Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
- Bribery and corruption €18.4m 40 % · 1 case
- Data protection €13.3m 29 % · 16 cases
- Consumer protection and online retail €7m 15 % · 4 cases
- Competition law €6.55m 14 % · 6 cases
- Money laundering and terrorist financing €373,141 1 % · 3 cases
- Sanctions and export control €215,000 0 % · 1 case
- Capital markets and financial supervision €16,500 0 % · 1 case
Who?
by company- SURYS SAS (Gruppe Imprimerie Nationale) €18.4m 40 % · 1 case
- Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen) €13m 29 % · 1 case
- Società Cooperativa Culture (CoopCulture) €7m 15 % · 1 case
- Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE) €4.52m 10 % · 1 case
- „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООД €1.4m 3 % · 1 case
- Synot W, a.s.; Ing. Igor Vicel (Unternehmer) €428,500 1 % · 1 case
- Stanleybet Malta Limited €225,730 0 % · 1 case
- Hrvatski lovački savez €89,935 0 % · 1 case
- Goldwin Ltd €80,907 0 % · 1 case
- ONE WAY PRIVATE COMPANY €80,000 0 % · 1 case
- 18 more€299,269
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €5,005 |
| Q2 2024 | 0 | — |
| Q3 2024 | 3 | €215,695 |
| Q4 2024 | 7 | €1.68m |
| Q1 2025 | 2 | €7.43m |
| Q2 2025 | 1 | — |
| Q3 2025 | 1 | €18.4m |
| Q4 2025 | 3 | €97,600 |
| Q1 2026 | 6 | €4.79m |
| Q2 2026 | 4 | €13.1m |
| Q3 2026 | 4 | €138,221 |
32 cases
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative Order
On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.
Keep retention or pause offers off the confirmation page of the online cancellation process.
Design of the cancellation process (cancellation button, retention offers)
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- § 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
- Action
- Order
- Status of proceedings
- final
- Sector
- Other
- Published
- 16 Jul 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment €80,907
The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.
Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.
Risk-based customer assessment in gambling
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 16 Jul 2026
- Administrative Measure Publication Notice – Goldwin Ltd Decision of an authority
- Publication of AML/CFT Administrative Penalties and Measures – FIAU Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR €1,948
An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.
Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.
Access to surveillance rooms; staff bound by instructions
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 15 Jun 2026
Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.
- ANSPDCP – Comunicat de presă 15.06.2026 (SSG SELECT SOLUTIONS S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report €16,500
The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.
Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Published
- 7 Aug 2026
- CySEC Board Decision – Fines under the Transparency Requirements Law (08.06.2026) Decision of an authority
- CySEC Board Decision – Fines under the Transparency Requirements Law (14.07.2025, Jahresbericht 2023) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware €71,474
An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.
Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.
Permissible monitoring of employees and IT use
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- Liability of senior managers
- Additional fine of 4,000 EUR on the responsible person.
- Published
- 9 Apr 2026
- Delodajalcu, ki je prikrito nadzoroval vse aktivnosti zaposlenih na računalnikih, izrečena globa več kot 70.000 EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops €225,730
Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.
Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.
Recognising structured deposits below the checking threshold
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Published
- 16 Apr 2026
- Administrative Measure Publication Notice – Stanleybet Malta Limited Decision of an authority
- Administrative Measures – FIAU Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule €4.52m
From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).
An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.
No-poach agreements in association rules
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 12 Mar 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list €8,200
Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).
Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.
No price recommendations by professional associations
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 29 Jan 2026
- AdC sanciona Associação de Guias de Informação Turística dos Açores por fixação de preços Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier €80,000
Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).
Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.
Checking consent before telemarketing
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5, 6, 7, 29, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Απόφαση 44/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers €17,600
The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.
New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Mitigating circumstances
- Partial immediate payment (20% reduction under Art. 85 LPACAP).
- AEPD Resolución PS/00160/2024 (EXP202308414) Decision of an authority
- AEPD Resolución recurso de reposición PS/00160/2024 (Datum der Ausgangsentscheidung 13.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script Order
The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.
Publicly accessible register data remain personal data – automated scraping requires its own legal basis.
Public registers are no licence for data collection
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Other
- Ettekirjutus-hoiatus nr 2.1.-4/25/1239-2660-6 (Zu Disain OÜ), 06.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2025 SURYS SAS (Gruppe Imprimerie Nationale)Hologram manufacturer SURYS: CJIP of 18.4 million EUR in the Ukrainian passport case €18.4m
From 2013, SURYS supplied security holograms for Ukrainian passports to the state-owned company Polygraph via an interposed Estonian company; the investigation (following a request for mutual legal assistance from Ukraine's National Anti-Corruption Bureau, NABU) concerned misappropriation of public funds, bribery of foreign public officials and money laundering. Public interest fine of 18,363,007 EUR, plus 3,770,000 EUR in damages to the Ukrainian state and a three-year AFA compliance programme.
If a state customer insists on an interposed trader without any discernible added value, treat this as a red flag for misappropriation and bribery.
Interposed trading companies and sales agents
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger, Geldwäsche
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 250 to 999
- Culpability
- intentional
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 3 Sep 2025
- Communiqué de presse du procureur de la République financier – CJIP SURYS Press release of an authority
- Convention judiciaire d'intérêt public – SURYS (08.07.2025) Decision of an authority
- Ministère de la Justice: Conventions judiciaires d'intérêt public (Verzeichnis) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Apr 2025 OGH: gyms may not impose fee increases by way of deemed consent Order
Two gym operators announced a fee increase of 6 EUR a month and treated silence or the failure to exercise a special right of termination as consent. In an action brought by the Austrian Federal Chamber of Labour (Bundesarbeitskammer), the OGH upheld the prohibition of such increases without express agreement and the publication of the judgment; it dismissed claims for repayment and information.
Price increases in ongoing consumer contracts require genuine consent – silence is not enough.
- Authority / court
- Oberster Gerichtshof (OGH), GZ 4 Ob 51/25s
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- § 6 Abs. 1 Z 2, § 28a KSchG; §§ 1a, 14 UWG
- Action
- Order
- Status of proceedings
- final
- Sector
- Other
- OGH 4 Ob 51/25s vom 11.04.2025 (RIS Justiz) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2025 Società Cooperativa Culture (CoopCulture)Colosseum tickets: CoopCulture 7 million EUR, around 20 million in total over ticket bots €7m
The Colosseum's ticketing service provider did not prevent tour operators from buying up basic tickets in bulk using bots, and itself reserved large allocations for more expensive packages; as a result, visitors could hardly find regular tickets. The AGCM imposed a fine of 7 million EUR on CoopCulture and further fines on six tour providers (including Tiqets, GetYourGuide, Musement), almost 20 million EUR in total.
Anyone selling a scarce allocation must actively prevent bot purchases and must not steer access towards expensive packages.
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 20, comma 2 Codice del Consumo (CoopCulture); Artt. 24, 25, 23 comma 1 lett. bb-bis (Touranbieter)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 8 Apr 2025
- PS12603 - Servizi Biglietteria Parco Archeologico del Colosseo, sanzionati CoopCulture e sei operatori turistici per quasi 20 milioni di euro Press release of an authority
- AGCM Provvedimento PS12603 (Biglietteria Colosseo), adunanza del 25 marzo 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Feb 2025 Synot W, a.s.; Ing. Igor Vicel (Unternehmer)Gambling takeover without notification: 428,500 EUR for gun-jumping €428,500
In 2020, Synot and a sole trader jointly acquired control of the gambling operator SLOV-MATIC, transferred shares and replaced corporate bodies before notifying the concentration. Under a settlement, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 400,000 EUR on Synot and 28,500 EUR on the entrepreneur; final since 7 March 2025.
Before closing, neither replace corporate bodies nor steer finances – M&A teams need a gun-jumping checklist.
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Merger control
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Anmeldepflicht und Vollzugsverbot)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Mitigating circumstances
- Voluntary subsequent notification, admission and settlement (50% reduction).
- Published
- 10 Mar 2025
- KONCENTRÁCIE: PMÚ uložil pokutu viac ako 428-tisíc eur za „gun-jumping“ v oblasti hazardu Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2024 Hrvatski lovački savezCroatia: 89,935 EUR against hunting association for predatory pricing in hunter training €89,935
From 2022 to March 2024, the Croatian Hunting Association offered hunter training below cost and financed this from areas in which it holds a statutory monopoly in order to drive out competitors. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed 89,935.20 EUR and ordered separate cost accounting; the High Administrative Court dismissed the action on 17 December 2025.
An organisation holding a monopoly in one market must not use the profits from it to undercut in neighbouring markets – separate cost accounting provides evidence.
- Authority / court
- Agencija za zaštitu tržišnog natjecanja (AZTN)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 13 Nr. 1 Zakon o zaštiti tržišnog natjecanja (ZZTN)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Published
- 10 Feb 2025
- AZTN zbog zlouporabe vladajućeg položaja predatorskim cijenama kaznio Hrvatski lovački savez Press release of an authority
- Visoki upravni sud Republike Hrvatske odbio tužbu Hrvatskog lovačkog saveza i potvrdio rješenje AZTN-a Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Dec 2024 Aktiebolaget Trav och GaloppATG: reprimand over misleadingly designed cookie banner Reprimand or warning
Following a complaint – one of several complaints about cookie banners lodged with European data protection authorities – the Swedish Authority for Privacy Protection (IMY) found that the betting operator did not make withdrawing consent as easy as giving it and, through the misleading design of the banner (choice of colours, contrast, rejection only as a link), made informed, freely given consent more difficult. IMY issued a reprimand; ATG had since changed the banner.
Rejecting must be as easy as accepting: colour, contrast and link placement in the cookie banner must not steer the decision.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- DSGVO Art. 6, Art. 7 Abs. 3
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Other
- IMY – Tillsyn Aktiebolaget Trav och Galopp Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2023-16453 (16.12.2024) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Nov 2024 CMC Certus Management Consultants LtdCyprus: 4,000 EUR against visa service provider CMC Certus – client documents on Scribd €4,000
Without informing them, the residence permit consultancy sent a client couple’s marriage certificate and proof of salary to a sister company in Georgia for translation; the documents subsequently appeared publicly on the Scribd platform. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 2,000 EUR each for an impermissible transfer to a third country and for lack of security measures, as well as a reprimand for insufficient cooperation.
Translation by a group company in a third country is also a data transfer – requiring safeguards, information and confidentiality rules.
Passing client documents on to translators and group companies
- Authority / court
- Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 31, Art. 44 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Decision – Complaint against CMC Certus Management Consultants Ltd (26.11.2024) Decision of an authority
- 28/03/2025 Αποφάσεις: Οκτώβριος – Δεκέμβριος 2024 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Nov 2024 „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООДWork shoe cartel in tenders – 2.75 million leva for three manufacturers €1.4m
The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that three suppliers had fixed prices and shared markets in public tenders by various contracting authorities for professional work shoes (Art. 15 ZZK – Bulgarian Protection of Competition Act, Art. 101 TFEU). Sanctions: 1,678,897 leva (Technomat-Merkuriy), 657,675 leva (disabled persons’ cooperative Zdravohod) and 409,424 leva (Kavaler Union 2001), a total of 2,745,996 leva. Appeals have been lodged against the decision.
Coordination on prices or on ‘who gets which contract’ is a hardcore cartel carrying a risk of millions, even among small niche suppliers.
Competition law in tenders
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 15 Abs. 1 Nr. 1 und 2 ZZK; Art. 101 Abs. 1 lit. a und c AEUV
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
Original amount 2,745,996 BGN, converted at the ECB reference rate of 21 Nov 2024.
- КЗК Публичен електронен регистър – Производство (Решение № 1254 от 21.11.2024; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 Integritas Consulting LtdMalta: 66,504 EUR against corporate services firm Integritas for lack of monitoring €66,504
The corporate services provider did not question why a client company that had been dormant for seven years suddenly received over 4 million EUR and passed almost identical amounts on to its shareholder, and did not keep customer information up to date. The Financial Intelligence Analysis Unit (FIAU) imposed 66,504 EUR; remediation was no longer possible because the firm had surrendered its licence and is being wound up.
Sudden flows of millions through dormant companies are a trigger for updated due diligence and, where appropriate, a suspicious transaction report.
Recognising unusual transactions in dormant companies
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 7(2)(a), 7(2)(b), 11(9), 15(3) PMLFTR
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 13 Nov 2024
- Administrative Measure Publication Notice – Integritas Consulting Ltd Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Oct 2024 Untold SRLUntold SRL fails to answer access and erasure request – 15,000 EUR €14,998
Untold SRL left an access request and an erasure request from a data subject unanswered, even though the data subject had provided all contact details. The Romanian data protection authority (ANSPDCP) imposed 49,741 lei (10,000 EUR) in respect of access and 24,870.5 lei (5,000 EUR) in respect of erasure and ordered staff training. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Data subject requests need a ticketing system with the one-month deadline – seasonal event organisers included.
Timely handling of data subject requests
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 12 Abs. 3 und 4, Art. 15, Art. 17 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 30 Oct 2024
Original amount 74,611.5 RON, converted at the ECB reference rate of 30 Oct 2024.
- ANSPDCP – Comunicat de presă 30.10.2024 (Untold SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2024 OGH: 100,000 EUR gun-jumping fine for premature start of a mask production joint venture €100,000
A textile company started operations with a joint venture (H* GmbH) for the production of protective masks on 24 April 2020, before the notifiable concentration had been cleared; the infringement lasted until 25 May 2020. The Cartel Court imposed a fine of 5,000 EUR; the OGH increased the fine to 100,000 EUR.
The standstill obligation applies even in emergencies such as the pandemic – a joint venture may only start operating after clearance.
Standstill obligation before clearance (gun-jumping), including in crisis situations
- Authority / court
- Oberster Gerichtshof als Kartellobergericht (Antrag der Bundeswettbewerbsbehörde)
- Area of law
- Competition law · Merger control
- Legal basis
- § 29 Z 1 lit a iVm § 17 Abs 1 KartG 2005
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Culpability
- intentional
- OGH 16 Ok 4/24k vom 16.10.2024 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Sep 2024 AS WasaWellness hotel Wasa must suspend video surveillance in treatment area Order
Following a tip-off that at the Wasa Resort Spa filming was also taking place in the treatment area and for monitoring work discipline, and that cameras captured the neighbouring property, the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered the hotel to suspend video surveillance until a sound balancing of interests had been submitted, to stop recording the neighbouring property and to correct the camera information on the website. The hotel had repeatedly let the supervisory authority’s deadlines lapse.
Cameras require a documented balancing of interests for each location – performance monitoring of employees is not a permissible purpose.
Video surveillance of employees and guests
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Video surveillance
- Legal basis
- § 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d und f, Art. 5 Abs. 1, Art. 6 Abs. 1 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Other
- Ettekirjutus-hoiatus nr 2.1.-1/23/124-377-13 (AS Wasa), 30.09.2024 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Sep 2024 Amsterdam company pays settlement: dividend paid out to oligarch's company €215,000
At the end of 2021, a company based in Amsterdam paid out a dividend of around 18 million EUR to a Russian shareholder behind which there was a sanctioned person, repaid a loan to a listed Russian company in 2019 and did not freeze shares and voting rights; in addition, a gatekeeper was misinformed. In a settlement (transactie) with the Dutch Public Prosecution Service (Openbaar Ministerie), the company paid 195,000 EUR and the managing director, as de facto manager, 20,000 EUR.
Dividends, loan repayments and voting rights vis-à-vis shareholders with a sanctioned owner in the background are also frozen – gatekeepers must know the full structure.
Freezing shares of listed shareholders, beneficial owners
- Authority / court
- Openbaar Ministerie (Staatsanwaltschaft der Niederlande)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Sanctiewet 1977 i. V. m. EU-Finanzsanktionen gegen Russland (seit 2014)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Liability of senior managers
- The managing director paid 20,000 EUR as de facto manager.
- Published
- 23 Sep 2024
- OM: Transacties na verdenking overtredingen Sanctiewet (23.09.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Sep 2024 „Българиън Дрийм Травъл“ ЕООДBulgarian Dream Travel feigns experience with education fairs – 1,360 leva €695
The company gave universities and schools the impression of many years of experience with international education fairs and of supposedly upcoming tours, although it had not actually held any such events; in doing so, it relied on the relationships of the applicant SRT International. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) regarded this conduct over more than one and a half years as seriously misleading (Art. 31 ZZK – Bulgarian Protection of Competition Act) and imposed 8% of 2023 turnover (17,000 leva), i.e. 1,360 leva, plus reimbursement of costs of 6,000.26 leva.
Micro-enterprises are also liable for references and claims of experience – borrowed success stories are misleading.
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 31 ZZK (Irreführung)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
Original amount 1,360 BGN, converted at the ECB reference rate of 19 Sep 2024.
- КЗК Публичен електронен регистър – Производство (Решение № 944 от 19.09.2024; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2024 EURO MINI STORAGE ROMANIA SRLEuro Mini Storage paralysed for weeks after cyber attack – 5,000 EUR €5,005
A cyber attack on the server paralysed the company for several weeks and allowed access to customer data. The Romanian data protection authority (ANSPDCP) imposed 24,884.50 lei (5,000 EUR) for insufficient security measures and ordered access logging with a retention period of at least 30 days as well as backups. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Logging and tested backups determine whether an attack means days or weeks of downtime.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 5 Mar 2024
Original amount 24,884.5 RON, converted at the ECB reference rate of 5 Mar 2024.
- ANSPDCP – Comunicat de presă 05.03.2024 (EURO MINI STORAGE ROMANIA SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link