Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- McKinsey and Company Africa (Pty) Ltd €116.6m 49 % · 1 case
- Anonymised companies €22.7m 10 % · 19 cases
- SURYS SAS (Gruppe Imprimerie Nationale) €18.4m 8 % · 1 case
- Capita plc und Capita Pension Solutions Limited €16.1m 7 % · 1 case
- Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen) €13m 5 % · 1 case
- Philip Morris Italia S.r.l. €7m 3 % · 1 case
- Società Cooperativa Culture (CoopCulture) €7m 3 % · 1 case
- Caesars Entertainment, Inc. / Desert Palace, LLC (Caesars Palace) €6.77m 3 % · 1 case
- Automobile Association Developments Limited (AA Driving School, BSM Driving School) €4.83m 2 % · 1 case
- Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE) €4.52m 2 % · 1 case
- 70 more€21.1m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €1m |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
1 case
20 Dec 2024 Profisportorganisation, Spanien (anonymisiert)AEPD: EUR 1 million fine on a sports organisation over biometric access control without a valid DPIA €1m
A Spanish professional sports organisation required its members to control access to certain spectator areas biometrically without first carrying out a valid data protection impact assessment. The Spanish data protection authority AEPD imposed a fine of EUR 1 million for breaching Art. 35 GDPR and ordered the biometric processing to be suspended until a proper impact assessment is in place.
Anyone imposing biometric systems on others is itself a controller and must assess necessity and risks beforehand.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection
- Legal basis
- Art. 35 DSGVO (Art. 83 Abs. 4 lit. a DSGVO)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- AEPD, Resoluciones (Übersicht) (Entscheidung 2024) Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link