Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
€4.57mTotal of monetary amounts
€4.21mLargest single case: Telenor Norge AS
€342,745Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Nasjonal kommunikasjonsmyndighet (Nkom) €4.21m 92 % · 1 case
  2. Datatilsynet €364,076 8 % · 2 cases

What for?

by area of law

All areas of law

  1. Information security and cyber €4.21m 92 % · 1 case
  2. Data protection €364,076 8 % · 2 cases

Who?

by company
  1. Telenor Norge AS €4.21m 92 % · 1 case
  2. Telenor ASA €342,745 7 % · 1 case
  3. Timegrip AS €21,331 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20251€342,745
Q2 20250—
Q3 20251€4.21m
Q4 20250—
Q1 20261€21,331
Q2 20260—
Q3 20260—

3 cases

16 Jan 2026 Timegrip ASTimegrip AS: NOK 250,000 for denying staff access to time records NorwayData subject rights and transparency €21,331

Datatilsynet (Norwegian Data Protection Authority) fined the time-recording system provider Timegrip AS NOK 250,000 because, after a retail chain went bankrupt, the company refused 80 former employees access to their clock-in data, which they needed to document their wage claims. The authority treated Timegrip as controller, since after the bankruptcy the company alone in fact decided on storage, use and access, and found a breach of the right of access under Art. 15(1) and (3) GDPR. A fine of NOK 750,000 had been notified; the authority took into account, among other things, the confused situation and its own long case-handling time.

What organisations can take from it

Processors should agree in their contracts how data will be released if the controller goes bankrupt – whoever in fact controls the data is liable as controller, including for access requests.

Relevance to training and awareness

Employees' right of access and the allocation of controller and processor roles

Authority / court
Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 15 Abs. 1 und 3, Art. 58 Abs. 2 lit. i, Art. 83 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Mitigating circumstances
The confused situation after the customer's bankruptcy (given only limited weight) and Datatilsynet's long case-handling time; NOK 750,000 had been notified.
Published
20 Jan 2026

Original amount 250,000 NOK, converted at the ECB reference rate of 16 Jan 2026.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jul 2025 Telenor Norge ASTelenor Norge: 50 million NOK after four disruptions to emergency numbers in autumn 2024 NorwayCritical infrastructure €4.21m

The Nasjonal kommunikasjonsmyndighet (Nkom, Norwegian Communications Authority) imposed an administrative penalty (overtredelsesgebyr) of 50,000,000 NOK on Telenor Norge because, on four occasions in autumn 2024 (29 August, 16 September, 17/18 October, 13 November), emergency calls over its network failed entirely or intermittently or were misrouted. The inspection found 22 breaches of ekomloven (Electronic Communications Act), sikkerhetsloven (National Security Act) and several regulations, including inadequate risk assessments, planned work not carried out securely, insufficient redundancy, inadequate auditing of a subcontractor and late notification of the authority. In its final decision Nkom maintained the amount announced in February 2025; the deadline for an administrative appeal ran until 8 September 2025.

What organisations can take from it

Operators that carry emergency call services must safeguard planned network changes with a risk analysis and working redundancy, audit their suppliers and report disruptions on time.

Relevance to training and awareness

Planned work on critical networks: risk analysis, a working fallback and notifying the regulator within 30 minutes

Authority / court
Nasjonal kommunikasjonsmyndighet (Nkom)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
ekomloven (lov 4. juli 2003 nr. 83), sikkerhetsloven (lov 1. juni 2018 nr. 24), ekomforskriften, nummerforskriften, klassifiseringsforskriften, virksomhetssikkerhetsforskriften
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
1,000 to 9,999
Published
3 Jul 2025

Original amount 50,000,000 NOK, converted at the ECB reference rate of 3 Jul 2025.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Mar 2025 Telenor ASATelenor ASA: NOK 4m fine over data protection officer set-up and internal control NorwayData protection €342,745

Following an inspection, Datatilsynet (Norwegian Data Protection Authority) fined Telenor ASA NOK 4,000,000 because the group parent had not put in place appropriate organisational measures and policies for the position of its data protection officer (Art. 24(1) and (2) GDPR). The authority also issued a reprimand because for about one year there was no reporting line from the data protection officer to the highest management level, and ordered the company to carry out a documented assessment of whether it must designate a data protection officer and to revise its record of processing activities. According to Datatilsynet, the decision has been appealed and a ruling by the Personvernnemnda (Privacy Appeals Board) is expected in autumn 2026. The decision is not final.

What organisations can take from it

The data protection officer's role must be documented – with a direct reporting line to top management, clear rules on the officer's involvement and an assessment of potential conflicts of interest.

Relevance to training and awareness

Position and independence of the data protection officer

Authority / court
Datatilsynet
Area of law
Data protection
Legal basis
Art. 24 Abs. 1 und 2, Art. 30, Art. 37 Abs. 7, Art. 38 Abs. 2 und 3, Art. 58 Abs. 2 lit. b, d und i DSGVO; § 26 personopplysningsloven
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
No specific harm to data subjects was identified; the long case-handling time was taken into account when setting the amount.
Published
14 Mar 2025

Original amount 4,000,000 NOK, converted at the ECB reference rate of 10 Mar 2025.

Checked against the official source on 28 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial