Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by stateWhat for?
by area of lawAll areas of law
- Data protection €1.2bn 82 % · 7 cases
- Environment and sustainability €168.7m 12 % · 1 case
- Money laundering and terrorist financing €69.2m 5 % · 4 cases
- Health and safety and employment law €14.9m 1 % · 9 cases
- Information security and cyber €11m 1 % · 7 cases
- Consumer protection and online retail €4.14m 0 % · 1 case
Who?
by sectorAll sectors
- Telecoms, IT and software €1.19bn 81 % · 1 case
- Automotive €169.3m 12 % · 2 cases
- Financial services and insurance €73.5m 5 % · 10 cases
- Retail and e-commerce €12m 1 % · 5 cases
- Food and agriculture €7.34m 1 % · 3 cases
- Other €7.19m 0 % · 3 cases
- Media and online platforms €3.62m 0 % · 2 cases
- Healthcare €612,121 0 % · 1 case
- Steel and metals €180,168 0 % · 1 case
- Construction and real estate — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 2 | €913,159 |
| Q1 2024 | 1 | €929,541 |
| Q2 2024 | 2 | €6.12m |
| Q3 2024 | 1 | €1.53m |
| Q4 2024 | 0 | — |
| Q1 2025 | 2 | €2.5m |
| Q2 2025 | 2 | €36.4m |
| Q3 2025 | 6 | €31.1m |
| Q4 2025 | 7 | €1.21bn |
| Q1 2026 | 3 | €7.72m |
| Q2 2026 | 2 | €170.6m |
| Q3 2026 | 1 | €216,375 |
29 cases
5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies €216,375
The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.
Even small financial service providers must keep documented patch policies and regular risk assessments.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
- Published
- 5 Aug 2026
Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 May 2026 Volvo Group North America, LLCVolvo Group North America: settlement of around 197 million USD over undisclosed emission control devices €168.7m
Around 10,000 heavy-duty Volvo diesel engines from model years 2010 to 2016 used auxiliary emission control devices (AECDs) that were not disclosed during certification and emitted more NOx than permitted. The settlement with the California Air Resources Board (CARB) comprises 17.5 million USD in penalties and costs, 71 million USD for mitigation measures and 108 million USD for emission reduction projects in California.
Every emissions-relevant control function must be fully disclosed in the certification application; otherwise high settlement payments may follow years later.
- Authority / court
- California Air Resources Board (CARB)
- Area of law
- Environment and sustainability · Emissions and permits
- Legal basis
- Kalifornische Emissions- und Zertifizierungsvorschriften für schwere Nutzfahrzeugmotoren
- Action
- Fine
- Status of proceedings
- final
- Sector
- Automotive
- Employees
- 10,000 or more
- Mitigating circumstances
- Cooperation during the investigation; recall and extended warranty for engines from model years 2014 to 2016.
- Published
- 18 May 2026
Original amount 196,500,000 USD, converted at the ECB reference rate of 18 May 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification €1.92m
In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.
Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 30 Apr 2026
Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.
- DFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental Press release of an authority
- Consent Order to Delta Dental 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Feb 2026 All FAB Precision Sheetmetal, Inc.Sheet metal fabricator: second amputation on the same press brake – Cal/OSHA $212,850 €180,168
In June 2025, an employee in San Jose lost a finger on a press brake without guarding – identical to an accident in June 2024 for which the business had already been fined $43,500. The California Division of Occupational Safety and Health (Cal/OSHA) imposed $212,850 (including a wilful repeat violation); the employer appealed.
After an accident, retrofitting the machine is mandatory – an identical second accident will be treated as wilful.
- Authority / court
- California Division of Occupational Safety and Health (Cal/OSHA)
- Area of law
- Health and safety and employment law · Workplace safety and accidents
- Legal basis
- California Code of Regulations, Title 8 (Maschinenschutz)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Steel and metals
- Culpability
- intentional
- Repeat case
- yes
- Published
- 26 Feb 2026
Original amount 212,850 USD, converted at the ECB reference rate of 26 Feb 2026.
- Cal/OSHA cites San Jose sheet metal company more than $212,000 following amputation accident (DIR) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Feb 2026 Disney DTC, LLC und ABC Enterprises, Inc. (The Walt Disney Company)California: $2.75 million against Disney over incomplete opt-outs for streaming €2.31m
Disney implemented objections to the sale and sharing of data only for individual services or devices rather than across the whole account, continued to disclose data via embedded ad-tech providers and offered no opt-out in connected TV apps. It was the largest CCPA settlement at the time of the agreement with the Attorney General of California.
An opt-out must take effect across all services, devices and integrated third-party providers of an account.
- Authority / court
- Attorney General of California (California Department of Justice)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 11 Feb 2026
Original amount 2,750,000 USD, converted at the ECB reference rate of 11 Feb 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Feb 2026 Alco Harvesting LLC dba Bonipak Produce Inc. und verbundene UnternehmenBonipak: $6.175 million for farmworkers over undisclosed paid sick leave €5.22m
Following the COVID death of a farmworker in employer-provided housing, the California Labor Commissioner's Office sued the agricultural business in Santa Maria in 2021: more than 10,000 farmworkers, including H-2A seasonal workers, had not been informed of their entitlement to paid sick leave; in addition, there was unpaid travel time as well as overtime and minimum wage violations. The settlement of $6,175,000 (of which $4.2 million goes directly to workers) includes posting and reporting obligations.
Information obligations towards seasonal workers are not a formality – companies that leave workers in the dark about paid sick leave are liable for the consequences.
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- California Labor Code (Paid Sick Leave, COVID-19 Supplemental Paid Sick Leave, Mindestlohn, Überstunden)
- Action
- Other
- Status of proceedings
- final
- Sector
- Food and agriculture
- Published
- 4 Feb 2026
Original amount 6,175,000 USD, converted at the ECB reference rate of 4 Feb 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Dec 2025 Rickenbacher Data LLC (Datamasters)CPPA: $45,000 against data broker Datamasters over failure to register €38,275
Without registering as a data broker, the Texas reseller traded in the names and contact details of millions of people, sorted by illnesses such as Alzheimer's or addiction, by age, presumed ethnicity and political views. In addition to the fine, the California Privacy Protection Agency (CPPA) requires it to stop selling data on all Californians.
Companies that buy or sell address lists for advertising must check registration obligations – health-related lists are particularly risky.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- California Delete Act (Registrierungspflicht für Datenhändler)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Published
- 8 Jan 2026
Original amount 45,000 USD, converted at the ECB reference rate of 30 Dec 2025.
- CalPrivacy Data Broker Enforcement Strike Force: enforcement actions Press release of an authority
- CPPA Order of Decision: Rickenbacher Data LLC d/b/a Datamasters (ENF25-172-D-DA) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 Caesars Entertainment, Inc. / Desert Palace, LLC (Caesars Palace)Nevada: 7.8 million USD against Caesars over gambling by an illegal bookmaker €6.77m
On 13 November 2025, the Nevada Gaming Control Board (NGCB) filed a disciplinary complaint for unsuitable methods of operation in connection with the illegal bookmaker Mathew Bowyer and at the same time concluded a settlement of 7.8 million USD with conditions attached to the gaming licences. The conditions relate primarily to improving the AML programme and to additional training and awareness-raising for employees; the Nevada Gaming Commission (NGC) adopted the settlement as its order on 20 November 2025 (Case No. 25-03).
Casino staff must recognise high-risk players and unexplained sources of funds – revenue interests must not override AML obligations.
Checking the source of gambling funds, recognising high-risk customers
Missing or inadequate training played a role in the decision.
- Authority / court
- Nevada Gaming Commission (NGC) auf Beschwerde des Nevada Gaming Control Board (NGCB)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Glücksspielrecht Nevada (unsuitable methods of operation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 10,000 or more
- Mitigating circumstances
- Numerous remedial measures already implemented
- Published
- 13 Nov 2025
Original amount 7,800,000 USD, converted at the ECB reference rate of 20 Nov 2025.
- Nevada Gaming Control Board and Caesars Entertainment, Inc. Enter into Proposed Stipulation for Settlement Regarding Disciplinary Complaint Press release of an authority
- Nevada Gaming Commission – Disposition, November 2025 Agenda (20.11.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data €1.19bn
Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.
Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.
- Authority / court
- Office of the Attorney General of Texas
- Area of law
- Data protection · Cookies and tracking
- Action
- Other
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 31 Oct 2025
Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.
- Attorney General Ken Paxton Finalizes Historic Settlement with Google and Secures $1.375 Billion Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 TFG Holding, Inc.JustFab, ShoeDazzle, FabKids: 4.8 million USD settlement with 33 attorneys general over VIP membership €4.14m
According to the allegations of the attorneys general, the online fashion retailer enrolled buyers in a paid VIP membership programme without their express consent, presented prices in a misleading way and made cancellation difficult. Under the settlement with 32 states and D.C., TFG is providing around 3.8 million USD in automatic refunds and paying 1 million USD to the states; the settlement does not constitute an admission of guilt.
A purchase must not silently trigger a membership with monthly charges.
Subscription models and express consent at checkout
- Authority / court
- Attorney General of Pennsylvania (verhandelt mit Maryland, Texas und D.C.; Vergleich mit 33 Attorneys General)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Verbraucherschutzgesetze der beteiligten Bundesstaaten
- Action
- Disgorgement of profits
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Published
- 23 Oct 2025
Original amount 4,800,000 USD, converted at the ECB reference rate of 23 Oct 2025.
- AG Sunday Secures Settlement Valued at $4.8 Million with Online Clothing Retailer Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Oct 2025 Winsor Maintenance Inc., Main Source Group, Inc. u. a. sowie OptumCare Management LLC (Auftraggeberin)Cleaning companies/OptumCare: 438,204 USD – overtime and missed breaks €377,534
More than 90 cleaners in industrial, laboratory and healthcare facilities often worked beyond scheduled hours without overtime pay, received no compensation for split shifts and travel time and were unable to take breaks because of excessive workloads. A web of companies owned by the Hong family concealed the employer; the Notice of Final Findings of 21 October 2025 established 438,204 USD, with OptumCare jointly liable as the client.
Clients of cleaning and service providers should check working hours and breaks at the provider – otherwise they are jointly liable.
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code § 2810.3; Overtime, Split Shift, Meal and Rest Periods, Mindestlohn
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Other
- Liability of senior managers
- Members of the owning family and an acquaintance cited personally.
- Published
- 24 Nov 2025
Original amount 438,204 USD, converted at the ECB reference rate of 21 Oct 2025.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools €2.4m
Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.
Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 14 Oct 2025
Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- DFS Secures More than $19 Million from Auto Insurance Companies over Data Breaches Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2025 Tractor Supply CompanyCPPA: $1.35 million against Tractor Supply over missing opt-out mechanisms €1.16m
The rural retail giant inadequately informed consumers and job applicants about their rights, offered no effective means of opting out of the sale and sharing of data (including no Global Privacy Control) and passed data on to third parties without the required contracts. An officer must certify compliance annually for four years, as required by the California Privacy Protection Agency (CPPA).
Privacy notices must also cover job applicants, and browser opt-out signals such as GPC must be implemented technically.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 30 Sep 2025
Original amount 1,350,000 USD, converted at the ECB reference rate of 26 Sep 2025.
- CPPA: Tractor Supply Company enforcement decision Press release of an authority
- CPPA Order of Decision and Stipulated Final Order: Tractor Supply Company (ENF24-M-TR-04) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Midri, Inc. (Restaurant J BBQ, Los Angeles)Restaurant J BBQ: 680,238 USD – breaks denied, split shifts without premium €584,046
The Koreatown restaurant regularly denied 48 employees meal and rest breaks, required them to remain available for guests even during the lunch break, did not pay split-shift premiums and did not pay all wages. The California Labor Commissioner’s Office imposed 680,238 USD, of which 538,638 USD for the benefit of the employees.
In the restaurant trade, breaks must be actively scheduled and documented – being on call for guests during the break turns it into working time.
Break arrangements in the restaurant trade
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code (Meal and Rest Periods, Split Shift Premium, Lohnabrechnung)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Liability of senior managers
- Owner Byung Kwan Lee named in the announcement.
Original amount 680,238 USD, converted at the ECB reference rate of 4 Sep 2025.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Aug 2025 Paxos Trust Company, LLCNYDFS: 26.5 million USD against Paxos over AML deficiencies in Binance business €22.8m
The New York State Department of Financial Services (NYDFS) imposed a penalty of 26.5 million USD on the crypto trust company because Paxos did not maintain an effective BSA/AML programme before 2023: KYC checks and risk ratings were inadequate, and transaction monitoring and suspicious activity reporting procedures had gaps, including in connection with the business relationship with Binance, contrary to a 2020 agreement. In addition, Paxos must invest at least 22 million USD in its compliance programme.
Companies that distribute products via partner platforms must include those platforms' customer and transaction risks in their own AML programme.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- New York Banking Law §§ 39, 44; AML-Vorschriften des NYDFS und Bank Secrecy Act
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 7 Aug 2025
Original amount 26,500,000 USD, converted at the ECB reference rate of 7 Aug 2025.
- In the Matter of Paxos Trust Company, LLC – Consent Order Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jul 2025 Wise US, Inc.Six US states: 4.2 million USD against Wise US over AML programme deficiencies €3.59m
In a coordinated multistate proceeding brought by six states – the New York State Department of Financial Services (NYDFS) with the supervisory authorities of CA, MN, NE, TX and MA – the money transmitter must pay 4.2 million USD. An examination (July 2022 to September 2023) found, among other things, a lack of independent AML reviews at an appropriate frequency, late suspicious activity reports, data quality problems in transaction monitoring and unremedied earlier findings; Wise does not admit any legal infringements and must conduct a lookback.
Remedy findings from earlier examinations and audits on time – otherwise they become a ground for sanctions in their own right.
- Authority / court
- New York State Department of Financial Services (NYDFS) mit den Aufsichtsbehörden von CA, MN, NE, TX und MA
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Bundes- und einzelstaatliches Recht zu Geldtransfer und BSA/AML (u. a. 31 CFR 1022.320)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Remedial measures already initiated and lookback
- Published
- 9 Jul 2025
Original amount 4,200,000 USD, converted at the ECB reference rate of 9 Jul 2025.
- Consent Order – Wise US, Inc. (Multi-State) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Jul 2025 Healthline Media LLCCalifornia: $1.55 million against Healthline over disclosure of illness-related article titles €1.31m
Despite objections, the health portal continued to pass data to advertising partners and transmitted article titles suggestive of diagnoses for targeted advertising; the consent banner did not stop the tracking. In addition, the required contractual clauses with advertising partners were missing. The settlement was reached with the Attorney General of California.
Test consent banners technically: if rejecting does not actually switch off tracking, that is misleading and unlawful.
- Authority / court
- Attorney General of California (California Department of Justice)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- California Consumer Privacy Act (CCPA), Unfair Competition Law
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 1 Jul 2025
Original amount 1,550,000 USD, converted at the ECB reference rate of 1 Jul 2025.
- Attorney General Bonta Announces Largest CCPA Settlement to Date, Secures $1.55 Million from Healthline.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 May 2025 Todd Snyder, Inc.Todd Snyder: 345,178 USD – tracking opt-out ineffective for 40 days €304,793
For 40 days, the fashion retailer’s misconfigured privacy portal did not process objections to the sale and sharing of personal data; in addition, the company required too much data and identity verification before an opt-out. The California Privacy Protection Agency (CPPA) imposed 345,178 USD and required correct configuration of consent management and employee training.
A consent management platform does not relieve companies of responsibility: check regularly whether opt-outs are actually implemented technically.
Configuration and monitoring of consent management platforms
Missing or inadequate training played a role in the decision.
- Authority / court
- California Privacy Protection Agency (CPPA), Board
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
Original amount 345,178 USD, converted at the ECB reference rate of 6 May 2025.
- CPPA Orders Clothing Retailer Todd Snyder to Pay Six-Figure Fine, Overhaul Privacy Practices (06.05.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Apr 2025 Block, Inc.NYDFS: 40 million USD against Block (Cash App) over AML deficiencies €36.1m
The New York State Department of Financial Services (NYDFS) imposed 40 million USD on the operator of Cash App for serious gaps in its BSA/AML programme, including insufficient customer due diligence, a lack of risk-based controls and untimely transaction monitoring. Rapid growth in 2019/2020 led to a considerable backlog of alerts; an independent monitor is being appointed.
Scale compliance capacity with growth – a backlog of alerts is a supervisory infringement in its own right.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- BSA/AML-, Geldtransfer- und Virtual-Currency-Vorschriften des NYDFS
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Cooperation and remedial measures already initiated
- Published
- 10 Apr 2025
Original amount 40,000,000 USD, converted at the ECB reference rate of 10 Apr 2025.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Mar 2025 American Honda Motor Co., Inc.CPPA: $632,500 against Honda over obstructed privacy requests €582,573
Honda required excessive information for opt-out requests, used a cookie tool without equivalent choices, made it harder to appoint authorised agents and passed data on to ad-tech firms without the required contracts. The order of the California Privacy Protection Agency (CPPA) requires, among other things, a simplified procedure and training for employees.
Do not undermine data subject rights through form hurdles or asymmetric consent dialogues.
- Authority / court
- California Privacy Protection Agency (CPPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- California Consumer Privacy Act (CCPA)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Automotive
- Employees
- 10,000 or more
- Published
- 12 Mar 2025
Original amount 632,500 USD, converted at the ECB reference rate of 7 Mar 2025.
- CPPA: Enforcement action against American Honda Motor Co. Press release of an authority
- CPPA Order of Decision: American Honda Motor Co., Inc. (ENF23-V-HO-2) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA €1.92m
When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.
Anyone changing data flows must know the security processes – training development teams is part of cyber defence.
Secure software development and change processes
Missing or inadequate training played a role in the decision.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- PayPal has since remedied the deficiencies.
- Published
- 23 Jan 2025
Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.
- DFS-Pressemitteilung vom 23.01.2025: Cybersecurity-Vergleich mit PayPal, Inc. (2 Mio. $) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2024 Fünf Wingstop-Filialgesellschaften in Kern County (Inhaber Clinton Lewis)Wingstop franchisee: 1.7 million USD – overtime evaded by splitting up companies €1.53m
The franchisee ran five Wingstop outlets in Bakersfield as separate companies and deployed employees at several locations on the same day. As a result, they lost out on overtime premiums after eight hours a day or 40 hours a week, premiums for missed meal breaks, paid travel time and the higher minimum wage for larger employers; the settlement of 1.7 million USD concerns around 550 employees.
Working time is added up across all locations of the same employer – splitting into separate companies does not protect against overtime obligations.
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code (Overtime, Meal Periods, Mindestlohn)
- Action
- Other
- Status of proceedings
- final
- Sector
- Food and agriculture
- Culpability
- intentional
- Liability of senior managers
- Owner Clinton Lewis personally responsible.
Original amount 1,700,000 USD, converted at the ECB reference rate of 16 Sep 2024.
- California DIR News Release 2024-73: California Labor Commissioner’s Office reaches $1.7 million settlement in Wingstop wage theft case (16.09.2024) Press release of an authority
- California DIR News Release 2023-68: California Labor Commissioner Cites Five Winstop Fast Food Restaurants and Their Owner More Than $3 Million (28.09.2023) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2024 Amazon.com Services, LLCAmazon: 5.9 million USD – undisclosed productivity quotas in two warehouses (Warehouse Quotas Law) €5.51m
Amazon did not inform employees at two warehouses in Moreno Valley and Redlands in writing of the productivity quotas that applied; the authority regarded the peer-to-peer rating system used as a quota within the meaning of the law, which prohibits quotas that prevent breaks, toilet visits or compliance with health and safety. For 59,017 violations between October 2023 and March 2024, the Labor Commissioner’s Office imposed 5,901,700 USD.
Disclose performance metrics for employees, and do not let them effectively prevent breaks – even when they come in the guise of peer ratings.
Making productivity quotas and break rights transparent (managers)
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Warehouse Quotas Law (AB 701, Labor Code §§ 2100 ff.); Labor Code § 2699(f)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
Original amount 5,901,700 USD, converted at the ECB reference rate of 18 Jun 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2024 Edgewood Residential Facility (Los Angeles)Edgewood Residential: 658,948 USD – care workers up to 24 hours without breaks €612,121
At the care facility, employees worked up to 24 hours a day, seven days a week, were not allowed to leave the premises, had to work through breaks and received no overtime pay. The settlement of 658,948 USD comprises 608,948 USD for 34 employees (including overtime and break premiums) and 50,000 USD in civil penalties.
Round-the-clock shifts without rest periods are a recurring pattern in care – rosters need checks against maximum working hours and breaks.
Working time limits and breaks in care
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code (Überstunden, Meal and Rest Periods, Mindestlohn)
- Action
- Other
- Status of proceedings
- final
- Sector
- Healthcare
Original amount 658,948 USD, converted at the ECB reference rate of 12 Jun 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Feb 2024 La Mina De Oro Inc., KD Distributors, Inc. und Desire Fragrances Inc.La Mina de Oro: 1 million USD – warehouse workers without daily overtime and genuine breaks €929,541
Warehouse and sales staff were not paid for all hours worked, received overtime premiums only after 40 hours a week instead of after eight hours a day, and had to remain available to customers during rest and meal breaks. Following citations issued in 2021, the California Labor Commissioner’s Office agreed a settlement of 1 million USD for 107 employees.
A break during which employees must remain available is legally working time – break arrangements must ensure genuine interruptions.
Breaks are time off work – not standby
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code (Daily Overtime, Meal and Rest Periods, Mindestlohn)
- Action
- Other
- Status of proceedings
- final
- Sector
- Retail and e-commerce
Original amount 1,000,000 USD, converted at the ECB reference rate of 8 Feb 2024.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2023 First American Title Insurance CompanyNYDFS: $1 million against First American over open document links €913,159
The EaglePro application generated links to transaction documents without login and without an expiry date; according to a journalist, by changing the sequential document number, 885 million documents containing, among other things, social security and bank data could be retrieved. Users were told not to send sensitive data, but there were no technical barriers. The penalty was imposed by the New York State Department of Financial Services (NYDFS).
Instructions to users do not replace technical controls – sharing links need authentication and an expiry date.
Classification and sending of sensitive documents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR §§ 500.3, 500.7 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 1,000,000 USD, converted at the ECB reference rate of 27 Nov 2023.
- Consent Order to First American Title Insurance Company Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Nov 2023 Calcrete Construction Inc.Calcrete Construction: over 1 million USD – up to 68 hours a week without overtime pay Other
Employees of the Glendale construction company regularly worked 45 to 68 hours a week without being paid for overtime; there was also no paid sick leave and no proper wage statements. The California Labor Commissioner’s Office concluded a settlement with the company of more than 1 million USD for the benefit of 249 construction workers.
Anyone allowing long working weeks must also record and pay for them in full – systematic unrecorded overtime comes to light in every wage audit.
- Authority / court
- California Labor Commissioner's Office (Division of Labor Standards Enforcement)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- California Labor Code (Überstunden, Paid Sick Leave, Lohnabrechnung)
- Action
- Other
- Status of proceedings
- final
- Sector
- Construction and real estate
Checked against the official source on 25 Sep 2026 · Direct link