Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by levelWhat for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €626,868 |
| Q4 2024 | 1 | €3.7m |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 2 | €126.5m |
| Q4 2025 | 2 | €1.29bn |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | — |
| Q3 2026 | 0 | — |
7 cases
5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students Order
According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.
Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- FTC Act (Verbot unlauterer und irreführender Praktiken)
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 5 Jun 2026
- FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students' Personal Data Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Nov 2025 Comunicaciones Celulares S.A. (TIGO Guatemala)TIGO Guatemala pays more than 118 million USD for bribing members of Congress €102.1m
From 2012 to 2018, the Guatemalan mobile network operator made monthly cash payments to members of Congress or their security staff in order to obtain legislative support; part of the funds came from laundered drug money. Two-year Deferred Prosecution Agreement with a criminal penalty of 60 million USD and administrative forfeiture of 58,198,343 USD.
In joint ventures with local partners, the parent company needs genuine control over cash flows and contacts with public officials – an early voluntary self-disclosure is no substitute for a full investigation.
Bribery of public officials, cash payments, integrity of co-shareholders
- Authority / court
- U.S. Department of Justice (Criminal Division, Fraud Section; USAO Southern District of Florida)
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- FCPA, 15 U.S.C. § 78dd-3 (Verschwörung, 18 U.S.C. § 371); Deferred Prosecution Agreement
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure by the parent company Millicom in 2015; subsequently extensive cooperation and remediation (including dismissals of staff and an 800 % increase in compliance personnel).
- Liability of senior managers
- According to the DOJ, the scheme was directed by the then Guatemalan shareholder and other senior individuals; four individuals had already been charged (not named).
- Published
- 12 Dec 2025
Original amount 118,198,343 USD, converted at the ECB reference rate of 12 Nov 2025.
- TIGO Guatemala Paid Over $118M to Resolve Foreign Bribery Investigation Press release of an authority
- Deferred Prosecution Agreement, United States v. Comunicaciones Celulares S.A. d/b/a TIGO Guatemala (Case 1:25-cr-20476) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data €1.19bn
Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.
Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.
- Authority / court
- Office of the Attorney General of Texas
- Area of law
- Data protection · Cookies and tracking
- Action
- Other
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 31 Oct 2025
Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.
- Attorney General Ken Paxton Finalizes Historic Settlement with Google and Secures $1.375 Billion Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Sep 2025 Chegg Inc.Chegg pays 7.5 million USD in FTC settlement over allegations of obstructed subscription cancellation €6.35m
According to the FTC complaint, the education provider hid the cancellation option for its automatically renewing subscriptions on its website and, since October 2020, continued to charge almost 200,000 customers even after they had cancelled. Under the settlement, Chegg is paying 7.5 million USD for refunds and must offer simple cancellation.
Cancellations received must be reliably implemented in the systems – continuing to charge customers is a separate violation.
Cancellation processes and customer service for subscriptions
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Restore Online Shoppers' Confidence Act (ROSCA); Section 5 FTC Act
- Action
- Disgorgement of profits
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Repeat case
- yes
- Published
- 15 Sep 2025
Original amount 7,500,000 USD, converted at the ECB reference rate of 18 Sep 2025.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Jul 2025 Cadence Design Systems Inc.Cadence pleads guilty: chip design software for Chinese military university €120.1m
From 2015 to 2021, the San José provider of chip design software supplied hardware, software and semiconductor IP at least 59 times to the National University of Defense Technology (NUDT), a military university on the Entity List, disguised under the alias Central South CAD Center. Cadence pleaded guilty before the US Department of Justice to conspiracy to commit export control violations; criminal penalties of almost 118 million USD and civil penalties of more than 95 million USD imposed by the Bureau of Industry and Security (BIS) result, after crediting, in a net total of more than 140 million USD.
Include cover names and known aliases of listed customers in screening; sales and compliance must escalate indications of military end users.
Recognising aliases and cover names of listed customers
- Authority / court
- U.S. Department of Justice; Bureau of Industry and Security (BIS)
- Area of law
- Sanctions and export control · Export control and dual-use goods
- Legal basis
- Export Administration Regulations (Entity List); ECRA; Verschwörung zu Exportkontrollverstößen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Culpability
- intentional
- Published
- 28 Jul 2025
Original amount 140,000,000 USD, converted at the ECB reference rate of 28 Jul 2025.
- DOJ: Cadence Design Systems Agrees to Plead Guilty and Pay Over $140 Million for Unlawfully Exporting to Military University in China (28.07.2025) Press release of an authority
- BIS: Cadence Design Systems to Pay $95 Million Penalty to BIS for Unauthorized Exports to Chinese Entities (28.07.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Oct 2024 Unisys Corp.SEC: $4 million against Unisys for downplaying cyber incidents after SolarWinds €3.7m
In mandatory disclosures, Unisys presented cyber risks as hypothetical, although it had suffered two intrusions with data exfiltration connected with the SolarWinds compromise. On the same day, the US Securities and Exchange Commission (SEC) also imposed penalties on Avaya ($1 million), Check Point ($995,000) and Mimecast ($990,000).
Do not describe cyber incidents that have occurred as a mere risk in investor information – disclosure processes must involve IT security.
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Securities Act of 1933, Securities Exchange Act of 1934 (inkl. Disclosure Controls)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Cooperation in the proceedings and improvement of cybersecurity controls.
- Published
- 22 Oct 2024
Original amount 4,000,000 USD, converted at the ECB reference rate of 22 Oct 2024.
- SEC Charges Four Companies With Misleading Cyber Disclosures Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Sep 2024 AppFolio, Inc.SEC: AppFolio pays 692,250 US dollars over waivers of whistleblower awards €626,868
The provider of property management software had employees waive potential awards for reports to authorities in two employment agreements and one settlement agreement; 68 consulting agreements (January 2020 to October 2023) prohibited voluntary disclosures to authorities. As part of a sweep against seven listed companies, AppFolio paid 692,250 US dollars to the U.S. Securities and Exchange Commission (SEC); the contract templates were amended.
Separation and employment agreements must restrict neither reports to authorities nor the entitlement to whistleblower awards.
Whistleblower protection in contract templates (HR/Legal)
- Authority / court
- U.S. Securities and Exchange Commission
- Area of law
- Whistleblower protection · Retaliation against whistleblowers
- Legal basis
- Securities Exchange Act of 1934, Rule 21F-17(a)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Amendment of the templates after contact by the SEC, information provided to those affected, and cooperation
- Published
- 9 Sep 2024
Original amount 692,250 USD, converted at the ECB reference rate of 9 Sep 2024.
- SEC Charges Seven Public Companies with Violations of Whistleblower Protection Rule Press release of an authority
- In the Matter of AppFolio, Inc., Release No. 34-100971 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link