Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

5cases from 2 jurisdictions
€66.4mTotal of monetary amounts (4 cases with an amount)
€45mLargest single case: Vodafone GmbH
€10.6mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€19.4m
Q1 20240—
Q2 20241—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20252€46.8m
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20261€240,000

5 cases

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay GermanyDisclosure and reporting obligations €240,000

Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.

What organisations can take from it

Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.

Relevance to training and awareness

Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2025 SAP SESAP: failure to publish notice on the 2022 annual financial report GermanyDisclosure and reporting obligations €1.75m

SAP had not published an announcement stating from when and at which internet address the 2022 annual financial report was publicly available in addition to the company register (Hinweisbekanntmachung). BaFin imposed a fine of 1.75 million EUR; the notice is final.

What organisations can take from it

Even seemingly formal disclosure steps such as the notice announcement need a fixed place in the financial calendar – the range of fines extends up to five per cent of total turnover.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 114 Abs. 1 Satz 2 WpHG
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
27 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack SwitzerlandData processors Other

Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.

What organisations can take from it

Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.

Relevance to training and awareness

Passing real data to service providers for support

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data processors
Legal basis
Datenschutzgesetz (DSG)
Action
Other
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
1 May 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Dec 2023 Swisscom (Schweiz) AGWEKO: CHF 18.4 million against Swisscom over fibre network roll-out strategy SwitzerlandAbuse of market power €19.4m

Swisscom expanded its fibre-optic network in such a way that competitors were not given Layer 1 access from the local exchanges. WEKO considered this to be an abuse of a dominant position, imposed a sanction of CHF 18,362,014, required Swisscom to retrofit the network and imposed procedural costs of CHF 927,307.

What organisations can take from it

Dominant network operators must assess infrastructure decisions for their consequences for competitors' access.

Authority / court
Wettbewerbskommission (WEKO)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 7 Abs. 1 i.V.m. Abs. 2 lit. a und e KG, Art. 49a Abs. 1 KG
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Employees
10,000 or more

Original amount 18,362,014 CHF, converted at the ECB reference rate of 4 Dec 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial