Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America and Asia-Pacific: 1,905 cases from 39 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- AS "Latvijas valsts meži" €7.86m 50 % · 1 case
- France Travail €5m 32 % · 1 case
- Health Service Executive (HSE) €645,000 4 % · 1 case
- Department of Social Protection (DSP) €550,000 4 % · 1 case
- Anonymised companies €410,751 3 % · 8 cases
- Ελληνική Εταιρεία Τοπικής Ανάπτυξης και Αυτοδιοίκησης Α.Ε. (EETAA) und Υπουργείο Κοινωνικής Συνοχής και Οικογένειας €350,000 2 % · 1 case
- Gemeenten Delft, Ede, Eindhoven u. a. (10 Gemeinden) €250,000 2 % · 1 case
- Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences) €175,000 1 % · 1 case
- University of Limerick €98,000 1 % · 1 case
- Ministerstvo vnútra Slovenskej republiky €70,000 0 % · 1 case
- 16 more€155,407
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €98,000 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Dec 2025 University of LimerickDPC: €98,000 fine against University of Limerick after phishing of staff mailboxes €98,000
Between 2018 and 2020 the university notified twelve personal data breaches, six of which involved unauthorised persons gaining access to staff email accounts through phishing and in some cases setting up forwarding rules. The DPC found infringements of Art. 5(1)(f), 30(1), 32(1), 33(1) and 34(1) GDPR, issued a reprimand and imposed fines of €45,000, €3,000, €35,000 and €15,000, totalling €98,000.
Phishing protection for mailboxes and clear internal reporting channels determine whether data breaches are reported to the authority and affected persons on time.
Recognising phishing and reporting data breaches within 72 hours
Missing or inadequate training played a role in the decision.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5(1)(f), 30(1), 32(1), 33(1), 34(1) DSGVO; ss. 110–111 Data Protection Act 2018
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Mitigating circumstances
- The university accepted most of the findings, acknowledged responsibility and improved its systems, training and policies; the fines are well below those in the draft and no remedial order was made.
- DPC: Inquiry concerning the University of Limerick (IN-19-7-1) Decision of an authority
Checked against the official source on 2 Oct 2026 · Direct link