Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EURomaniaOther Clear all filters
5cases from 1 jurisdiction
€79,265Total of monetary amounts
€54,316Largest single case: AMATO BESTSELLER S.R.L.
€5,005Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) €79,265 100 % · 5 cases

What for?

by area of law

All areas of law

  1. Data protection €79,265 100 % · 5 cases

Who?

by company
  1. AMATO BESTSELLER S.R.L. €54,316 69 % · 1 case
  2. Untold SRL €14,998 19 % · 1 case
  3. EURO MINI STORAGE ROMANIA SRL €5,005 6 % · 1 case
  4. Poliserv JG (PJG) SRL €2,998 4 % · 1 case
  5. SSG SELECT SOLUTIONS S.R.L. €1,948 2 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20241€5,005
Q2 20240—
Q3 20240—
Q4 20241€14,998
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20261€1,948
Q3 20262€57,314

5 cases

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Oct 2024 Untold SRLUntold SRL fails to answer access and erasure request – 15,000 EUR RomaniaData subject rights and transparency €14,998

Untold SRL left an access request and an erasure request from a data subject unanswered, even though the data subject had provided all contact details. The Romanian data protection authority (ANSPDCP) imposed 49,741 lei (10,000 EUR) in respect of access and 24,870.5 lei (5,000 EUR) in respect of erasure and ordered staff training. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Data subject requests need a ticketing system with the one-month deadline – seasonal event organisers included.

Relevance to training and awareness

Timely handling of data subject requests

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12 Abs. 3 und 4, Art. 15, Art. 17 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
30 Oct 2024

Original amount 74,611.5 RON, converted at the ECB reference rate of 30 Oct 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2024 EURO MINI STORAGE ROMANIA SRLEuro Mini Storage paralysed for weeks after cyber attack – 5,000 EUR RomaniaData breaches and data security €5,005

A cyber attack on the server paralysed the company for several weeks and allowed access to customer data. The Romanian data protection authority (ANSPDCP) imposed 24,884.50 lei (5,000 EUR) for insufficient security measures and ordered access logging with a retention period of at least 30 days as well as backups. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Logging and tested backups determine whether an attack means days or weeks of downtime.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
5 Mar 2024

Original amount 24,884.5 RON, converted at the ECB reference rate of 5 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial