Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet €26,803 100 % · 1 case
- Datatilsynet — 0 % · 1 case
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | €26,803 |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
2 cases
27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts Other
At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.
Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.
Offboarding, access rights and multi-factor authentication
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 27 Nov 2024
- Datatilsynet anmelder Lyngby-Taarbæk Kommune til politiet Decision of an authority
- Datatilsynet: Bødesager (Lyngby-Taarbæk Kommune unter „Sager, der fortsat verserer“) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2024 Hvidovre KommuneHvidovre Kommune: 200,000 DKK after disclosing protected addresses of children to parents €26,803
Following a system change, both parents with custody gained access to letters from the municipal dental care service and automatically received letters containing, in some cases, protected addresses of the children – without any check as to whether the disclosure was permissible. The Danish Data Protection Agency (Datatilsynet) criticised the lack of change management; the municipality accepted a fine notice of 200,000 DKK.
Whenever access rights or automated mailing processes are changed, check in advance who will see which data afterwards.
Change management for IT systems holding sensitive data
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
Original amount 200,000 DKK, converted at the ECB reference rate of 27 May 2024.
- Datatilsynet – Hvidovre Kommune indstilles til bøde (Opdatering: afgjort 27. maj 2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link