Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
€26,803Total of monetary amounts (1 case with an amount)
€26,803Largest single case: Hvidovre Kommune
€26,803Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet €26,803 100 % · 1 case
  2. Datatilsynet — 0 % · 1 case

What for?

by area of law

All areas of law

  1. Data protection €26,803 100 % · 2 cases

Who?

by company
  1. Hvidovre Kommune €26,803 100 % · 1 case
  2. Lyngby-Taarbæk Kommune — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€26,803
Q3 20240—
Q4 20241—
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20260—

2 cases

27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts DenmarkData breaches and data security Other

At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.

What organisations can take from it

Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.

Relevance to training and awareness

Offboarding, access rights and multi-factor authentication

Authority / court
Datatilsynet
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 32
Action
Other
Status of proceedings
unknown
Sector
Public sector
Published
27 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2024 Hvidovre KommuneHvidovre Kommune: 200,000 DKK after disclosing protected addresses of children to parents DenmarkData breaches and data security €26,803

Following a system change, both parents with custody gained access to letters from the municipal dental care service and automatically received letters containing, in some cases, protected addresses of the children – without any check as to whether the disclosure was permissible. The Danish Data Protection Agency (Datatilsynet) criticised the lack of change management; the municipality accepted a fine notice of 200,000 DKK.

What organisations can take from it

Whenever access rights or automated mailing processes are changed, check in advance who will see which data afterwards.

Relevance to training and awareness

Change management for IT systems holding sensitive data

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector

Original amount 200,000 DKK, converted at the ECB reference rate of 27 May 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial