Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUOther Clear all filters
32cases from 19 jurisdictions
€45.8mTotal of monetary amounts (27 cases with an amount)
€18.4mLargest single case: SURYS SAS (Gruppe Imprimerie Nationale)
€66,504Median per case with an amount

Click a bar to drill down one level.

Where?

by country
  1. France €18.4m 40 % · 1 case
  2. Austria €13.1m 29 % · 4 cases
  3. Italy €7m 15 % · 1 case
  4. Portugal €4.53m 10 % · 2 cases
  5. Bulgaria €1.4m 3 % · 2 cases
  6. Slovakia €428,500 1 % · 1 case
  7. Malta €373,141 1 % · 3 cases
  8. Netherlands €215,000 0 % · 1 case
  9. Croatia €89,935 0 % · 1 case
  10. Greece €80,000 0 % · 1 case
  11. 9 more€198,370

What for?

by area of law

All areas of law

  1. Bribery and corruption €18.4m 40 % · 1 case
  2. Data protection €13.3m 29 % · 16 cases
  3. Consumer protection and online retail €7m 15 % · 4 cases
  4. Competition law €6.55m 14 % · 6 cases
  5. Money laundering and terrorist financing €373,141 1 % · 3 cases
  6. Sanctions and export control €215,000 0 % · 1 case
  7. Capital markets and financial supervision €16,500 0 % · 1 case

Who?

by company
  1. SURYS SAS (Gruppe Imprimerie Nationale) €18.4m 40 % · 1 case
  2. Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen) €13m 29 % · 1 case
  3. Società Cooperativa Culture (CoopCulture) €7m 15 % · 1 case
  4. Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE) €4.52m 10 % · 1 case
  5. „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООД €1.4m 3 % · 1 case
  6. Synot W, a.s.; Ing. Igor Vicel (Unternehmer) €428,500 1 % · 1 case
  7. Stanleybet Malta Limited €225,730 0 % · 1 case
  8. Hrvatski lovački savez €89,935 0 % · 1 case
  9. Goldwin Ltd €80,907 0 % · 1 case
  10. ONE WAY PRIVATE COMPANY €80,000 0 % · 1 case
  11. 18 more€299,269

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20241€5,005
Q2 20240—
Q3 20243€215,695
Q4 20247€1.68m
Q1 20252€7.43m
Q2 20251—
Q3 20251€18.4m
Q4 20253€97,600
Q1 20266€4.79m
Q2 20264€13.1m
Q3 20264€138,221

32 cases

3 Sep 2025 SURYS SAS (Gruppe Imprimerie Nationale)Hologram manufacturer SURYS: CJIP of 18.4 million EUR in the Ukrainian passport case FranceBribery of public officials €18.4m

From 2013, SURYS supplied security holograms for Ukrainian passports to the state-owned company Polygraph via an interposed Estonian company; the investigation (following a request for mutual legal assistance from Ukraine's National Anti-Corruption Bureau, NABU) concerned misappropriation of public funds, bribery of foreign public officials and money laundering. Public interest fine of 18,363,007 EUR, plus 3,770,000 EUR in damages to the Ukrainian state and a three-year AFA compliance programme.

What organisations can take from it

If a state customer insists on an interposed trader without any discernible added value, treat this as a red flag for misappropriation and bribery.

Relevance to training and awareness

Interposed trading companies and sales agents

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger, Geldwäsche
Action
Fine
Status of proceedings
final
Sector
Other
Employees
250 to 999
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
3 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative GermanyInformation duties in online retail Order

On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.

What organisations can take from it

Keep retention or pause offers off the confirmation page of the online cancellation process.

Relevance to training and awareness

Design of the cancellation process (cancellation button, retention offers)

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
Action
Order
Status of proceedings
final
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment MaltaCustomer due diligence €80,907

The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.

What organisations can take from it

Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.

Relevance to training and awareness

Risk-based customer assessment in gambling

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report CyprusDisclosure and reporting obligations €16,500

The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.

What organisations can take from it

Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes
Published
7 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware SloveniaEmployee data €71,474

An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.

What organisations can take from it

Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.

Relevance to training and awareness

Permissible monitoring of employees and IT use

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Liability of senior managers
Additional fine of 4,000 EUR on the responsible person.
Published
9 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR LatviaData subject rights and transparency €1,500

A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.

What organisations can take from it

Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.

Relevance to training and awareness

Handling data subject requests and correspondence from authorities

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops MaltaCustomer due diligence €225,730

Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.

What organisations can take from it

Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.

Relevance to training and awareness

Recognising structured deposits below the checking threshold

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
16 Apr 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule PortugalCartels and collusion €4.52m

From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).

What organisations can take from it

An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.

Relevance to training and awareness

No-poach agreements in association rules

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
12 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order DenmarkData subject rights and transparency €8,031

Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.

What organisations can take from it

Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.

Relevance to training and awareness

Handling access requests (Art. 15 GDPR)

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
Action
Fine
Status of proceedings
final
Sector
Other

Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list PortugalCartels and collusion €8,200

Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).

What organisations can take from it

Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.

Relevance to training and awareness

No price recommendations by professional associations

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants AustriaData subject rights and transparency €25,500

The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).

What organisations can take from it

Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.

Relevance to training and awareness

Recording of telephone calls and applicant data

Authority / court
Datenschutzbehörde
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
Action
Fine
Status of proceedings
under appeal
Sector
Other
Employees
Under 50
Mitigating circumstances
No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier GreeceMarketing and consent €80,000

Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).

What organisations can take from it

Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.

Relevance to training and awareness

Checking consent before telemarketing

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5, 6, 7, 29, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers SpainData subject rights and transparency €17,600

The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.

What organisations can take from it

New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Mitigating circumstances
Partial immediate payment (20% reduction under Art. 85 LPACAP).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script EstoniaData protection Order

The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.

What organisations can take from it

Publicly accessible register data remain personal data – automated scraping requires its own legal basis.

Relevance to training and awareness

Public registers are no licence for data collection

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Apr 2025 OGH: gyms may not impose fee increases by way of deemed consent AustriaInformation duties in online retail Order

Two gym operators announced a fee increase of 6 EUR a month and treated silence or the failure to exercise a special right of termination as consent. In an action brought by the Austrian Federal Chamber of Labour (Bundesarbeitskammer), the OGH upheld the prohibition of such increases without express agreement and the publication of the judgment; it dismissed claims for repayment and information.

What organisations can take from it

Price increases in ongoing consumer contracts require genuine consent – silence is not enough.

Authority / court
Oberster Gerichtshof (OGH), GZ 4 Ob 51/25s
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 6 Abs. 1 Z 2, § 28a KSchG; §§ 1a, 14 UWG
Action
Order
Status of proceedings
final
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2025 Società Cooperativa Culture (CoopCulture)Colosseum tickets: CoopCulture 7 million EUR, around 20 million in total over ticket bots ItalyMisleading advertising and pricing €7m

The Colosseum's ticketing service provider did not prevent tour operators from buying up basic tickets in bulk using bots, and itself reserved large allocations for more expensive packages; as a result, visitors could hardly find regular tickets. The AGCM imposed a fine of 7 million EUR on CoopCulture and further fines on six tour providers (including Tiqets, GetYourGuide, Musement), almost 20 million EUR in total.

What organisations can take from it

Anyone selling a scarce allocation must actively prevent bot purchases and must not steer access towards expensive packages.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 20, comma 2 Codice del Consumo (CoopCulture); Artt. 24, 25, 23 comma 1 lett. bb-bis (Touranbieter)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
8 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Load 12 more of 12

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial