Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

49cases from 23 jurisdictions
€3.03bnTotal of monetary amounts (43 cases with an amount)
€1.19bnLargest single case: Google LLC
€1.72mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€19.4m
Q1 20241€157,176
Q2 20243€44.4m
Q3 20242€1.05m
Q4 20244€4.87m
Q1 20256€6.79m
Q2 20257€568.7m
Q3 20254€126.8m
Q4 20258€1.3bn
Q1 20264€43.1m
Q2 20264€11.1m
Q3 20265€902.2m

49 cases

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking CzechiaCartels and collusion €11.7m

From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.

What organisations can take from it

Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.

Relevance to training and awareness

Coordination with cooperation partners on customers and tenders

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Published
26 Aug 2026

Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering EU levelPlatform obligations €890m

In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.

What organisations can take from it

Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay GermanyDisclosure and reporting obligations €240,000

Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.

What organisations can take from it

Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.

Relevance to training and awareness

Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Portugal: 8.18 million EUR against three companies over advertising in TV recordings PortugalCartels and collusion €8.18m

With the support of a consultancy, the three largest pay-TV providers agreed from 2019 to May 2025 to introduce advertising as a condition for accessing recordings and to standardise the marketing of this advertising space. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,181,000 EUR on three companies; together with the fourth participant, already sanctioned earlier under a settlement, the fines add up to 13,351,000 EUR. Owing to ongoing court proceedings, the AdC did not publish the names in its announcement.

What organisations can take from it

Jointly coordinated ‘industry solutions’ at customers’ expense are cartels – even when a service provider takes on the coordination.

Relevance to training and awareness

Coordinated product changes among competitors

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º (Processo PRC/2020/4)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students USAData breaches and data security Order

According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.

What organisations can take from it

Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.

Authority / court
Federal Trade Commission (FTC)
Area of law
Data protection · Data breaches and data security
Legal basis
FTC Act (Verbot unlauterer und irreführender Praktiken)
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Sabre Global Technologies LimitedSabre subsidiary accepted payments from designated Ural Airlines United KingdomBreaches of sanctions and embargoes €1.16m

The provider of a travel booking system continued to provide services to Ural Airlines, designated in May 2022, requested payments of around 906,600 USD and, after the funds were frozen by the bank, looked for alternative payment routes, which HM Treasury's Office of Financial Sanctions Implementation (OFSI) regarded as circumvention. A lack of escalation during a change of roles, vacant leadership positions in legal and compliance, policies focused on US law and screening that did not flag the designation all contributed.

What organisations can take from it

If an existing customer is designated, escalate this immediately; looking for alternative payment routes after the bank has frozen funds is itself a breach.

Relevance to training and awareness

Responding to new designations of existing customers, prohibition of circumvention

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, regs. 13, 14, 19
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Voluntary disclosure (31 October 2022) and full cooperation; settlement under the new settlement procedure
Published
17 Jun 2026

Original amount 1,000,920.59 GBP, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff ItalyData breaches and data security €1.72m

Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.

What organisations can take from it

Staff in branches and partner shops must verify alleged support calls before granting access.

Relevance to training and awareness

Social engineering / fake IT support

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO (Integrität und Vertraulichkeit, Art. 32)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy FinlandData subject rights and transparency €5,000

Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.

What organisations can take from it

Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.

Relevance to training and awareness

Right of access to call recordings

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15 Abs. 1 und 3
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Périphériques et Matériels de Contrôle SAS (Groupe Carrus)Betting terminal manufacturer PMC: CJIP over payments to the head of state-owned PMU Mali FranceBribery of public officials €499,150

From 2008 to 2011, the Paris-based supplier of betting and gaming terminals made unjustified payments of 78,972 EUR to the head of the majority state-owned Pari Mutuel Urbain Mali, with which it had a supply contract awarded without a tender. The case was triggered by a report from TRACFIN (the French financial intelligence unit). Public interest fine of 499,150 EUR (including 335,000 EUR already seized) and a three-year AFA compliance programme.

What organisations can take from it

Managers of state-controlled companies are also public officials – even small private payments to them create a risk of criminal liability for medium-sized companies.

Relevance to training and awareness

Payments to heads of state-owned companies abroad

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger und Geldwäsche
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
50 to 249
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data SwedenData breaches and data security €564,626

The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).

What organisations can take from it

Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
Published
26 Jan 2026

Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts FranceData breaches and data security €42m

Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.

What organisations can take from it

Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
Published
14 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws FranceData processors €1.7m

As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.

What organisations can take from it

Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Snowball.xyz-Gruppe (Snowball.xyz, Šviesa, Tavo mokykla, Ateities pamoka) und AL holdingas-Gruppe (AL holdingas, Ugdymo sprendimai, UNT nuoma)E-register providers shared the market – 3.6 million EUR in cartel fines LithuaniaCartels and collusion €3.63m

In August 2020, the operators of the electronic class registers ‘Tamo’ and ‘Eduka’ agreed to stop competing: one group kept the class register business, the other took over the digital learning content. Following acknowledgement of the infringement, the fines were reduced by 15%: 2,714,940 EUR jointly and severally for the Snowball.xyz group and 913,340 EUR for the AL holdingas group (Art. 101 TFEU). The decision can be appealed. Source: archived copy of the press release.

What organisations can take from it

Agreements between competitors on ‘who does what’ are cartels – even when dressed up as portfolio streamlining.

Relevance to training and awareness

Market sharing among competitors

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Cartels and collusion
Legal basis
Konkurencijos įstatymas; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Acknowledgement of the infringement (15% reduction)
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Bravogroup Holding Vagyonkezelő Kft.Bravogroup: 32.6 million HUF for unnotified stake in Xiaomi distributor HungaryMerger control €84,042

In February 2023, the IT holding company acquired a 50% stake with negative sole control in the Xiaomi distributor Mystical Hungary Zrt., but only approached the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) after 582 days and notified the concentration thereafter. Following voluntary disclosure, acknowledgement and waiver of legal remedies, the authority imposed a significantly reduced 32.6 million HUF.

What organisations can take from it

Blocking rights (negative control) can also trigger a notification requirement – review stakes under merger control law before signing.

Relevance to training and awareness

Merger control for minority stakes with veto rights

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Merger control
Legal basis
Ungarisches Wettbewerbsgesetz, Vollzugsverbot (VJ/20/2025)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Voluntary disclosure, acknowledgement and waiver of legal remedies.
Published
18 Dec 2025

Original amount 32,600,000 HUF, converted at the ECB reference rate of 18 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis BelgiumMarketing and consent €5,000

The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.

What organisations can take from it

Data brokers must be able to prove for every record on which legal basis it was collected and resold.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database United KingdomData breaches and data security €1.39m

In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.

What organisations can take from it

Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.

Relevance to training and awareness

Separation of personal and work devices and credentials

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
11 Dec 2025

Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses CroatiaInternational data transfers €4.5m

The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.

What organisations can take from it

Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2025 Comunicaciones Celulares S.A. (TIGO Guatemala)TIGO Guatemala pays more than 118 million USD for bribing members of Congress USABribery of public officials €102.1m

From 2012 to 2018, the Guatemalan mobile network operator made monthly cash payments to members of Congress or their security staff in order to obtain legislative support; part of the funds came from laundered drug money. Two-year Deferred Prosecution Agreement with a criminal penalty of 60 million USD and administrative forfeiture of 58,198,343 USD.

What organisations can take from it

In joint ventures with local partners, the parent company needs genuine control over cash flows and contacts with public officials – an early voluntary self-disclosure is no substitute for a full investigation.

Relevance to training and awareness

Bribery of public officials, cash payments, integrity of co-shareholders

Authority / court
U.S. Department of Justice (Criminal Division, Fraud Section; USAO Southern District of Florida)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA, 15 U.S.C. § 78dd-3 (Verschwörung, 18 U.S.C. § 371); Deferred Prosecution Agreement
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure by the parent company Millicom in 2015; subsequently extensive cooperation and remediation (including dismissals of staff and an 800 % increase in compliance personnel).
Liability of senior managers
According to the DOJ, the scheme was directed by the then Guatemalan shareholder and other senior individuals; four individuals had already been charged (not named).
Published
12 Dec 2025

Original amount 118,198,343 USD, converted at the ECB reference rate of 12 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data USA, TXCookies and tracking €1.19bn

Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.

What organisations can take from it

Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.

Authority / court
Office of the Attorney General of Texas
Area of law
Data protection · Cookies and tracking
Action
Other
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
31 Oct 2025

Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Sep 2025 „Смарт Софт“ ЕООДBidder Smart Soft denigrates competitor in letters to schools – 37,410 leva BulgariaCompetition law €19,128

During ongoing tenders for school equipment, Smart Soft sent dozens of identical letters to schools in the Plovdiv/Pazardzhik/Panagyurishte region containing untrue or distorted statements about its competitor Evroklas-konsult. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act) over around two months and imposed 3% of 2024 turnover, i.e. 37,410 leva. An appeal has been lodged against the decision.

What organisations can take from it

Have sales letters about competitors – especially to public contracting authorities – legally reviewed before they are sent.

Relevance to training and awareness

Communication about competitors in sales

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software

Original amount 37,410 BGN, converted at the ECB reference rate of 25 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Sep 2025 Chegg Inc.Chegg pays 7.5 million USD in FTC settlement over allegations of obstructed subscription cancellation USAInformation duties in online retail €6.35m

According to the FTC complaint, the education provider hid the cancellation option for its automatically renewing subscriptions on its website and, since October 2020, continued to charge almost 200,000 customers even after they had cancelled. Under the settlement, Chegg is paying 7.5 million USD for refunds and must offer simple cancellation.

What organisations can take from it

Cancellations received must be reliably implemented in the systems – continuing to charge customers is a separate violation.

Relevance to training and awareness

Cancellation processes and customer service for subscriptions

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Restore Online Shoppers' Confidence Act (ROSCA); Section 5 FTC Act
Action
Disgorgement of profits
Status of proceedings
final
Sector
Telecoms, IT and software
Repeat case
yes
Published
15 Sep 2025

Original amount 7,500,000 USD, converted at the ECB reference rate of 18 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor LatviaData breaches and data security €300,000

Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.

What organisations can take from it

Processors are also independently liable for the security of the systems they operate.

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2025 Cadence Design Systems Inc.Cadence pleads guilty: chip design software for Chinese military university USAExport control and dual-use goods €120.1m

From 2015 to 2021, the San José provider of chip design software supplied hardware, software and semiconductor IP at least 59 times to the National University of Defense Technology (NUDT), a military university on the Entity List, disguised under the alias Central South CAD Center. Cadence pleaded guilty before the US Department of Justice to conspiracy to commit export control violations; criminal penalties of almost 118 million USD and civil penalties of more than 95 million USD imposed by the Bureau of Industry and Security (BIS) result, after crediting, in a net total of more than 140 million USD.

What organisations can take from it

Include cover names and known aliases of listed customers in screening; sales and compliance must escalate indications of military end users.

Relevance to training and awareness

Recognising aliases and cover names of listed customers

Authority / court
U.S. Department of Justice; Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations (Entity List); ECRA; Verschwörung zu Exportkontrollverstößen
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Culpability
intentional
Published
28 Jul 2025

Original amount 140,000,000 USD, converted at the ECB reference rate of 28 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names GreeceData processors €700,000

Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.

What organisations can take from it

Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.

Relevance to training and awareness

Identity verification when concluding contracts in partner distribution

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jun 2025 Exclusive Networks Corporate SASIT distributor Exclusive Networks: CJIP of 16 million EUR following a whistleblower report FranceCommercial bribery €16.1m

In 2021, a whistleblower reported payments by subsidiaries in Indonesia, Malaysia, Vietnam, Thailand and India to contractual partners; the investigation concerned private-sector bribery and bribery of foreign public officials. The CJIP provides for a public interest fine of 16,074,511 EUR (including 1 million EUR already seized) and a three-year AFA compliance programme.

What organisations can take from it

A functioning whistleblowing system uncovers foreign risks – companies should investigate reports themselves before the authorities do.

Relevance to training and awareness

Payments to sales partners in Asia, whistleblowing systems

Authority / court
Parquet national financier (PNF); Validierung durch das Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung im privaten Sektor und ausländischer Amtsträger
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
1,000 to 9,999
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 May 2025 Xfera Móviles, S.A.U.AEPD: 200,000 EUR against Xfera (MásMóvil) over number porting without consent SpainData breaches and data security €200,000

A customer's mobile number was ported to MásMóvil without the customer having requested it; the new SIM card was handed over to a third party who did not identify themselves. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found processing without a legal basis, imposed 200,000 EUR and ordered measures against such incidents; the company's request for reconsideration was unsuccessful.

What organisations can take from it

Issue SIM cards and carry out porting only after robust identity verification – couriers and sales partners must comply with this too.

Relevance to training and awareness

Identity verification for porting and SIM handover (SIM swapping)

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2025 SAP SESAP: failure to publish notice on the 2022 annual financial report GermanyDisclosure and reporting obligations €1.75m

SAP had not published an announcement stating from when and at which internet address the 2022 annual financial report was publicly available in addition to the company register (Hinweisbekanntmachung). BaFin imposed a fine of 1.75 million EUR; the notice is final.

What organisations can take from it

Even seemingly formal disclosure steps such as the notice announcement need a fixed place in the financial calendar – the range of fines extends up to five per cent of total turnover.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 114 Abs. 1 Satz 2 WpHG
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
27 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2025 AppleDMA: 500 million EUR against Apple over anti-steering in the App Store EU levelPlatform obligations €500m

In one of the first non-compliance decisions under the Digital Markets Act (DMA), the European Commission found that Apple prevents app developers from informing customers free of charge about cheaper offers outside the App Store and steering them there. In addition to a fine of 500 million EUR, the removal of the restrictions within 60 days was ordered, failing which periodic penalty payments may be imposed.

What organisations can take from it

Gatekeepers must allow business users to communicate freely with their customers; technical or commercial hurdles are treated as circumvention.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Apr 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Apr 2025 Luka Inc.Garante: 5 million EUR against Replika operator Luka over lack of legal basis ItalyAI systems €5m

The US operator of the Replika chatbot had not determined a legal basis for the processing, had an inadequate privacy notice and, despite declaring that minors were excluded, had no age verification. Italy's data protection authority (Garante per la protezione dei dati personali) imposed 5 million EUR and opened further proceedings concerning the training of the underlying language model.

What organisations can take from it

A declared exclusion of minors is worthless without effective age verification at registration and during use.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO (Rechtmäßigkeit, Transparenz, Schutz Minderjähriger)
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Published
19 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA United KingdomData processors €3.68m

Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.

What organisations can take from it

MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data processors
Legal basis
UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
Published
27 Mar 2025

Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2025 AppleApple: Commission sets out specific interoperability obligations for iOS by DMA decision EU levelPlatform obligations Order

In two specification decisions under the Digital Markets Act, the European Commission set out which interoperability measures Apple must take: access for manufacturers of connected devices to nine iOS features (such as notifications on smartwatches, peer-to-peer Wi-Fi, NFC, pairing) and a more transparent and faster procedure for developers’ interoperability requests.

What organisations can take from it

Gatekeepers must actively open interfaces – anyone handling third-party requests sluggishly risks detailed regulatory requirements.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Markets Act (Verordnung (EU) 2022/1925): Interoperabilitätspflicht, Spezifizierungsbeschlüsse
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2025 Inetum (drei Gesellschaften der Unternehmensgruppe)Portugal: 3.09 million EUR against Inetum for no-poach agreements, upheld by court PortugalCartels and collusion €3.09m

From 2014 to 2021, the IT consultancy group participated in bilateral agreements not to poach competitors’ employees. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 3,092,000 EUR on three companies; in March 2026, the Competition, Regulation and Supervision Court (TCRS) upheld the fine in full – the first judicial confirmation of a labour market cartel fine in Portugal.

What organisations can take from it

Agreements not to poach each other’s skilled staff are cartels – HR and managers must be aware of this.

Relevance to training and awareness

Prohibition of no-poach agreements between competitors

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
19 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jan 2025 Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; Beijing DeepSeek Artificial Intelligence Co., Ltd.Garante blocks DeepSeek: immediate limitation of processing for Italian users ItalyAI systems Order

After the Chinese providers had declared that they did not operate in Italy and were not subject to the GDPR, Italy's data protection authority (Garante per la protezione dei dati personali) ordered, as a matter of urgency and with immediate effect, the limitation of the processing of Italian users' data and opened an investigation.

What organisations can take from it

Companies that offer AI services to European users are subject to the GDPR – regardless of where they are headquartered.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO, Art. 58 Abs. 2 lit. f (Beschränkung der Verarbeitung)
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
30 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2025 Mobile TeleSystems Public Joint Stock Company (MTS)Federal Court dismisses mobile operator MTS's challenge to sanctions listing CanadaBreaches of sanctions and embargoes Order

Russia's largest mobile and fixed-line operator challenged its inclusion on the Canadian Russia sanctions list directly in court. The Federal Court (2025 FC 181) upheld the striking out of the application, sought by the Attorney General of Canada, without leave to amend, because MTS should first have used the delisting procedure before the Minister provided for in the Regulations.

What organisations can take from it

The route against a sanctions listing is first the administrative delisting procedure; business partners must observe the listing until then.

Authority / court
Federal Court (2025 FC 181); Attorney General of Canada
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Special Economic Measures Act; Regulations Amending the Special Economic Measures (Russia) Regulations, SOR/2023-163, s. 8
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees RomaniaData breaches and data security €14,974

Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.

Relevance to training and awareness

BCC, use of messaging apps, sending customer documents

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
20 Jan 2025

Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2024 Ericsson Nikola Tesla d.d., Kodeks d.o.o., Retel d.o.o., Vatel d.o.o., LUMISS d.o.o., Mitel Austria GmbHCroatia: 1.17 million EUR against Ericsson Nikola Tesla and five partners for customer allocation CroatiaCartels and collusion €1.17m

From 2010 to 2015, the suppliers of Ericsson/Aastra/Mitel telephone systems (PBX) allocated customers among themselves so as not to undercut each other. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed a total of 1,170,968.24 EUR, of which 785,570.58 EUR on Ericsson Nikola Tesla; one leniency applicant (Steiner) was not penalised, and Kodeks received a reduction.

What organisations can take from it

Dealers of the same brand are also competitors – agreements on ‘own’ customers are a hardcore cartel.

Relevance to training and awareness

No agreements on customer or territorial allocation

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 8 Zakon o zaštiti tržišnog natjecanja (ZZTN)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Leniency programme for two participants
Published
5 Mar 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware DenmarkData processors €5,363

As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.

What organisations can take from it

A backup only counts if restoration is tested regularly – including access to the keys.

Authority / court
Dänisches Gericht auf Anzeige der Datatilsynet
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO; Auftragsverarbeitungsvertrag
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Nov 2024 OpenAIGarante: 15 million EUR against OpenAI over ChatGPT – later annulled by the court ItalyAI systems overturned

Italy's data protection authority (Garante per la protezione dei dati personali) imposed 15 million EUR because OpenAI trained ChatGPT with user data without an appropriate legal basis, breached transparency obligations, failed to report a data breach from March 2023 and did not provide for age verification; in addition, a six-month information campaign was ordered. The Rome Court (Tribunale di Roma) upheld OpenAI's action in judgment no. 4153/2026 (published on 18 March 2026); the Garante subsequently removed the decision from its website.

What organisations can take from it

Companies that train AI models with personal data need a documented legal basis and age verification in advance.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO (Rechtsgrundlage, Transparenz, Meldung von Datenpannen, Schutz Minderjähriger)
Action
Fine
Status of proceedings
overturned
Sector
Telecoms, IT and software
Published
20 Dec 2024

Amount in EUR; no ECB reference rate is available for this currency.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Oct 2024 Unisys Corp.SEC: $4 million against Unisys for downplaying cyber incidents after SolarWinds USADisclosure and reporting obligations €3.7m

In mandatory disclosures, Unisys presented cyber risks as hypothetical, although it had suffered two intrusions with data exfiltration connected with the SolarWinds compromise. On the same day, the US Securities and Exchange Commission (SEC) also imposed penalties on Avaya ($1 million), Check Point ($995,000) and Mimecast ($990,000).

What organisations can take from it

Do not describe cyber incidents that have occurred as a mere risk in investor information – disclosure processes must involve IT security.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Securities Act of 1933, Securities Exchange Act of 1934 (inkl. Disclosure Controls)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Cooperation in the proceedings and improvement of cybersecurity controls.
Published
22 Oct 2024

Original amount 4,000,000 USD, converted at the ECB reference rate of 22 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Sep 2024 AppFolio, Inc.SEC: AppFolio pays 692,250 US dollars over waivers of whistleblower awards USARetaliation against whistleblowers €626,868

The provider of property management software had employees waive potential awards for reports to authorities in two employment agreements and one settlement agreement; 68 consulting agreements (January 2020 to October 2023) prohibited voluntary disclosures to authorities. As part of a sweep against seven listed companies, AppFolio paid 692,250 US dollars to the U.S. Securities and Exchange Commission (SEC); the contract templates were amended.

What organisations can take from it

Separation and employment agreements must restrict neither reports to authorities nor the entitlement to whistleblower awards.

Relevance to training and awareness

Whistleblower protection in contract templates (HR/Legal)

Authority / court
U.S. Securities and Exchange Commission
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Securities Exchange Act of 1934, Rule 21F-17(a)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Amendment of the templates after contact by the SEC, information provided to those affected, and cooperation
Published
9 Sep 2024

Original amount 692,250 USD, converted at the ECB reference rate of 9 Sep 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jul 2024 Parrot SAParrot: misleading half-yearly report and insider dealing ahead of a takeover bid FranceMarket abuse and insider dealing €420,000

In its 2018 half-yearly report, the drone manufacturer disseminated misleading information on the absence of impairment indicators for the drone division, on goodwill and on earnings; in addition, the deputy managing director used inside information about a planned takeover bid. Sanctions: Parrot 150,000 EUR, CEO Henri Seydoux 60,000 EUR, Gilles Labossière 210,000 EUR.

What organisations can take from it

Impairment tests for loss-making divisions and trading bans for management are particularly sensitive in a takeover context.

Relevance to training and awareness

Insider dealing ban for executives in connection with takeover plans

Authority / court
Autorité des marchés financiers (AMF), Commission des sanctions
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Art. 12 Abs. 1 lit. c, Art. 15 MAR; Art. 8 und 14 MAR
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Liability of senior managers
Henri Seydoux (Président-directeur général): 60,000 EUR; Gilles Labossière (directeur général délégué): 210,000 EUR, including for insider dealing
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 May 2024 Clearview AI Inc.Dutch AP: 30.5 million EUR against Clearview AI over facial database NetherlandsAI systems €30.5m

Clearview processes biometric data of people in the Netherlands without a legal basis for a facial recognition database compiled from the internet, did not inform data subjects, did not respond to access requests and did not designate an EU representative. In addition to a fine of 30.5 million EUR, the Dutch data protection authority (Autoriteit Persoonsgegevens, AP) imposed four orders subject to penalty payments.

What organisations can take from it

Publicly accessible photos are no licence for biometric analysis – users of such services risk fines of their own.

Authority / court
Autoriteit Persoonsgegevens
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, 6 Abs. 1, 9 Abs. 1, 12, 14, 15, 27
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
3 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2024 Xplain AG; Bundesamt für Polizei (fedpol); Bundesamt für Zoll und Grenzsicherheit (BAZG)FDPIC: data protection infringements at Xplain, fedpol and FOCBS after ransomware attack SwitzerlandData processors Other

Following the hacker attack on the IT service provider Xplain, the Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) found that personal data of the Federal Office of Police (fedpol) and the Federal Office for Customs and Border Security (BAZG) had reached Xplain via support processes without the necessary data protection safeguards. Xplain subsequently retained the data in breach of data protection law and partly in breach of contract.

What organisations can take from it

Real data does not belong in service providers' support and test environments – clients must control disclosure and deletion.

Relevance to training and awareness

Passing real data to service providers for support

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data processors
Legal basis
Datenschutzgesetz (DSG)
Action
Other
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
1 May 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2024 Avast Software s.r.o.Avast: 351 million CZK for passing browsing histories to Jumpshot CzechiaData subject rights and transparency €13.9m

In 2019, the antivirus manufacturer passed pseudonymised browsing histories of around 100 million users to its subsidiary Jumpshot, which sold insights into online behaviour to marketing clients. The data declared as anonymous allowed re-identification and users were misinformed; the Úřad pro ochranu osobních údajů (Czech data protection authority, ÚOOÚ) imposed a final fine of 351 million CZK.

What organisations can take from it

Pseudonymised data are not anonymous data – anyone passing on usage data must assess re-identification risks and inform users honestly.

Authority / court
Úřad pro ochranu osobních údajů (ÚOOÚ)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (unrechtmäßige Verarbeitung, Transparenz), One-Stop-Shop-Verfahren
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
15 Apr 2024

Original amount 351,000,000 CZK, converted at the ECB reference rate of 15 Apr 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jan 2024 Black Tiger Belgium (vormals Bisnode Belgium)Black Tiger Belgium: fine for non-transparent data trading, reduced by 10% in court BelgiumData subject rights and transparency €157,176

The data broker processed data obtained from third-party sources (including the companies register) on a large scale and over a long period without proactively informing the data subjects; access requests were answered incompletely and the record of processing activities had gaps. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed three fines totalling 174,640 EUR and prohibited, among other things, the ‘Data Quality’ service until data subjects had been informed; on 4 September 2024 the Brussels Market Court set aside the orders and reduced the fines by 10% to a total of 157,176 EUR.

What organisations can take from it

Anyone collecting data indirectly must actively inform data subjects – legitimate interest does not hold where laws prohibit further use.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO – Rechtmäßigkeit, Fairness und Transparenz, Auskunftsrecht, Verzeichnis von Verarbeitungstätigkeiten
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software
Mitigating circumstances
Discontinuation of the ‘Data Delivery’ service and destruction of the CMX consumer database.
Published
16 Jan 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Dec 2023 Swisscom (Schweiz) AGWEKO: CHF 18.4 million against Swisscom over fibre network roll-out strategy SwitzerlandAbuse of market power €19.4m

Swisscom expanded its fibre-optic network in such a way that competitors were not given Layer 1 access from the local exchanges. WEKO considered this to be an abuse of a dominant position, imposed a sanction of CHF 18,362,014, required Swisscom to retrofit the network and imposed procedural costs of CHF 927,307.

What organisations can take from it

Dominant network operators must assess infrastructure decisions for their consequences for competitors' access.

Authority / court
Wettbewerbskommission (WEKO)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 7 Abs. 1 i.V.m. Abs. 2 lit. a und e KG, Art. 49a Abs. 1 KG
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Employees
10,000 or more

Original amount 18,362,014 CHF, converted at the ECB reference rate of 4 Dec 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial