examination of a whistleblower report SlovakiaMissing or inadequate reporting channel €6,000

The state land fund examined a report from September 2022 only after 128 days and, until November 2024, did not sufficiently inform employees about the reporting procedure, protection options and the responsible person. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 6,000 EUR.

What organisations can take from it

Whistleblower reports are subject to statutory examination deadlines – anyone who misses them and does not publicise the procedure will be sanctioned.

Relevance to training and awareness

Deadlines and transparency in the internal reporting system

Authority / court
Úrad na ochranu oznamovateľov (Slowakei)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
§ 10 Abs. 5 und 8, § 19 Gesetz Nr. 54/2019 über den Schutz von Hinweisgebern (UOO-277/2025)
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Culpability
negligent

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2025 Ústredie práce, sociálnych vecí a rodinyCentral Office ÚPSVaR: 5,000 EUR – reporting office for children’s homes not operated SlovakiaMissing or inadequate reporting channel €5,000

For months, the central authority failed to perform the tasks of the reporting office for three centres for children and families under its authority and did not make the responsible person known to employees. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 5,000 EUR; the appeal decision of 12 September 2025 reworded the operative part but left the fine at 5,000 EUR.

What organisations can take from it

Anyone running the reporting office for subordinate units must also make it visible there and handle reports from those units.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 3 und 5, § 19 Abs. 3
Action
Fine
Status of proceedings
final
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2025 Department of Social Protection (DSP)DPC: 550,000 EUR against Irish social protection ministry over facial matching without legal basis IrelandData subject rights and transparency €550,000

For registration for the Public Services Card, the ministry created biometric facial templates of a large part of the population without a sufficiently clear legal basis, with deficient information and an incomplete data protection impact assessment. Ireland's Data Protection Commission (DPC) issued a reprimand, imposed 550,000 EUR and ordered the biometric processing to be stopped within nine months if no valid legal basis is found.

What organisations can take from it

Biometric procedures require a precise statutory basis and a complete impact assessment before they are rolled out widely.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und e, Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 Abs. 7 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Mitigating circumstances
No deficiencies were found in the technical and organisational security measures.
Published
12 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2025 Ville de LongueuilCity of Longueuil pays 30,000 CAD for mowing that destroyed a protected bird's nest Canada, QCEnvironment and sustainability €18,979

During mowing work in the municipal Parc des Sorbiers in July 2024, at least one nest of the protected bobolink was destroyed; a citizen reported the find. The city pleaded guilty under the Species at Risk Act and is paying 30,000 CAD.

What organisations can take from it

Maintenance plans for green spaces must take into account the breeding seasons of protected species, and the teams carrying out the work must be briefed accordingly.

Relevance to training and awareness

Species protection in green space maintenance

Authority / court
Court of Québec (Anklage: Environment and Climate Change Canada)
Area of law
Environment and sustainability
Legal basis
Species at Risk Act, s. 33
Action
Fine
Status of proceedings
final
Sector
Public sector
Published
12 Jun 2025

Original amount 30,000 CAD, converted at the ECB reference rate of 12 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2025 Slovenské národné múzeumSlovak National Museum: 7,000 EUR – employees not informed about reporting system SlovakiaMissing or inadequate reporting channel €7,000

The museum published no information on the protection options or on the external reporting channel and could not prove that employees were familiar with the internal reporting rules – there were no signature lists and no proof of intranet access. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 7,000 EUR.

What organisations can take from it

Informing employees about the reporting system must be documented – without proof, it is deemed not to have taken place.

Relevance to training and awareness

Informing employees about internal and external reporting channels

Missing or inadequate training played a role in the decision.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 5, § 19 Abs. 3
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Feb 2025 Obec SološnicaMunicipality of Sološnica: 200 EUR – contradictory reporting rules and missing information on protection SlovakiaMissing or inadequate reporting channel €200

The municipality did not publish any information on the protection available to whistleblowers and at times had two valid, contradictory sets of rules on the internal reporting procedure online without stating which applied. The Office imposed a fine of 200 EUR.

What organisations can take from it

Reporting rules must be unambiguous and up to date – remove outdated versions from the internet.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 5, § 19 Abs. 2
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jan 2025 Užimtumo tarnyba prie Lietuvos Respublikos socialinės apsaugos ir darbo ministerijosEmployment service sends Excel file with data of 29,636 clients – 9,000 EUR LithuaniaData breaches and data security €9,000

An employee accidentally attached an Excel file containing data of 29,636 clients, including health data, to an e-mail sent to 292 clients. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that measures to prevent data leakage had not been sufficiently tested and that the employee had not been involved in data classification and had been insufficiently instructed; fine of 9,000 EUR. Date = publication; source: archived copy.

What organisations can take from it

One wrong attachment is enough for a mass data breach – DLP tools only help if all employees are trained and involved.

Relevance to training and awareness

Checking e-mail attachments, data classification

Missing or inadequate training played a role in the decision.

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
21 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts DenmarkData breaches and data security Other

At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.

What organisations can take from it

Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.

Relevance to training and awareness

Offboarding, access rights and multi-factor authentication

Authority / court
Datatilsynet
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 32
Action
Other
Status of proceedings
unknown
Sector
Public sector
Published
27 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Nov 2024 Správa účelových zariadeníState body SÚZ: 2,000 EUR – no reporting office of its own, channels not published SlovakiaMissing or inadequate reporting channel €2,000

Instead of designating its own responsible person, the body subordinate to the Ministry of Foreign Affairs, with at least 50 employees, had named the ministry’s secretary general and had not published the reporting channels in a way accessible to all employees. The Office imposed 2,000 EUR.

What organisations can take from it

Every obliged organisation needs its own reporting office that is known internally – the responsibility of the parent body is not sufficient.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 1 und 5, § 19 Abs. 2
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Oct 2024 Vilniaus rajono savivaldybės administracijaRansomware attack on Vilnius district administration – data protection fine of 9,000 EUR LithuaniaData breaches and data security €9,000

Following a break-in into the district administration’s servers in which data were encrypted, services failed and social benefits were delayed. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found insufficient malware protection, deficient management of rights and passwords, a lack of recovery and insufficient information of data subjects and imposed 9,000 EUR. Date = publication; source: archived copy.

What organisations can take from it

Backups, patch management and password rules are a data protection duty for public authorities too – and data subjects must receive specific advice on protecting themselves.

Relevance to training and awareness

Password security, ransomware preparedness

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. b, c und d, Art. 34 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
18 Oct 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2024 Police Service of Northern Ireland (PSNI)ICO: £750,000 against Northern Ireland police after spreadsheet error in FOI response United KingdomData breaches and data security €898,979

In its response to a freedom of information request, the Police Service of Northern Ireland (PSNI) published an Excel file whose hidden worksheet contained the surnames, initials, rank and role of all 9,483 employees. The file was visible for just over two hours and was deleted after almost three hours; the police assumed that it had fallen into the hands of dissident republicans.

What organisations can take from it

Before releasing any file, check for hidden sheets, metadata and raw data – a four-eyes approval process prevents such breaches.

Relevance to training and awareness

Checking files before publication (hidden worksheets)

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Employees
1,000 to 9,999
Culpability
negligent
Mitigating circumstances
Application of the public sector approach; without it, the fine would have been £5.6 million.
Published
3 Oct 2024

Original amount 750,000 GBP, converted at the ECB reference rate of 26 Sep 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2024 Hvidovre KommuneHvidovre Kommune: 200,000 DKK after disclosing protected addresses of children to parents DenmarkData breaches and data security €26,803

Following a system change, both parents with custody gained access to letters from the municipal dental care service and automatically received letters containing, in some cases, protected addresses of the children – without any check as to whether the disclosure was permissible. The Danish Data Protection Agency (Datatilsynet) criticised the lack of change management; the municipality accepted a fine notice of 200,000 DKK.

What organisations can take from it

Whenever access rights or automated mailing processes are changed, check in advance who will see which data afterwards.

Relevance to training and awareness

Change management for IT systems holding sensitive data

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector

Original amount 200,000 DKK, converted at the ECB reference rate of 27 May 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jan 2024 Ministerstvo životného prostredia Slovenskej republikySlovak Ministry of the Environment: 7,000 EUR – reporting office existed only on paper SlovakiaMissing or inadequate reporting channel €7,000

From February 2021 to July 2023, the ministry had designated as the office responsible for reports an ‘anti-corruption unit’ that did not even exist in the organisational structure. A report from April 2022 had still not been examined at the time of the inspection in May 2023; the ministry’s appeal was unsuccessful on 22 April 2024.

What organisations can take from it

A reporting office must actually be staffed – responsibility on paper does not fulfil the statutory obligation.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 1, 4, 5 und 7, § 19 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Dec 2023 Natsionalna agentsia za prihodite (NAP, bulgarische Steuerbehörde)CJEU: after hacker attack, Bulgaria's tax authority must prove adequate security EU levelData breaches and data security —

Following a cyber attack in 2019, data on millions of people from the IT system of the Bulgarian tax authority (Natsionalna agentsia za prihodite, NAP) was published on the internet. The Court of Justice of the European Union (Case C-340/21) ruled that the controller must prove the adequacy of its protective measures, can be liable even for attacks by third parties, and that the mere fear of misuse of data can constitute non-material damage.

What organisations can take from it

After an attack, the company bears the burden of proving adequate security – documenting the measures protects against liability.

Authority / court
Gerichtshof der Europäischen Union, Rs. C-340/21
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 24, Art. 32, Art. 82
Status of proceedings
unknown
Sector
Public sector
Published
14 Dec 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial