Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,929 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€235,206Total of monetary amounts
€235,206Largest single case: National Amusements, Inc.
€235,206Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20241€235,206
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

13 Nov 2024 National Amusements, Inc.Cinema operator National Amusements: 250,000 USD over data breach and late notice USA, NYEmployee data €235,206

In December 2022 an attacker used an employee's stolen credentials to break into the systems of the cinema operator National Amusements because multi-factor authentication was not enforced for all access routes; data such as social security, passport and account numbers of 82,128 people was affected – according to the company, current and former employees and contractors – of whom 23,365 were in New York, and some of the social security numbers were stored unencrypted. Those affected were only notified on 18 December 2023, more than a year after the incident. Under the Assurance of Discontinuance with the New York Attorney General's office, the company pays 250,000 USD and must introduce, among other things, encryption, password rules, vulnerability testing and an incident response plan. The authority allegedly made the findings set out here; this account is not based on a final judgment.

What organisations can take from it

Employee data also triggers notification duties – notice must not wait until the data review is fully completed.

Relevance to training and awareness

Multi-factor authentication for all access routes; timely notification of data breaches

Missing or inadequate training played a role in the decision.

Authority / court
Office of the New York State Attorney General (Bureau of Internet & Technology)
Area of law
Data protection · Employee data
Legal basis
New York Executive Law § 63(12); New York General Business Law § 899-aa (Benachrichtigung bei Datenpannen) und § 899-bb (SHIELD Act, Datensicherheit)
Action
Fine
Status of proceedings
final
Sector
Other
Published
15 Nov 2024

Original amount 250,000 USD, converted at the ECB reference rate of 13 Nov 2024.

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial