Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€1mTotal of monetary amounts
€1mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20241€1m
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20260—

1 case

20 Dec 2024 Profisportorganisation, Spanien (anonymisiert)AEPD: EUR 1 million fine on a sports organisation over biometric access control without a valid DPIA SpainData protection €1m

A Spanish professional sports organisation required its members to control access to certain spectator areas biometrically without first carrying out a valid data protection impact assessment. The Spanish data protection authority AEPD imposed a fine of EUR 1 million for breaching Art. 35 GDPR and ordered the biometric processing to be suspended until a proper impact assessment is in place.

What organisations can take from it

Anyone imposing biometric systems on others is itself a controller and must assess necessity and risks beforehand.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection
Legal basis
Art. 35 DSGVO (Art. 83 Abs. 4 lit. a DSGVO)
Action
Fine
Status of proceedings
unknown
Sector
Other

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial