Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 1,370 cases from 35 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Datatilsynet €21,331 100 % · 1 case
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 1 | €21,331 |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
1 case
16 Jan 2026 Timegrip ASTimegrip AS: NOK 250,000 for denying staff access to time records €21,331
Datatilsynet (Norwegian Data Protection Authority) fined the time-recording system provider Timegrip AS NOK 250,000 because, after a retail chain went bankrupt, the company refused 80 former employees access to their clock-in data, which they needed to document their wage claims. The authority treated Timegrip as controller, since after the bankruptcy the company alone in fact decided on storage, use and access, and found a breach of the right of access under Art. 15(1) and (3) GDPR. A fine of NOK 750,000 had been notified; the authority took into account, among other things, the confused situation and its own long case-handling time.
Processors should agree in their contracts how data will be released if the controller goes bankrupt – whoever in fact controls the data is liable as controller, including for access requests.
Employees' right of access and the allocation of controller and processor roles
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 15 Abs. 1 und 3, Art. 58 Abs. 2 lit. i, Art. 83 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Mitigating circumstances
- The confused situation after the customer's bankruptcy (given only limited weight) and Datatilsynet's long case-handling time; NOK 750,000 had been notified.
- Published
- 20 Jan 2026
Original amount 250,000 NOK, converted at the ECB reference rate of 16 Jan 2026.
- Datatilsynet: Overtredelsesgebyr for manglende innsyn (20.01.2026) Press release of an authority
- Datatilsynet, Vedtak om ileggelse av overtredelsesgebyr – Timegrip AS, 20/02911-20, 16.01.2026 Decision of an authority
Checked against the official source on 28 Sep 2026 · Direct link