Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
- Bribery and corruption €18.4m 40 % · 1 case
- Data protection €13.3m 29 % · 16 cases
- Consumer protection and online retail €7m 15 % · 4 cases
- Competition law €6.55m 14 % · 6 cases
- Money laundering and terrorist financing €373,141 1 % · 3 cases
- Sanctions and export control €215,000 0 % · 1 case
- Capital markets and financial supervision €16,500 0 % · 1 case
Who?
by company- SURYS SAS (Gruppe Imprimerie Nationale) €18.4m 40 % · 1 case
- Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen) €13m 29 % · 1 case
- Società Cooperativa Culture (CoopCulture) €7m 15 % · 1 case
- Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE) €4.52m 10 % · 1 case
- „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООД €1.4m 3 % · 1 case
- Synot W, a.s.; Ing. Igor Vicel (Unternehmer) €428,500 1 % · 1 case
- Stanleybet Malta Limited €225,730 0 % · 1 case
- Hrvatski lovački savez €89,935 0 % · 1 case
- Goldwin Ltd €80,907 0 % · 1 case
- ONE WAY PRIVATE COMPANY €80,000 0 % · 1 case
- 18 more€299,269
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €5,005 |
| Q2 2024 | 0 | — |
| Q3 2024 | 3 | €215,695 |
| Q4 2024 | 7 | €1.68m |
| Q1 2025 | 2 | €7.43m |
| Q2 2025 | 1 | — |
| Q3 2025 | 1 | €18.4m |
| Q4 2025 | 3 | €97,600 |
| Q1 2026 | 6 | €4.79m |
| Q2 2026 | 4 | €13.1m |
| Q3 2026 | 4 | €138,221 |
32 cases
3 Sep 2025 SURYS SAS (Gruppe Imprimerie Nationale)Hologram manufacturer SURYS: CJIP of 18.4 million EUR in the Ukrainian passport case €18.4m
From 2013, SURYS supplied security holograms for Ukrainian passports to the state-owned company Polygraph via an interposed Estonian company; the investigation (following a request for mutual legal assistance from Ukraine's National Anti-Corruption Bureau, NABU) concerned misappropriation of public funds, bribery of foreign public officials and money laundering. Public interest fine of 18,363,007 EUR, plus 3,770,000 EUR in damages to the Ukrainian state and a three-year AFA compliance programme.
If a state customer insists on an interposed trader without any discernible added value, treat this as a red flag for misappropriation and bribery.
Interposed trading companies and sales agents
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger, Geldwäsche
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 250 to 999
- Culpability
- intentional
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 3 Sep 2025
- Communiqué de presse du procureur de la République financier – CJIP SURYS Press release of an authority
- Convention judiciaire d'intérêt public – SURYS (08.07.2025) Decision of an authority
- Ministère de la Justice: Conventions judiciaires d'intérêt public (Verzeichnis) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative Order
On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.
Keep retention or pause offers off the confirmation page of the online cancellation process.
Design of the cancellation process (cancellation button, retention offers)
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- § 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
- Action
- Order
- Status of proceedings
- final
- Sector
- Other
- Published
- 16 Jul 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment €80,907
The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.
Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.
Risk-based customer assessment in gambling
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 16 Jul 2026
- Administrative Measure Publication Notice – Goldwin Ltd Decision of an authority
- Publication of AML/CFT Administrative Penalties and Measures – FIAU Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR €1,948
An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.
Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.
Access to surveillance rooms; staff bound by instructions
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 15 Jun 2026
Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.
- ANSPDCP – Comunicat de presă 15.06.2026 (SSG SELECT SOLUTIONS S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report €16,500
The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.
Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Published
- 7 Aug 2026
- CySEC Board Decision – Fines under the Transparency Requirements Law (08.06.2026) Decision of an authority
- CySEC Board Decision – Fines under the Transparency Requirements Law (14.07.2025, Jahresbericht 2023) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware €71,474
An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.
Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.
Permissible monitoring of employees and IT use
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- Liability of senior managers
- Additional fine of 4,000 EUR on the responsible person.
- Published
- 9 Apr 2026
- Delodajalcu, ki je prikrito nadzoroval vse aktivnosti zaposlenih na računalnikih, izrečena globa več kot 70.000 EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops €225,730
Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.
Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.
Recognising structured deposits below the checking threshold
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Published
- 16 Apr 2026
- Administrative Measure Publication Notice – Stanleybet Malta Limited Decision of an authority
- Administrative Measures – FIAU Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule €4.52m
From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).
An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.
No-poach agreements in association rules
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 12 Mar 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list €8,200
Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).
Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.
No price recommendations by professional associations
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 29 Jan 2026
- AdC sanciona Associação de Guias de Informação Turística dos Açores por fixação de preços Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier €80,000
Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).
Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.
Checking consent before telemarketing
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5, 6, 7, 29, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Απόφαση 44/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers €17,600
The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.
New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Mitigating circumstances
- Partial immediate payment (20% reduction under Art. 85 LPACAP).
- AEPD Resolución PS/00160/2024 (EXP202308414) Decision of an authority
- AEPD Resolución recurso de reposición PS/00160/2024 (Datum der Ausgangsentscheidung 13.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script Order
The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.
Publicly accessible register data remain personal data – automated scraping requires its own legal basis.
Public registers are no licence for data collection
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Other
- Ettekirjutus-hoiatus nr 2.1.-4/25/1239-2660-6 (Zu Disain OÜ), 06.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Apr 2025 OGH: gyms may not impose fee increases by way of deemed consent Order
Two gym operators announced a fee increase of 6 EUR a month and treated silence or the failure to exercise a special right of termination as consent. In an action brought by the Austrian Federal Chamber of Labour (Bundesarbeitskammer), the OGH upheld the prohibition of such increases without express agreement and the publication of the judgment; it dismissed claims for repayment and information.
Price increases in ongoing consumer contracts require genuine consent – silence is not enough.
- Authority / court
- Oberster Gerichtshof (OGH), GZ 4 Ob 51/25s
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- § 6 Abs. 1 Z 2, § 28a KSchG; §§ 1a, 14 UWG
- Action
- Order
- Status of proceedings
- final
- Sector
- Other
- OGH 4 Ob 51/25s vom 11.04.2025 (RIS Justiz) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2025 Società Cooperativa Culture (CoopCulture)Colosseum tickets: CoopCulture 7 million EUR, around 20 million in total over ticket bots €7m
The Colosseum's ticketing service provider did not prevent tour operators from buying up basic tickets in bulk using bots, and itself reserved large allocations for more expensive packages; as a result, visitors could hardly find regular tickets. The AGCM imposed a fine of 7 million EUR on CoopCulture and further fines on six tour providers (including Tiqets, GetYourGuide, Musement), almost 20 million EUR in total.
Anyone selling a scarce allocation must actively prevent bot purchases and must not steer access towards expensive packages.
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 20, comma 2 Codice del Consumo (CoopCulture); Artt. 24, 25, 23 comma 1 lett. bb-bis (Touranbieter)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 8 Apr 2025
- PS12603 - Servizi Biglietteria Parco Archeologico del Colosseo, sanzionati CoopCulture e sei operatori turistici per quasi 20 milioni di euro Press release of an authority
- AGCM Provvedimento PS12603 (Biglietteria Colosseo), adunanza del 25 marzo 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link