Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,929 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Anonymised companies 25 cases 36 % · €1.72m
- Glasgow City Council 2 cases 3 % · €92,092
- Greater Manchester Police 2 cases 3 % ·
- ACRO Criminal Records Office 1 case 1 % ·
- AS "Latvijas valsts meži" 1 case 1 % · €7.86m
- ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento) 1 case 1 % · €8,000
- Bristol City Council 1 case 1 % ·
- Canada Revenue Agency (CRA) 1 case 1 % ·
- Cardiff University 1 case 1 % · €323,232
- City of Edinburgh Council 1 case 1 % ·
- 33 more33 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €98,000 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Dec 2025 University of LimerickDPC: €98,000 fine against University of Limerick after phishing of staff mailboxes €98,000
Between 2018 and 2020 the university notified twelve personal data breaches, six of which involved unauthorised persons gaining access to staff email accounts through phishing and in some cases setting up forwarding rules. The DPC found infringements of Art. 5(1)(f), 30(1), 32(1), 33(1) and 34(1) GDPR, issued a reprimand and imposed fines of €45,000, €3,000, €35,000 and €15,000, totalling €98,000.
Phishing protection for mailboxes and clear internal reporting channels determine whether data breaches are reported to the authority and affected persons on time.
Recognising phishing and reporting data breaches within 72 hours
Missing or inadequate training played a role in the decision.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5(1)(f), 30(1), 32(1), 33(1), 34(1) DSGVO; ss. 110–111 Data Protection Act 2018
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Mitigating circumstances
- The university accepted most of the findings, acknowledged responsibility and improved its systems, training and policies; the fines are well below those in the draft and no remedial order was made.
- DPC: Inquiry concerning the University of Limerick (IN-19-7-1) Decision of an authority
Checked against the official source on 2 Oct 2026 · Direct link