Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,918 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- AS "Latvijas valsts meži" €7.86m 50 % · 1 case
- France Travail €5m 32 % · 1 case
- Health Service Executive (HSE) €645,000 4 % · 1 case
- Department of Social Protection (DSP) €550,000 4 % · 1 case
- Anonymised companies €410,751 3 % · 8 cases
- Ελληνική Εταιρεία Τοπικής Ανάπτυξης και Αυτοδιοίκησης Α.Ε. (EETAA) und Υπουργείο Κοινωνικής Συνοχής και Οικογένειας €350,000 2 % · 1 case
- Gemeenten Delft, Ede, Eindhoven u. a. (10 Gemeinden) €250,000 2 % · 1 case
- Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences) €175,000 1 % · 1 case
- University of Limerick €98,000 1 % · 1 case
- Ministerstvo vnútra Slovenskej republiky €70,000 0 % · 1 case
- 16 more€155,407
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 1 | €66,919 |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
23 Mar 2026 Region SyddanmarkRegion Syddanmark: GDPR fine over exposed research database halved on appeal €66,919
In December 2024 the Kolding City Court fined the Region Syddanmark (Region of Southern Denmark) 1,000,000 DKK for two breaches of the duty to ensure appropriate data security. On 23 March 2026 the Vestre Landsret (Western High Court) upheld only the first charge – in a research and clinical database, logged-in users could access PDF documents of more than 23,000 registered persons, including health data of minors in psychiatric care, by changing the URL – and reduced the fine to 500,000 DKK; it acquitted the region of the charge concerning patient data in a presentation on its website.
Access rights must be checked server-side for every document; an editable URL is not access control.
Access control in web applications (manipulable URLs)
- Authority / court
- Retten i Kolding; Vestre Landsret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, Art. 83 Abs. 4 lit. a und Abs. 9 DSGVO; databeskyttelseslovens § 41 stk. 1 nr. 1, stk. 3 og 6
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Public sector
- Culpability
- negligent
- Repeat case
- yes
Original amount 500,000 DKK, converted at the ECB reference rate of 23 Mar 2026.
- Datatilsynet: Region Syddanmark indstilles til bøde (2021, mit Update zu Byret und Landsret) Press release of an authority
- Retten i Kolding, dom 23.12.2024, SS-5399/2023-KOL (Domsdatabasen) Court decision
- Vestre Landsret, dom 23.03.2026, SS-113/2025-VLR (Domsdatabasen, ECLI:DK:VLR:2026:SS0000000101) Court decision
Checked against the official source on 28 Sep 2026 · Direct link