Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Information Commissioner's Office (ICO) €5.07m 81 % · 2 cases
- HM Treasury, Office of Financial Sanctions Implementation (OFSI) €1.16m 19 % · 1 case
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €3.68m |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €1.39m |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €1.16m |
| Q3 2026 | 0 | — |
3 cases
26 May 2026 Sabre Global Technologies LimitedSabre subsidiary accepted payments from designated Ural Airlines €1.16m
The provider of a travel booking system continued to provide services to Ural Airlines, designated in May 2022, requested payments of around 906,600 USD and, after the funds were frozen by the bank, looked for alternative payment routes, which HM Treasury's Office of Financial Sanctions Implementation (OFSI) regarded as circumvention. A lack of escalation during a change of roles, vacant leadership positions in legal and compliance, policies focused on US law and screening that did not flag the designation all contributed.
If an existing customer is designated, escalate this immediately; looking for alternative payment routes after the bank has frozen funds is itself a breach.
Responding to new designations of existing customers, prohibition of circumvention
- Authority / court
- HM Treasury, Office of Financial Sanctions Implementation (OFSI)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Russia (Sanctions) (EU Exit) Regulations 2019, regs. 13, 14, 19
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Voluntary disclosure (31 October 2022) and full cooperation; settlement under the new settlement procedure
- Published
- 17 Jun 2026
Original amount 1,000,920.59 GBP, converted at the ECB reference rate of 26 May 2026.
- OFSI: Imposition of Monetary Penalty – Sabre Global Technologies Limited Decision of an authority
- OFSI – Enforcement of financial sanctions (Sammlung) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database €1.39m
In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.
Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.
Separation of personal and work devices and credentials
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 11 Dec 2025
Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.
- Password manager provider fined £1.2m by ICO for data breach Press release of an authority
- ICO Enforcement: LastPass UK Ltd Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA €3.68m
Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.
MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data processors
- Legal basis
- UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
- Published
- 27 Mar 2025
Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.
- Software provider fined £3m following 2022 ransomware attack Press release of an authority
- ICO Enforcement: Advanced Computer Software Group Limited Enforcement database of an authority
- ICO Penalty Notice: Advanced Computer Software Group Ltd Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link