Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
- Data protection 22 cases 45 % · €1.31bn
- Competition law 8 cases 16 % · €47.2m
- AI and digital regulation 7 cases 14 % · €1.43bn
- Capital markets and financial supervision 4 cases 8 % · €6.11m
- Bribery and corruption 3 cases 6 % · €118.7m
- Sanctions and export control 3 cases 6 % · €121.3m
- Whistleblower protection 1 case 2 % · €626,868
- Consumer protection and online retail 1 case 2 % · €6.35m
Who?
by company- Apple 2 cases 4 % · €500m
- „Смарт Софт“ ЕООД 1 case 2 % · €19,128
- Advanced Computer Software Group Ltd 1 case 2 % · €3.68m
- AppFolio, Inc. 1 case 2 % · €626,868
- Avast Software s.r.o. 1 case 2 % · €13.9m
- Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt) 1 case 2 % · €4.5m
- Black Tiger Belgium (vormals Bisnode Belgium) 1 case 2 % · €157,176
- Bravogroup Holding Vagyonkezelő Kft. 1 case 2 % · €84,042
- Cadence Design Systems Inc. 1 case 2 % · €120.1m
- Chegg Inc. 1 case 2 % · €6.35m
- 37 more37 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €19.4m |
| Q1 2024 | 1 | €157,176 |
| Q2 2024 | 3 | €44.4m |
| Q3 2024 | 2 | €1.05m |
| Q4 2024 | 4 | €4.87m |
| Q1 2025 | 6 | €6.79m |
| Q2 2025 | 7 | €568.7m |
| Q3 2025 | 4 | €126.8m |
| Q4 2025 | 8 | €1.3bn |
| Q1 2026 | 4 | €43.1m |
| Q2 2026 | 4 | €11.1m |
| Q3 2026 | 5 | €902.2m |
49 cases
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking €11.7m
From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.
Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.
Coordination with cooperation partners on customers and tenders
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Published
- 26 Aug 2026
Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.
- Fines exceeding CZK 280 million imposed on O2 Czech Republic and SHERLOG Technology for cartel agreement Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering €890m
In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.
Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Jul 2026
- Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
- IP/26/1670: Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay €240,000
Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.
Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.
Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 20 Jul 2026
- TeamViewer SE: BaFin setzt Geldbuße fest Decision of an authority
- Bekanntmachung der BaFin zur TeamViewer SE (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Portugal: 8.18 million EUR against three companies over advertising in TV recordings €8.18m
With the support of a consultancy, the three largest pay-TV providers agreed from 2019 to May 2025 to introduce advertising as a condition for accessing recordings and to standardise the marketing of this advertising space. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,181,000 EUR on three companies; together with the fourth participant, already sanctioned earlier under a settlement, the fines add up to 13,351,000 EUR. Owing to ongoing court proceedings, the AdC did not publish the names in its announcement.
Jointly coordinated ‘industry solutions’ at customers’ expense are cartels – even when a service provider takes on the coordination.
Coordinated product changes among competitors
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º (Processo PRC/2020/4)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 5 Jun 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students Order
According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.
Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.
- Authority / court
- Federal Trade Commission (FTC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- FTC Act (Verbot unlauterer und irreführender Praktiken)
- Action
- Order
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 5 Jun 2026
- FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students' Personal Data Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 May 2026 Sabre Global Technologies LimitedSabre subsidiary accepted payments from designated Ural Airlines €1.16m
The provider of a travel booking system continued to provide services to Ural Airlines, designated in May 2022, requested payments of around 906,600 USD and, after the funds were frozen by the bank, looked for alternative payment routes, which HM Treasury's Office of Financial Sanctions Implementation (OFSI) regarded as circumvention. A lack of escalation during a change of roles, vacant leadership positions in legal and compliance, policies focused on US law and screening that did not flag the designation all contributed.
If an existing customer is designated, escalate this immediately; looking for alternative payment routes after the bank has frozen funds is itself a breach.
Responding to new designations of existing customers, prohibition of circumvention
- Authority / court
- HM Treasury, Office of Financial Sanctions Implementation (OFSI)
- Area of law
- Sanctions and export control · Breaches of sanctions and embargoes
- Legal basis
- Russia (Sanctions) (EU Exit) Regulations 2019, regs. 13, 14, 19
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Voluntary disclosure (31 October 2022) and full cooperation; settlement under the new settlement procedure
- Published
- 17 Jun 2026
Original amount 1,000,920.59 GBP, converted at the ECB reference rate of 26 May 2026.
- OFSI: Imposition of Monetary Penalty – Sabre Global Technologies Limited Decision of an authority
- OFSI – Enforcement of financial sanctions (Sammlung) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy €5,000
Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.
Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.
Right of access to call recordings
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15 Abs. 1 und 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 25 Mar 2026
- Finlex – Tietosuojavaltuutettu 2.3.2026 (puhelutallenteet) Decision of an authority
- Tietosuojavaltuutettu – Suomen Numerokeskukselle seuraamusmaksu puutteista puhelutallenteiden antamisessa (25.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Périphériques et Matériels de Contrôle SAS (Groupe Carrus)Betting terminal manufacturer PMC: CJIP over payments to the head of state-owned PMU Mali €499,150
From 2008 to 2011, the Paris-based supplier of betting and gaming terminals made unjustified payments of 78,972 EUR to the head of the majority state-owned Pari Mutuel Urbain Mali, with which it had a supply contract awarded without a tender. The case was triggered by a report from TRACFIN (the French financial intelligence unit). Public interest fine of 499,150 EUR (including 335,000 EUR already seized) and a three-year AFA compliance programme.
Managers of state-controlled companies are also public officials – even small private payments to them create a risk of criminal liability for medium-sized companies.
Payments to heads of state-owned companies abroad
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger und Geldwäsche
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 50 to 249
- Culpability
- intentional
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 18 Feb 2026
- Communiqué de presse du procureur de la République financier – CJIP PMC Press release of an authority
- Convention judiciaire d'intérêt public – Périphériques et Matériels de Contrôle SAS Decision of an authority
- Ministère de la Justice: Conventions judiciaires d'intérêt public (Verzeichnis) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data €564,626
The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).
Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
- Published
- 26 Jan 2026
Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.
- IMY – Tillsyn Sportadmin i Skandinavien AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2025-7801 (26.01.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts €42m
Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.
Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
- Published
- 14 Jan 2026
- Violation de données : sanction de 42 millions d'euros à l'encontre des sociétés FREE MOBILE et FREE Press release of an authority
- Délibération SAN-2026-001 du 8 janvier 2026 (FREE MOBILE) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws €1.7m
As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.
Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Délibération SAN-2025-015 du 22 décembre 2025 (NEXPUBLICA FRANCE) Decision of an authority
- Les sanctions prononcées par la CNIL Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Snowball.xyz-Gruppe (Snowball.xyz, Šviesa, Tavo mokykla, Ateities pamoka) und AL holdingas-Gruppe (AL holdingas, Ugdymo sprendimai, UNT nuoma)E-register providers shared the market – 3.6 million EUR in cartel fines €3.63m
In August 2020, the operators of the electronic class registers ‘Tamo’ and ‘Eduka’ agreed to stop competing: one group kept the class register business, the other took over the digital learning content. Following acknowledgement of the infringement, the fines were reduced by 15%: 2,714,940 EUR jointly and severally for the Snowball.xyz group and 913,340 EUR for the AL holdingas group (Art. 101 TFEU). The decision can be appealed. Source: archived copy of the press release.
Agreements between competitors on ‘who does what’ are cartels – even when dressed up as portfolio streamlining.
Market sharing among competitors
- Authority / court
- Konkurencijos taryba (Litauischer Wettbewerbsrat)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Konkurencijos įstatymas; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Acknowledgement of the infringement (15% reduction)
- Published
- 18 Dec 2025
- Konkurencijos taryba, Pranešimas 2025-12-18 (Archivkopie web.archive.org von kt.gov.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Bravogroup Holding Vagyonkezelő Kft.Bravogroup: 32.6 million HUF for unnotified stake in Xiaomi distributor €84,042
In February 2023, the IT holding company acquired a 50% stake with negative sole control in the Xiaomi distributor Mystical Hungary Zrt., but only approached the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) after 582 days and notified the concentration thereafter. Following voluntary disclosure, acknowledgement and waiver of legal remedies, the authority imposed a significantly reduced 32.6 million HUF.
Blocking rights (negative control) can also trigger a notification requirement – review stakes under merger control law before signing.
Merger control for minority stakes with veto rights
- Authority / court
- Gazdasági Versenyhivatal (GVH)
- Area of law
- Competition law · Merger control
- Legal basis
- Ungarisches Wettbewerbsgesetz, Vollzugsverbot (VJ/20/2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Voluntary disclosure, acknowledgement and waiver of legal remedies.
- Published
- 18 Dec 2025
Original amount 32,600,000 HUF, converted at the ECB reference rate of 18 Dec 2025.
- Bejelentés és engedély nélkül végrehajtott fúzió miatt bírságolt a GVH Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis €5,000
The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.
Data brokers must be able to prove for every record on which legal basis it was collected and resold.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database €1.39m
In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.
Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.
Separation of personal and work devices and credentials
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 11 Dec 2025
Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.
- Password manager provider fined £1.2m by ICO for data breach Press release of an authority
- ICO Enforcement: LastPass UK Ltd Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses €4.5m
The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.
Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 14 Nov 2025
- AZOP: Administrative Fine of EUR 4.5 Million Imposed on a Telecommunications Operator (14.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Nov 2025 Comunicaciones Celulares S.A. (TIGO Guatemala)TIGO Guatemala pays more than 118 million USD for bribing members of Congress €102.1m
From 2012 to 2018, the Guatemalan mobile network operator made monthly cash payments to members of Congress or their security staff in order to obtain legislative support; part of the funds came from laundered drug money. Two-year Deferred Prosecution Agreement with a criminal penalty of 60 million USD and administrative forfeiture of 58,198,343 USD.
In joint ventures with local partners, the parent company needs genuine control over cash flows and contacts with public officials – an early voluntary self-disclosure is no substitute for a full investigation.
Bribery of public officials, cash payments, integrity of co-shareholders
- Authority / court
- U.S. Department of Justice (Criminal Division, Fraud Section; USAO Southern District of Florida)
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- FCPA, 15 U.S.C. § 78dd-3 (Verschwörung, 18 U.S.C. § 371); Deferred Prosecution Agreement
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure by the parent company Millicom in 2015; subsequently extensive cooperation and remediation (including dismissals of staff and an 800 % increase in compliance personnel).
- Liability of senior managers
- According to the DOJ, the scheme was directed by the then Guatemalan shareholder and other senior individuals; four individuals had already been charged (not named).
- Published
- 12 Dec 2025
Original amount 118,198,343 USD, converted at the ECB reference rate of 12 Nov 2025.
- TIGO Guatemala Paid Over $118M to Resolve Foreign Bribery Investigation Press release of an authority
- Deferred Prosecution Agreement, United States v. Comunicaciones Celulares S.A. d/b/a TIGO Guatemala (Case 1:25-cr-20476) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link