Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

Other Clear all filters
49cases from 22 jurisdictions
€75.6mTotal of monetary amounts (40 cases with an amount)
€18.4mLargest single case: SURYS SAS (Gruppe Imprimerie Nationale)
€81,586Median per case with an amount

Click a bar to drill down one level.

Where?

by region

All jurisdictions

  1. EU 32 cases 65 % · €45.8m
  2. USA 7 cases 14 % · €8.02m
  3. United Kingdom 6 cases 12 % · €21.2m
  4. Canada 4 cases 8 % · €549,261

What for?

by area of law

All areas of law

  1. Data protection 19 cases 39 % · €29.5m
  2. Money laundering and terrorist financing 7 cases 14 % · €8.17m
  3. Competition law 6 cases 12 % · €6.55m
  4. Consumer protection and online retail 5 cases 10 % · €11.8m
  5. Health and safety and employment law 3 cases 6 % · €736,841
  6. Supply chain and human rights 3 cases 6 % ·
  7. Whistleblower protection 2 cases 4 % · €82,264
  8. Capital markets and financial supervision 1 case 2 % · €16,500
  9. Bribery and corruption 1 case 2 % · €18.4m
  10. Sanctions and export control 1 case 2 % · €215,000
  11. 1 more1 case

Who?

by company
  1. „Българиън Дрийм Травъл“ ЕООД 1 case 2 % · €695
  2. „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООД 1 case 2 % · €1.4m
  3. 12066424 Canada Inc. 1 case 2 % · €93,832
  4. 3R Technology UK Ltd 1 case 2 % · €164,216
  5. A. Tsokkos Hotels Public Limited 1 case 2 % · €16,500
  6. Aktiebolaget Trav och Galopp 1 case 2 % ·
  7. AMATO BESTSELLER S.R.L. 1 case 2 % · €54,316
  8. Arbeitgeber (in der Mitteilung nicht namentlich genannt) 1 case 2 % · €71,474
  9. AS Wasa 1 case 2 % ·
  10. Associação de Guias de Informação Turística dos Açores (AGITA) 1 case 2 % · €8,200
  11. 35 more35 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20241€5,005
Q2 20240—
Q3 20243€215,695
Q4 20248€2.51m
Q1 20253€7.69m
Q2 20252€69,458
Q3 20252€18.4m
Q4 20258€23.4m
Q1 20267€4.95m
Q2 20268€18.1m
Q3 20267€282,805

49 cases

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Aug 2026 Shandong Weiqiao Pioneering Group Co., Ltd.UFLPA list: textile group Shandong Weiqiao Pioneering Group over Xinjiang cotton USAForced and child labour Order

The U.S. Forced Labor Enforcement Task Force (FLETF) added the cotton and textile producer to the Uyghur Forced Labor Prevention Act (UFLPA) Entity List because it sources cotton from Xinjiang. The company's goods are therefore presumed to have been produced with forced labour on import into the US unless the importer rebuts this.

What organisations can take from it

Textile retailers need proof of origin for cotton down to the fibre, for example through isotope or traceability testing.

Authority / court
U.S. Department of Homeland Security (Forced Labor Enforcement Task Force)
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
Uyghur Forced Labor Prevention Act, Section 2(d)(2)(B)(v)
Action
Order
Status of proceedings
unknown
Sector
Other
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2026 Nova Scotia Gaming CorporationFINTRAC: 231,826 CAD against Nova Scotia Gaming over missing suspicious transaction reports CanadaSuspicious activity reports €144,584

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 231,826 CAD on the Halifax gaming corporation (casino sector) because it failed to file suspicious transaction reports on attempted transactions despite reasonable grounds for suspicion, did not keep its compliance policies up to date and approved by a senior officer, and did not assess the money laundering risk as required. The penalty was paid in full.

What organisations can take from it

Even aborted or merely attempted transactions can be reportable – cashier staff must know this.

Relevance to training and awareness

Suspicious transaction reports even for merely attempted transactions

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
final
Sector
Other
Published
3 Sep 2026

Original amount 231,826 CAD, converted at the ECB reference rate of 23 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative GermanyInformation duties in online retail Order

On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.

What organisations can take from it

Keep retention or pause offers off the confirmation page of the online cancellation process.

Relevance to training and awareness

Design of the cancellation process (cancellation button, retention offers)

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
Action
Order
Status of proceedings
final
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment MaltaCustomer due diligence €80,907

The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.

What organisations can take from it

Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.

Relevance to training and awareness

Risk-based customer assessment in gambling

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jul 2026 Hutchison Technologies LtdTribunal: Hutchison Technologies dismissed employee after she raised holiday pay concerns United KingdomRetaliation against whistleblowers Other

An employee of the Dundee-based electrical services provider for gyms (around 140 employees) had pointed out that the technicians' holiday pay was being calculated incorrectly; a few days later her home working arrangement was withdrawn, and on 11 June 2025 she was dismissed. The Employment Tribunal upheld her claims for automatically unfair dismissal (s. 103A) and detriment (s. 47B); compensation will be decided separately.

What organisations can take from it

Employers who worsen working conditions shortly after a disclosure must be able to prove a documented reason unrelated to the disclosure.

Relevance to training and awareness

How managers handle internal reports

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, ss. 43B, 47B, 103A
Action
Other
Status of proceedings
unknown
Sector
Other
Employees
50 to 249
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Needle Craft Ltd.; Casual Wear Apparel LLCCBP import stop for textiles from Jordan's Needle Craft and Casual Wear Apparel USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: clothing from Needle Craft Ltd.; Casual Wear Apparel LLC (Jordan) is being detained at all US ports of entry because there are indications of forced labour (ILO indicators including physical and sexual violence, retention of identity documents, restriction of movement and withholding of wages). These are two parallel orders against both manufacturers.

What organisations can take from it

Fashion brands should supplement social audits at garment makers with confidential worker interviews, because violence and confiscation of identity documents remain invisible in paper-based checks.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Other
Published
23 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report CyprusDisclosure and reporting obligations €16,500

The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.

What organisations can take from it

Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes
Published
7 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2026 Sonus Public Relations LtdTribunal: PR agency Sonus must pay £71,052 after subjecting whistleblower to detriment United KingdomRetaliation against whistleblowers €82,264

The PR agency, which did not appear, lost on all claims: detriment on grounds of whistleblowing (£20,000 for injury to feelings), wrongful termination without notice pay (£3,547.60) and constructive unfair dismissal (basic and compensatory award including a 25 % ACAS uplift). A total of £71,051.82 was awarded.

What organisations can take from it

Employers who do not take part in the proceedings risk, in addition to whistleblower compensation, an uplift for failing to follow the ACAS Code of Practice.

Relevance to training and awareness

How managers handle internal reports

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, s. 47B (Benachteiligung wegen geschützter Offenlegung); konstruktive unfaire Kündigung; wrongful dismissal
Action
Other
Status of proceedings
unknown
Sector
Other
Published
22 Jul 2026

Original amount 71,051.82 GBP, converted at the ECB reference rate of 3 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2026 12066424 Canada Inc.Temporary staffing agency and director: CA$150,000 over unpaid wages Canada, ONMinimum wage and undeclared work €93,832

Following complaints, the labour inspectorate found, among other things, outstanding minimum wages at the temporary staffing agency in Leamington; an audit for 2022 showed that hundreds of employees were owed a total of CA$234,212 in regular wages, public holiday pay and vacation pay. The company and its director did not comply with the 2023 orders to pay; in proceedings held in their absence, the court imposed CA$100,000 on the company and CA$50,000 on the director (plus victim fine surcharge).

What organisations can take from it

Companies that ignore regulatory orders to pay outstanding wages risk not only a corporate fine but also personal liability for management.

Authority / court
Provincial Offences Court Windsor (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Employment Standards Act, 2000 (Ontario), ss. 103(8), 106, 132, 136
Action
Fine
Status of proceedings
unknown
Sector
Other
Liability of senior managers
Director Son-Van Duong personally fined CA$50,000.
Published
3 Jun 2026

Original amount 150,000 CAD, converted at the ECB reference rate of 23 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Automobile Association Developments Limited (AA Driving School, BSM Driving School)AA and BSM driving schools: 4.2 million GBP for drip pricing – CMA's first consumer fine United KingdomMisleading advertising and pricing €4.83m

For online bookings, the driving schools only showed a mandatory booking fee at checkout instead of in the initial price. Following an admission and settlement, the CMA imposed a penalty of 4.2 million GBP (40 % discount on 7 million GBP) and ordered refunds of more than 760,000 GBP to more than 80,000 customers.

What organisations can take from it

Mandatory fees must be included from the very first price – in the United Kingdom, the CMA has been able to impose fines for this itself since 2025.

Relevance to training and awareness

Price disclosures and mandatory fees at online checkout

Authority / court
Competition and Markets Authority (CMA)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Digital Markets, Competition and Consumers Act 2024
Action
Fine
Status of proceedings
final
Sector
Other
Mitigating circumstances
Admission and early settlement (40 % discount).
Published
15 Apr 2026

Original amount 4,200,000 GBP, converted at the ECB reference rate of 15 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware SloveniaEmployee data €71,474

An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.

What organisations can take from it

Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.

Relevance to training and awareness

Permissible monitoring of employees and IT use

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Liability of senior managers
Additional fine of 4,000 EUR on the responsible person.
Published
9 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 3R Technology UK Ltd3R Technology UK: penalty for exporting contaminated plastic waste despite prohibition United KingdomWaste and hazardous substances €164,216

From 2022 to 2025, the company exported containers of supposedly clean plastic that was in fact contaminated with electronic waste such as cables and circuit boards; in some cases, the waste was hidden at the back of the container, and further containers were shipped despite prohibition notices from August 2024. The company and its director pleaded guilty to 16 counts: a fine of 80,000 GBP, 45,000 GBP in costs and a 2,000 GBP surcharge for the company; 120 hours of community service, 15,000 GBP in costs and a 114 GBP surcharge for the director.

What organisations can take from it

Incorrectly declared waste exports are detected during port inspections; those who ignore regulatory prohibitions also risk the personal conviction of management.

Relevance to training and awareness

Correct classification and declaration of waste for export

Authority / court
Preston Magistrates' Court (Anklage: Environment Agency)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Vorschriften zur grenzüberschreitenden Abfallverbringung (Notifizierung und Zustimmung); Verstoß gegen Untersagungsverfügungen
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Repeat case
yes
Mitigating circumstances
Guilty plea.
Liability of senior managers
Director Yulin Wang personally sentenced to 120 hours of community service, 15,000 GBP in costs and a 114 GBP surcharge.
Published
2 Apr 2026

Original amount 142,114 GBP, converted at the ECB reference rate of 24 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR LatviaData subject rights and transparency €1,500

A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.

What organisations can take from it

Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.

Relevance to training and awareness

Handling data subject requests and correspondence from authorities

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops MaltaCustomer due diligence €225,730

Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.

What organisations can take from it

Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.

Relevance to training and awareness

Recognising structured deposits below the checking threshold

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
16 Apr 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule PortugalCartels and collusion €4.52m

From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).

What organisations can take from it

An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.

Relevance to training and awareness

No-poach agreements in association rules

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
12 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order DenmarkData subject rights and transparency €8,031

Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.

What organisations can take from it

Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.

Relevance to training and awareness

Handling access requests (Art. 15 GDPR)

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
Action
Fine
Status of proceedings
final
Sector
Other

Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list PortugalCartels and collusion €8,200

Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).

What organisations can take from it

Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.

Relevance to training and awareness

No price recommendations by professional associations

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants AustriaData subject rights and transparency €25,500

The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).

What organisations can take from it

Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.

Relevance to training and awareness

Recording of telephone calls and applicant data

Authority / court
Datenschutzbehörde
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
Action
Fine
Status of proceedings
under appeal
Sector
Other
Employees
Under 50
Mitigating circumstances
No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier GreeceMarketing and consent €80,000

Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).

What organisations can take from it

Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.

Relevance to training and awareness

Checking consent before telemarketing

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5, 6, 7, 29, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Dec 2025 Rickenbacher Data LLC (Datamasters)CPPA: $45,000 against data broker Datamasters over failure to register USA, CAMarketing and consent €38,275

Without registering as a data broker, the Texas reseller traded in the names and contact details of millions of people, sorted by illnesses such as Alzheimer's or addiction, by age, presumed ethnicity and political views. In addition to the fine, the California Privacy Protection Agency (CPPA) requires it to stop selling data on all Californians.

What organisations can take from it

Companies that buy or sell address lists for advertising must check registration obligations – health-related lists are particularly risky.

Authority / court
California Privacy Protection Agency (CPPA)
Area of law
Data protection · Marketing and consent
Legal basis
California Delete Act (Registrierungspflicht für Datenhändler)
Action
Fine
Status of proceedings
final
Sector
Other
Published
8 Jan 2026

Original amount 45,000 USD, converted at the ECB reference rate of 30 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 Caesars Entertainment, Inc. / Desert Palace, LLC (Caesars Palace)Nevada: 7.8 million USD against Caesars over gambling by an illegal bookmaker USA, NVCustomer due diligence €6.77m

On 13 November 2025, the Nevada Gaming Control Board (NGCB) filed a disciplinary complaint for unsuitable methods of operation in connection with the illegal bookmaker Mathew Bowyer and at the same time concluded a settlement of 7.8 million USD with conditions attached to the gaming licences. The conditions relate primarily to improving the AML programme and to additional training and awareness-raising for employees; the Nevada Gaming Commission (NGC) adopted the settlement as its order on 20 November 2025 (Case No. 25-03).

What organisations can take from it

Casino staff must recognise high-risk players and unexplained sources of funds – revenue interests must not override AML obligations.

Relevance to training and awareness

Checking the source of gambling funds, recognising high-risk customers

Missing or inadequate training played a role in the decision.

Authority / court
Nevada Gaming Commission (NGC) auf Beschwerde des Nevada Gaming Control Board (NGCB)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Glücksspielrecht Nevada (unsuitable methods of operation)
Action
Fine
Status of proceedings
final
Sector
Other
Employees
10,000 or more
Mitigating circumstances
Numerous remedial measures already implemented
Published
13 Nov 2025

Original amount 7,800,000 USD, converted at the ECB reference rate of 20 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Nov 2025 Firemount Group Ltd.CBP stops clothing from Firemount Group in Mauritius USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: clothing and textiles from Firemount Group Ltd. (Mauritius) are being detained at all US ports of entry because there are indications of forced labour (ILO indicators including abuse of vulnerability, debt bondage, deception, and intimidation and threats).

What organisations can take from it

Suppliers outside traditional high-risk countries must also be checked for their recruitment practices for foreign workers.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Other
Published
18 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Oct 2025 Winsor Maintenance Inc., Main Source Group, Inc. u. a. sowie OptumCare Management LLC (Auftraggeberin)Cleaning companies/OptumCare: 438,204 USD – overtime and missed breaks USA, CAWorking time €377,534

More than 90 cleaners in industrial, laboratory and healthcare facilities often worked beyond scheduled hours without overtime pay, received no compensation for split shifts and travel time and were unable to take breaks because of excessive workloads. A web of companies owned by the Hong family concealed the employer; the Notice of Final Findings of 21 October 2025 established 438,204 USD, with OptumCare jointly liable as the client.

What organisations can take from it

Clients of cleaning and service providers should check working hours and breaks at the provider – otherwise they are jointly liable.

Authority / court
California Labor Commissioner's Office (Division of Labor Standards Enforcement)
Area of law
Health and safety and employment law · Working time
Legal basis
California Labor Code § 2810.3; Overtime, Split Shift, Meal and Rest Periods, Mindestlohn
Action
Other
Status of proceedings
unknown
Sector
Other
Liability of senior managers
Members of the owning family and an acquaintance cited personally.
Published
24 Nov 2025

Original amount 438,204 USD, converted at the ECB reference rate of 21 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Oct 2025 Capita plc und Capita Pension Solutions LimitedICO: £14 million against Capita after ransomware attack affecting 6.6 million people United KingdomData breaches and data security €16.1m

In March 2023, an employee unintentionally downloaded malicious files; although an alert was triggered after ten minutes, the device was only isolated after 58 hours. Attackers stole around one terabyte of data on 6.6 million people (including pension data and criminal record information). Fines imposed by the UK Information Commissioner's Office (ICO): £8 million against Capita plc and £6 million against Capita Pension Solutions.

What organisations can take from it

Security alerts need binding response times and an adequately staffed SOC – known vulnerabilities must be remedied across the group.

Relevance to training and awareness

Handling malicious downloads and security alerts

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32
Action
Fine
Status of proceedings
final
Sector
Other
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
£45 million had provisionally been proposed; reduced, among other things, for security improvements, credit monitoring for those affected and cooperation with authorities and the NCSC.
Published
15 Oct 2025

Original amount 14,000,000 GBP, converted at the ECB reference rate of 15 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers SpainData subject rights and transparency €17,600

The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.

What organisations can take from it

New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Mitigating circumstances
Partial immediate payment (20% reduction under Art. 85 LPACAP).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script EstoniaData protection Order

The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.

What organisations can take from it

Publicly accessible register data remain personal data – automated scraping requires its own legal basis.

Relevance to training and awareness

Public registers are no licence for data collection

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2025 SURYS SAS (Gruppe Imprimerie Nationale)Hologram manufacturer SURYS: CJIP of 18.4 million EUR in the Ukrainian passport case FranceBribery of public officials €18.4m

From 2013, SURYS supplied security holograms for Ukrainian passports to the state-owned company Polygraph via an interposed Estonian company; the investigation (following a request for mutual legal assistance from Ukraine's National Anti-Corruption Bureau, NABU) concerned misappropriation of public funds, bribery of foreign public officials and money laundering. Public interest fine of 18,363,007 EUR, plus 3,770,000 EUR in damages to the Ukrainian state and a three-year AFA compliance programme.

What organisations can take from it

If a state customer insists on an interposed trader without any discernible added value, treat this as a red flag for misappropriation and bribery.

Relevance to training and awareness

Interposed trading companies and sales agents

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger, Geldwäsche
Action
Fine
Status of proceedings
final
Sector
Other
Employees
250 to 999
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
3 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jul 2025 DMCL Chartered Professional AccountantsFINTRAC: accountancy firm DMCL without compliance programme – 72,750 CAD CanadaInternal controls €45,370

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 72,750 CAD on the auditing and accountancy firm with four offices in British Columbia: approved written compliance policies, a documented risk assessment and the prescribed two-yearly effectiveness review were all lacking. The penalty was paid.

What organisations can take from it

Firms that handle money movements for clients are themselves obliged entities and need their own AML programme.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
final
Sector
Other
Published
9 Oct 2025

Original amount 72,750 CAD, converted at the ECB reference rate of 25 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2025 DPP Law LtdICO: £60,000 against law firm DPP Law over hack and late notification United KingdomData breaches and data security €69,458

In 2022, attackers used brute force to penetrate the law firm's network via a rarely used administrator account without MFA and stole 32 GB of highly sensitive data, which appeared on the dark web. The firm only learned of this from the National Crime Agency and reported the incident to the UK Information Commissioner's Office (ICO) only 43 days later.

What organisations can take from it

Even small law firms need MFA on admin accounts and a reporting process that meets the 72-hour deadline.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2, Art. 33 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Published
16 Apr 2025

Original amount 60,000 GBP, converted at the ECB reference rate of 14 Apr 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Apr 2025 OGH: gyms may not impose fee increases by way of deemed consent AustriaInformation duties in online retail Order

Two gym operators announced a fee increase of 6 EUR a month and treated silence or the failure to exercise a special right of termination as consent. In an action brought by the Austrian Federal Chamber of Labour (Bundesarbeitskammer), the OGH upheld the prohibition of such increases without express agreement and the publication of the judgment; it dismissed claims for repayment and information.

What organisations can take from it

Price increases in ongoing consumer contracts require genuine consent – silence is not enough.

Authority / court
Oberster Gerichtshof (OGH), GZ 4 Ob 51/25s
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 6 Abs. 1 Z 2, § 28a KSchG; §§ 1a, 14 UWG
Action
Order
Status of proceedings
final
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Mar 2025 Ontario International College Inc.Private college and director: CA$410,000 for ignored orders to pay wages Canada, ONMinimum wage and undeclared work €265,475

The college failed to pay 14 employees wages of almost CA$185,000 and ignored the labour inspectorate's orders to pay from 2019/2020; the director did not pay either. The court imposed CA$270,000 on the company and CA$140,000 on the director, in addition to the outstanding wages.

What organisations can take from it

Outstanding wage claims do not go away – the fine comes on top of the back pay and also hits management personally.

Authority / court
Provincial Offences Court Toronto (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Employment Standards Act, 2000 (Ontario), ss. 103(8), 106, 132, 136
Action
Fine
Status of proceedings
unknown
Sector
Other
Liability of senior managers
Director Anchuan Jiang personally fined CA$140,000.
Published
28 May 2025

Original amount 410,000 CAD, converted at the ECB reference rate of 28 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2025 Società Cooperativa Culture (CoopCulture)Colosseum tickets: CoopCulture 7 million EUR, around 20 million in total over ticket bots ItalyMisleading advertising and pricing €7m

The Colosseum's ticketing service provider did not prevent tour operators from buying up basic tickets in bulk using bots, and itself reserved large allocations for more expensive packages; as a result, visitors could hardly find regular tickets. The AGCM imposed a fine of 7 million EUR on CoopCulture and further fines on six tour providers (including Tiqets, GetYourGuide, Musement), almost 20 million EUR in total.

What organisations can take from it

Anyone selling a scarce allocation must actively prevent bot purchases and must not steer access towards expensive packages.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 20, comma 2 Codice del Consumo (CoopCulture); Artt. 24, 25, 23 comma 1 lett. bb-bis (Touranbieter)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
8 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2025 Synot W, a.s.; Ing. Igor Vicel (Unternehmer)Gambling takeover without notification: 428,500 EUR for gun-jumping SlovakiaMerger control €428,500

In 2020, Synot and a sole trader jointly acquired control of the gambling operator SLOV-MATIC, transferred shares and replaced corporate bodies before notifying the concentration. Under a settlement, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 400,000 EUR on Synot and 28,500 EUR on the entrepreneur; final since 7 March 2025.

What organisations can take from it

Before closing, neither replace corporate bodies nor steer finances – M&A teams need a gun-jumping checklist.

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Merger control
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Anmeldepflicht und Vollzugsverbot)
Action
Fine
Status of proceedings
final
Sector
Other
Mitigating circumstances
Voluntary subsequent notification, admission and settlement (50% reduction).
Published
10 Mar 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Hrvatski lovački savezCroatia: 89,935 EUR against hunting association for predatory pricing in hunter training CroatiaAbuse of market power €89,935

From 2022 to March 2024, the Croatian Hunting Association offered hunter training below cost and financed this from areas in which it holds a statutory monopoly in order to drive out competitors. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed 89,935.20 EUR and ordered separate cost accounting; the High Administrative Court dismissed the action on 17 December 2025.

What organisations can take from it

An organisation holding a monopoly in one market must not use the profits from it to undercut in neighbouring markets – separate cost accounting provides evidence.

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 13 Nr. 1 Zakon o zaštiti tržišnog natjecanja (ZZTN)
Action
Fine
Status of proceedings
final
Sector
Other
Published
10 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Dec 2024 Aktiebolaget Trav och GaloppATG: reprimand over misleadingly designed cookie banner SwedenCookies and tracking Reprimand or warning

Following a complaint – one of several complaints about cookie banners lodged with European data protection authorities – the Swedish Authority for Privacy Protection (IMY) found that the betting operator did not make withdrawing consent as easy as giving it and, through the misleading design of the banner (choice of colours, contrast, rejection only as a link), made informed, freely given consent more difficult. IMY issued a reprimand; ATG had since changed the banner.

What organisations can take from it

Rejecting must be as easy as accepting: colour, contrast and link placement in the cookie banner must not steer the decision.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Cookies and tracking
Legal basis
DSGVO Art. 6, Art. 7 Abs. 3
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Nov 2024 CMC Certus Management Consultants LtdCyprus: 4,000 EUR against visa service provider CMC Certus – client documents on Scribd CyprusInternational data transfers €4,000

Without informing them, the residence permit consultancy sent a client couple’s marriage certificate and proof of salary to a sister company in Georgia for translation; the documents subsequently appeared publicly on the Scribd platform. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 2,000 EUR each for an impermissible transfer to a third country and for lack of security measures, as well as a reprimand for insufficient cooperation.

What organisations can take from it

Translation by a group company in a third country is also a data transfer – requiring safeguards, information and confidentiality rules.

Relevance to training and awareness

Passing client documents on to translators and group companies

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · International data transfers
Legal basis
Art. 5 Abs. 1 lit. f, Art. 31, Art. 44 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Nov 2024 „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООДWork shoe cartel in tenders – 2.75 million leva for three manufacturers BulgariaCartels and collusion €1.4m

The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that three suppliers had fixed prices and shared markets in public tenders by various contracting authorities for professional work shoes (Art. 15 ZZK – Bulgarian Protection of Competition Act, Art. 101 TFEU). Sanctions: 1,678,897 leva (Technomat-Merkuriy), 657,675 leva (disabled persons’ cooperative Zdravohod) and 409,424 leva (Kavaler Union 2001), a total of 2,745,996 leva. Appeals have been lodged against the decision.

What organisations can take from it

Coordination on prices or on ‘who gets which contract’ is a hardcore cartel carrying a risk of millions, even among small niche suppliers.

Relevance to training and awareness

Competition law in tenders

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 15 Abs. 1 Nr. 1 und 2 ZZK; Art. 101 Abs. 1 lit. a und c AEUV
Action
Fine
Status of proceedings
under appeal
Sector
Other

Original amount 2,745,996 BGN, converted at the ECB reference rate of 21 Nov 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Nov 2024 Integritas Consulting LtdMalta: 66,504 EUR against corporate services firm Integritas for lack of monitoring MaltaCustomer due diligence €66,504

The corporate services provider did not question why a client company that had been dormant for seven years suddenly received over 4 million EUR and passed almost identical amounts on to its shareholder, and did not keep customer information up to date. The Financial Intelligence Analysis Unit (FIAU) imposed 66,504 EUR; remediation was no longer possible because the firm had surrendered its licence and is being wound up.

What organisations can take from it

Sudden flows of millions through dormant companies are a trigger for updated due diligence and, where appropriate, a suspicious transaction report.

Relevance to training and awareness

Recognising unusual transactions in dormant companies

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 7(2)(a), 7(2)(b), 11(9), 15(3) PMLFTR
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
13 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Oct 2024 Untold SRLUntold SRL fails to answer access and erasure request – 15,000 EUR RomaniaData subject rights and transparency €14,998

Untold SRL left an access request and an erasure request from a data subject unanswered, even though the data subject had provided all contact details. The Romanian data protection authority (ANSPDCP) imposed 49,741 lei (10,000 EUR) in respect of access and 24,870.5 lei (5,000 EUR) in respect of erasure and ordered staff training. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Data subject requests need a ticketing system with the one-month deadline – seasonal event organisers included.

Relevance to training and awareness

Timely handling of data subject requests

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12 Abs. 3 und 4, Art. 15, Art. 17 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
30 Oct 2024

Original amount 74,611.5 RON, converted at the ECB reference rate of 30 Oct 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Oct 2024 Sahara Dunes Casino, LP (Lake Elsinore Hotel and Casino)FinCEN: 900,000 USD against Lake Elsinore card club over missing reports USASuspicious activity reports €831,716

The US Financial Crimes Enforcement Network (FinCEN) imposed 900,000 USD on the Californian card club, which admitted wilful infringements over more than four and a half years: no effective AML programme, missing currency transaction reports (CTR) and suspicious activity reports (SAR), and record-keeping deficiencies. The infringements stemmed from decisions by management.

What organisations can take from it

Even small casinos and card clubs must file currency transaction reports and suspicious activity reports without gaps – management decisions to the contrary are considered wilful.

Relevance to training and awareness

Currency transaction and suspicious activity reports in gambling operations

Authority / court
Financial Crimes Enforcement Network (FinCEN)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Bank Secrecy Act (BSA) und Durchführungsbestimmungen
Action
Fine
Status of proceedings
final
Sector
Other
Culpability
intentional
Liability of senior managers
According to FinCEN, the infringements were based on decisions by management
Published
23 Oct 2024

Original amount 900,000 USD, converted at the ECB reference rate of 22 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Oct 2024 OGH: 100,000 EUR gun-jumping fine for premature start of a mask production joint venture AustriaMerger control €100,000

A textile company started operations with a joint venture (H* GmbH) for the production of protective masks on 24 April 2020, before the notifiable concentration had been cleared; the infringement lasted until 25 May 2020. The Cartel Court imposed a fine of 5,000 EUR; the OGH increased the fine to 100,000 EUR.

What organisations can take from it

The standstill obligation applies even in emergencies such as the pandemic – a joint venture may only start operating after clearance.

Relevance to training and awareness

Standstill obligation before clearance (gun-jumping), including in crisis situations

Authority / court
Oberster Gerichtshof als Kartellobergericht (Antrag der Bundeswettbewerbsbehörde)
Area of law
Competition law · Merger control
Legal basis
§ 29 Z 1 lit a iVm § 17 Abs 1 KartG 2005
Action
Fine
Status of proceedings
final
Sector
Other
Culpability
intentional
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Sep 2024 AS WasaWellness hotel Wasa must suspend video surveillance in treatment area EstoniaVideo surveillance Order

Following a tip-off that at the Wasa Resort Spa filming was also taking place in the treatment area and for monitoring work discipline, and that cameras captured the neighbouring property, the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered the hotel to suspend video surveillance until a sound balancing of interests had been submitted, to stop recording the neighbouring property and to correct the camera information on the website. The hotel had repeatedly let the supervisory authority’s deadlines lapse.

What organisations can take from it

Cameras require a documented balancing of interests for each location – performance monitoring of employees is not a permissible purpose.

Relevance to training and awareness

Video surveillance of employees and guests

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Video surveillance
Legal basis
§ 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d und f, Art. 5 Abs. 1, Art. 6 Abs. 1 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Sep 2024 Amsterdam company pays settlement: dividend paid out to oligarch's company NetherlandsBreaches of sanctions and embargoes €215,000

At the end of 2021, a company based in Amsterdam paid out a dividend of around 18 million EUR to a Russian shareholder behind which there was a sanctioned person, repaid a loan to a listed Russian company in 2019 and did not freeze shares and voting rights; in addition, a gatekeeper was misinformed. In a settlement (transactie) with the Dutch Public Prosecution Service (Openbaar Ministerie), the company paid 195,000 EUR and the managing director, as de facto manager, 20,000 EUR.

What organisations can take from it

Dividends, loan repayments and voting rights vis-à-vis shareholders with a sanctioned owner in the background are also frozen – gatekeepers must know the full structure.

Relevance to training and awareness

Freezing shares of listed shareholders, beneficial owners

Authority / court
Openbaar Ministerie (Staatsanwaltschaft der Niederlande)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Sanctiewet 1977 i. V. m. EU-Finanzsanktionen gegen Russland (seit 2014)
Action
Fine
Status of proceedings
final
Sector
Other
Liability of senior managers
The managing director paid 20,000 EUR as de facto manager.
Published
23 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Sep 2024 „Българиън Дрийм Травъл“ ЕООДBulgarian Dream Travel feigns experience with education fairs – 1,360 leva BulgariaMisleading advertising and pricing €695

The company gave universities and schools the impression of many years of experience with international education fairs and of supposedly upcoming tours, although it had not actually held any such events; in doing so, it relied on the relationships of the applicant SRT International. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) regarded this conduct over more than one and a half years as seriously misleading (Art. 31 ZZK – Bulgarian Protection of Competition Act) and imposed 8% of 2023 turnover (17,000 leva), i.e. 1,360 leva, plus reimbursement of costs of 6,000.26 leva.

What organisations can take from it

Micro-enterprises are also liable for references and claims of experience – borrowed success stories are misleading.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 31 ZZK (Irreführung)
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 1,360 BGN, converted at the ECB reference rate of 19 Sep 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2024 EURO MINI STORAGE ROMANIA SRLEuro Mini Storage paralysed for weeks after cyber attack – 5,000 EUR RomaniaData breaches and data security €5,005

A cyber attack on the server paralysed the company for several weeks and allowed access to customer data. The Romanian data protection authority (ANSPDCP) imposed 24,884.50 lei (5,000 EUR) for insufficient security measures and ordered access logging with a retention period of at least 30 days as well as backups. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Logging and tested backups determine whether an attack means days or weeks of downtime.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
5 Mar 2024

Original amount 24,884.5 RON, converted at the ECB reference rate of 5 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial