Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 1,017 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

858cases from 32 jurisdictions
€24.9bnTotal of monetary amounts (691 cases with an amount)
€4.75bnLargest single case: Purdue Pharma L.P.
€425,293Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20235€58.5m
Q4 202352€958.5m
Q1 202446€1.74bn
Q2 202438€159.9m
Q3 202450€1.17bn
Q4 202480€1.75bn
Q1 202563€2.91bn
Q2 202572€2.6bn
Q3 202581€2.91bn
Q4 202597€2.37bn
Q1 202690€735.1m
Q2 202689€5.72bn
Q3 202695€1.86bn

858 cases

26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants DenmarkAbuse of market power Order

In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.

What organisations can take from it

Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
Competition law · Abuse of market power
Legal basis
Konkurrenceloven; AEUV Art. 102
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Published
26 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Sep 2026 Plaček Pet Products s.r.o.Plaček Pet Products: 36.4 million CZK for minimum prices on pet food CzechiaCartels and collusion €1.49m

From January 2013 to March 2022, the distributor of premium pet food and pet supplies imposed minimum resale prices on its retailers and threatened sanctions if they were undercut. In a settlement procedure, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 36.438 million CZK; the company ended the conduct after the inspection and introduced a compliance programme.

What organisations can take from it

Never enforce recommended retail prices with supply stops or sanctions – sales teams need clear rules on this.

Relevance to training and awareness

Price requirements imposed on retailers in sales

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Verbot vertikaler Preisbindung (tschechisches Wettbewerbsgesetz, Art. 101 AEUV)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Termination immediately after the inspection, information of customers about free pricing, full cooperation, settlement and newly introduced compliance programme.
Published
24 Sep 2026

Original amount 36,438,000 CZK, converted at the ECB reference rate of 24 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Sep 2026 M&J GroupCMA: fines against construction firm and two employees for concealing evidence during an inspection United KingdomCartels and collusion €58,149

During an inspection as part of an investigation into bid rigging, the Estimating Director Barry Pirrie instructed the Office Manager Tracey Woods to remove a work mobile phone and documents from the premises, and denied having a work mobile phone. The UK Competition and Markets Authority (CMA) imposed fines of 25,000 GBP on M&J, 20,000 GBP on Pirrie and 5,000 GBP on Woods.

What organisations can take from it

Dawn raid training is mandatory: anyone who removes mobile phones or documents during an inspection is personally liable – even when acting on a superior's instructions.

Relevance to training and awareness

Correct conduct during inspections (dawn raids), no removal of evidence

Authority / court
Competition and Markets Authority (CMA)
Area of law
Competition law · Cartels and collusion
Legal basis
Section 40A(1) Competition Act 1998
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
intentional
Liability of senior managers
Personal fines against Barry Pirrie (20,000 GBP) and Tracey Woods (5,000 GBP)
Published
24 Sep 2026

Original amount 50,000 GBP, converted at the ECB reference rate of 24 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Sep 2026 Kalibrate Canada (Tochter der Kalibrate Technologies Ltd.)Canada: Kalibrate must stop sharing retailer-specific petrol station data CanadaAbuse of market power Order

Kalibrate's "Market Intelligence" product passed on retailer-specific sales data from petrol stations that allowed conclusions to be drawn about competitors and could facilitate coordinated pricing behaviour. In an agreement registered with the Competition Tribunal, Kalibrate undertakes to supply only aggregated and time-delayed data – the first case under the reformed abuse of dominance rules.

What organisations can take from it

Providers of market and price data must ensure that their products do not disseminate individualised competitor data.

Authority / court
Competition Bureau Canada (Consent Agreement beim Competition Tribunal)
Area of law
Competition law · Abuse of market power
Legal basis
Abuse-of-dominance-Bestimmungen des Competition Act (Fassung 2023)
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Published
24 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Southern WaterSouthern Water: 2.4 million GBP fine for sewage and diesel pollution in Kent United KingdomEmissions and permits €2.9m

Between 2019 and 2021, untreated sewage, sewage residues, diesel from a generator and waste entered a stream and the sea around Faversham and Whitstable; the circumstances of one incident were not reported to the Environment Agency, around 70 fish died, and bathing warnings were in place at beaches in Tankerton and Herne Bay for almost a week. The court imposed a fine of 2,416,666.67 GBP, 69,894.04 GBP in costs and a 190 GBP victim surcharge; it was the company's second conviction that year (announcement of 22 September 2026, exact date of judgment not stated).

What organisations can take from it

Repeated pollution and failure to report incidents lead to a series of prosecutions with rising fines.

Relevance to training and awareness

Reporting environmental incidents to the regulator

Authority / court
Bromley Magistrates' Court (Anklage: Environment Agency)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Regulations 12(1)(b) und 38(1)(a) Environmental Permitting (England and Wales) Regulations 2016
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Repeat case
yes
Published
22 Sep 2026

Original amount 2,486,750.71 GBP, converted at the ECB reference rate of 22 Sep 2026.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 OTC Link LLCOTC Link: 575,000 USD – security policies never completed despite examination findings USACritical infrastructure €501,614

From 2016 to 2025, the operator of the OTC Link ATS trading system lacked complete policies on systems security, access control and vulnerability management as required under Regulation SCI. Although the examiners of the U.S. Securities and Exchange Commission (SEC) had criticised the gaps in several examinations, drafts remained unfinished; the SEC issued a censure and imposed 575,000 USD.

What organisations can take from it

Track supervisory examination findings with a deadline and a responsible person – points that remain open repeatedly become expensive.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Regulation SCI, Rule 1001(a)(1)–(3)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes

Original amount 575,000 USD, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Audax Renovables, S.A. – Sucursal em PortugalPortugal: 22,000 EUR against Audax Renovables over missing gas reserves and hotline PortugalOther €22,000

On a total of 249 days, the Portuguese branch of the energy supplier failed to hold the mandatory natural gas security reserves, did not correctly show network charges on invoices, did not publish, or published late, mandatory information and its quality report, and failed to meet the standards for hotline waiting times. In a settlement procedure, the Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) set a fine of 44,000 EUR and reduced it to 22,000 EUR.

What organisations can take from it

Security of supply and service obligations in the energy sector are sanctioned individually – a compliance calendar for reserves and reports helps.

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Other
Legal basis
Regime Sancionatório do Setor Energético (RSSE), Art. 28, 29; Decreto-Lei n.º 62/2020, Art. 96; RRC; RQS
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Settlement (transação) with full admission, remediation of all infringements

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Sep 2026 FleetCor Technologies Inc. (heute Corpay Inc.)FleetCor/Corpay pays 100 million USD over hidden fees on fuel cards USAMisleading advertising and pricing €87.1m

In 2023, a federal court found by way of summary judgment that the fuel card provider had charged its predominantly small business customers hidden or unauthorised fees and misrepresented savings; an appeals court upheld this in 2026. According to the FTC, the fees added up to hundreds of millions of dollars, and late fees were also charged despite punctual payment. Under the settlement resolving the administrative proceedings, FleetCor and CEO Ronald Clarke are paying 100 million USD for refunds; the order is not yet final.

What organisations can take from it

Fees hidden behind links or in account documents are deemed not to have been disclosed – including vis-à-vis business customers.

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Section 5 FTC Act
Action
Disgorgement of profits
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
CEO Ronald Clarke is named in the press release as a party involved.
Published
17 Sep 2026

Original amount 100,000,000 USD, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Sep 2026 Lesy České republiky, s.p. (Lesy ČR)Lesy ČR: 17.3 million CZK for export ban on wood chips CzechiaCartels and collusion €710,383

From July 2021 to July 2024, the state forestry company contractually prohibited a customer from actively and passively exporting wood chips and logging residues and secured the ban with a right of termination. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) considered this a restriction of competition by object under Czech and EU law and imposed 17.268 million CZK (first instance, not final).

What organisations can take from it

State-owned companies are also subject to competition law – have export and resale bans in framework agreements legally reviewed before signing.

Relevance to training and awareness

Anticompetitive clauses in supply contracts

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (Exportverbot, S0733/2025)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Voluntary termination immediately after proceedings were opened.
Published
17 Sep 2026

Original amount 17,268,000 CZK, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 Hillbeck Homes (Sowerby Bridge) LtdDeveloper pays £300,000 after agency worker falls through unprotected stairwell opening United KingdomWorkplace safety and accidents €349,895

A 24-year-old labourer working as a temporary worker for a scaffolding company fell, in his second week of work on the developer's housing site, through a stairwell opening that was neither securely covered nor guarded, dropping one storey onto concrete and suffering serious spinal injuries. The court found the company guilty on three counts because it had neither adequately planned nor supervised work at height and had not taken suitable measures to prevent falls. Fine of £300,000 plus costs.

What organisations can take from it

Floor openings on construction sites must be covered with load-bearing covers or guarded at all times – new and temporary workers in particular do not know where the hazards are.

Relevance to training and awareness

Fall protection at openings; induction of new workers

Authority / court
Leeds Magistrates' Court (Anklage: Health and Safety Executive)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Work at Height Regulations 2005
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Published
21 Sep 2026

Original amount 300,000 GBP, converted at the ECB reference rate of 16 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers SwedenOrganisational requirements €177,187

As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.

What organisations can take from it

Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.

Authority / court
Finansinspektionen (FI)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
No established damage to investors; remedial measures already taken during the investigation.
Published
16 Sep 2026

Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies EstoniaInternal controls Order

Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.

What organisations can take from it

Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance
Published
16 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker CzechiaOther €12,350

In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.

What organisations can take from it

External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.

Relevance to training and awareness

Conflicts of interest of external advisers in procurement procedures

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Other
Legal basis
Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Published
15 Sep 2026

Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Sep 2026 Dompé U.S. Inc.Dompé U.S.: 32 million USD – Medicare patients’ co-payments covered via foundations USAGifts, hospitality and benefits €27.5m

From 2018 to 2021, the pharmaceutical manufacturer allegedly used two patient assistance foundations to fund Medicare beneficiaries’ co-payments for its drug Oxervate in order to promote its sales. Following a self-disclosure, Dompé paid 32 million USD.

What organisations can take from it

Benefits flowing to customers via foundations or other third parties remain benefits provided by the company – donations to patient assistance programmes require strict independence.

Relevance to training and awareness

Benefits to patients and customers via third parties

Authority / court
U.S. Department of Justice / U.S. Attorney's Office, District of Massachusetts
Area of law
Bribery and corruption · Gifts, hospitality and benefits
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Mitigating circumstances
Self-disclosure.

Original amount 32,000,000 USD, converted at the ECB reference rate of 10 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Sep 2026 Algoma Steel Inc.Algoma Steel: 1.2 million CAD fine for gear oil in the St. Marys River Canada, ONWaste and hazardous substances €747,710

In June 2022, a gear oil tank overflowed at the steelworks in Sault Ste. Marie; an estimated 1,000 to 1,250 litres of oil entered the St. Marys River, harmful to fish and migratory birds. The company pleaded guilty to two counts and is paying 1.2 million CAD into the Environmental Damages Fund; its name is listed in the Environmental Offenders Registry.

What organisations can take from it

Even small tank overflows near watercourses lead to fines in the millions – overfill protection and containment systems are mandatory.

Relevance to training and awareness

Filling and monitoring oil tanks

Authority / court
Ontario Court of Justice, Sault Ste. Marie (Ermittlungen: Environment and Climate Change Canada)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Fisheries Act, Subsection 36(3); Migratory Birds Convention Act, 1994, Subsection 5.1(1)
Action
Fine
Status of proceedings
unknown
Sector
Steel and metals
Mitigating circumstances
Guilty plea.
Published
11 Sep 2026

Original amount 1,200,000 CAD, converted at the ECB reference rate of 10 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2026 United Utilities Water LimitedUnited Utilities: record fine of 900,000 GBP after sewage flood on the Fylde coast United KingdomEmissions and permits €1.12m

Following a partial pipe collapse at the Fleetwood wastewater treatment works, untreated sewage flowed from three pumping stations into the Irish Sea for over 35 hours in June 2023; seven bathing waters were affected and shellfish beds were closed. The water company pleaded guilty to five offences and must pay a fine of 900,000 GBP, 62,225 GBP in costs and a 2,000 GBP victim surcharge.

What organisations can take from it

The condition and redundancy of critical wastewater infrastructure are a permit obligation; the Environment Agency assessed the failure as reckless and in the highest harm category.

Authority / court
Preston Magistrates' Court (Anklage: Environment Agency)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Regulation 38(2) Environmental Permitting (England and Wales) Regulations 2016
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Around 38 million GBP invested in response and repair, and a voluntary payment of 250,000 GBP to Blackpool Council.
Published
8 Sep 2026

Original amount 964,225 GBP, converted at the ECB reference rate of 8 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2026 Samworth Brothers LimitedSamworth Brothers: £594,000 after two workers scalded at steam line United KingdomWorkplace safety and accidents €691,518

At the Kettleby Foods plant in Melton Mowbray, an employee and a contractor were scalded with hot water while replacing a leaking gasket on an isolation valve of a steam line (burns to 4–5 % and 9 % of their body surface respectively). The Health and Safety Executive (HSE) found that the task had neither been assessed nor documented as a safe system of work, isolation and lock-off procedures had not been applied, fall protection was missing and supervision was inadequate. Following a guilty plea, a fine of £594,000, plus £6,000 compensation for the injured employee, costs and a victim surcharge.

What organisations can take from it

Maintenance on steam and pressure lines requires a written isolation and lock-off procedure that is supervised on site.

Relevance to training and awareness

Isolating and locking off equipment during maintenance (lockout/tagout)

Authority / court
Birmingham Magistrates' Court (Anklage: Health and Safety Executive)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 2 Health and Safety at Work etc. Act 1974
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Published
16 Sep 2026

Original amount 594,000 GBP, converted at the ECB reference rate of 4 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection ItalyMarketing and consent €5.51m

For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).

What organisations can take from it

An objection to advertising must take effect immediately and reliably across all channels – including app messages.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 BDW Trading (Barratt Redrow)Barratt Redrow subsidiary BDW pays 201,500 GBP to environmental projects after silt entered brooks United KingdomEmissions and permits €234,153

At the Ladden Garden Village construction site in Yate, a subcontractor washed silt from the site drainage into two brooks over six days in July 2022. The Environment Agency accepted an Enforcement Undertaking: BDW is paying 201,500 GBP to three environmental and charitable projects, bears the investigation costs and had already invested over 180,000 GBP in remediation, training and improved surface water management.

What organisations can take from it

Developers are liable for environmental damage caused by their subcontractors; clear procedures and training on handling surface water prevent costly proceedings.

Relevance to training and awareness

Protecting watercourses on construction sites and managing subcontractors

Missing or inadequate training played a role in the decision.

Authority / court
Environment Agency
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Environmental Civil Sanctions (England) Order 2010 (Enforcement Undertaking)
Action
Other
Status of proceedings
final
Sector
Construction and real estate
Mitigating circumstances
Acceptance of responsibility, remediation, training of employees and application for a discharge permit.
Published
3 Sep 2026

Original amount 201,500 GBP, converted at the ECB reference rate of 3 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record ItalyEmployee data €24,000

Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).

What organisations can take from it

Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.

Relevance to training and awareness

Purpose limitation when accessing patient records

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator ItalyVideo surveillance €8,000

Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.

What organisations can take from it

Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2026 PPS Metal Recycling LtdScrapyard: £40,000 fine after metal pile collapses on father and son United KingdomWorkplace safety and accidents €46,699

In February 2025, a pile of scrap collapsed on a father and his son at the metal recycler's site while an excavator had been working near them for around 20 minutes; one of them suffered a broken leg. Pedestrians were separated neither from machinery nor from unstable stockpiles, even though there had been a near miss involving the same excavator shortly before. Fine of £40,000 plus £6,181 costs.

What organisations can take from it

Companies that allow customers or visitors onto a site with machinery must physically separate pedestrians and vehicles and treat near misses as a warning sign.

Authority / court
Grimsby Magistrates' Court (Anklage: Health and Safety Executive)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 3(1) Health and Safety at Work etc. Act 1974
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Mitigating circumstances
After the accident, a separate unloading zone, signage, supervised procedures and fenced-off walkways were introduced.
Published
2 Sep 2026

Original amount 40,000 GBP, converted at the ECB reference rate of 1 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports MaltaMoney laundering and terrorist financing €97,622

The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.

What organisations can take from it

Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction
Published
4 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Aug 2026 MSC Shipmanagement Limited; Hong Kong Spirit Shipping and Trading LimitedMSC Shipmanagement: 1.75 million USD fine for secretly discharging oily bilge water USAWaste and hazardous substances €1.5m

On board the MSC Samira III, senior engineering officers had oily bilge water pumped overboard via the sewage tank, bypassing the oily water separator, in 2024/2025, manipulated the oil content monitoring and falsified the oil record book, which was presented to the Coast Guard in Philadelphia. The operator and the owner each pleaded guilty to two counts under the Act to Prevent Pollution from Ships (APPS) and are paying a combined 1.75 million USD; in addition, there are four years of probation.

What organisations can take from it

Shipping companies must actively monitor practice on board and the oil record book, because instructions given by individual officers are attributed to the company under criminal law.

Relevance to training and awareness

MARPOL obligations on board, oil record book and reporting channels for crews

Authority / court
U.S. District Court for the Eastern District of Pennsylvania (Anklage: DOJ Environment and Natural Resources Division)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Act to Prevent Pollution from Ships (APPS), 33 U.S.C. § 1908
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Culpability
intentional
Liability of senior managers
Second Engineer Mikhail Tsurikov also pleaded guilty; sentencing scheduled for 10 September 2026.
Published
28 Aug 2026

Original amount 1,750,000 USD, converted at the ECB reference rate of 28 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 Maple Lodge Farms Ltd.Poultry processor Maple Lodge Farms: CA$500,000 after CO2 leak without gas detection system Canada, ONWorkplace safety and accidents €309,578

In March 2024, a CO2 hose on a vacuum mixer ruptured in the deli area of the plant in Brampton; around 16,000 pounds of carbon dioxide escaped and one worker suffered life-threatening injuries. There was no CO2 sensor with an alarm. Following a guilty plea, a fine of CA$500,000 plus a 25 % victim fine surcharge.

What organisations can take from it

Wherever refrigerant or inert gases are used in quantity, a gas detection system is part of the basic equipment.

Authority / court
Provincial Offences Court Brampton (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 25(2)(h) Occupational Health and Safety Act (Ontario)
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Guilty plea; permanently installed CO2 sensor after the incident.
Published
27 Aug 2026

Original amount 500,000 CAD, converted at the ECB reference rate of 27 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination MaltaCustomer due diligence €160,099

At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.

What organisations can take from it

A customer risk assessment belongs before business starts, not in a later remediation project.

Relevance to training and awareness

Risk-based customer profiles and source of funds

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction; remediation demonstrated
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 Flower bulb business failed to disclose hours of Polish seasonal workers – fine of around 95,600 EUR NetherlandsMinimum wage and undeclared work €95,588

A lily and tulip grower with an average of around 50 (at peak 75) employees, where Polish migrant workers are employed (anonymised in the judgment), was unable to produce sufficient records of hours worked and wages paid for 18 employees for September 2020 to February 2021. The Dutch Minister of Social Affairs and Employment (Minister van Sociale Zaken en Werkgelegenheid) imposed 118,000 EUR in 2024 (112,100 EUR after objection); the North Netherlands District Court (Rechtbank Noord-Nederland) reduced the fine to 95,587.50 EUR, partly because of measures taken and excessively long proceedings.

What organisations can take from it

Companies employing seasonal workers must be able to document hours and wage payments for each person without gaps – missing records are fined separately for each employee.

Authority / court
Rechtbank Noord-Nederland (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid / Nederlandse Arbeidsinspectie)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Art. 18b Abs. 2 Wet minimumloon en minimumvakantiebijslag (Wml)
Action
Fine
Status of proceedings
reduced
Sector
Food and agriculture
Employees
50 to 249
Mitigating circumstances
Reduction of 12.5 % for appropriate measures, 5 % for delay and 2,500 EUR for exceeding the reasonable length of proceedings.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking CzechiaCartels and collusion €11.7m

From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.

What organisations can take from it

Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.

Relevance to training and awareness

Coordination with cooperation partners on customers and tenders

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Published
26 Aug 2026

Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records IrelandData breaches and data security €645,000

In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.

What organisations can take from it

Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.

Relevance to training and awareness

Physical security and retention of paper records

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector
Employees
10,000 or more
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 ExxonMobil Chemical LimitedExxonMobil Chemical: 267,000 GBP for five hydrocarbon leaks at Fife ethylene plant United KingdomWorkplace safety and accidents €312,098

Between February 2018 and September 2019, five leaks of highly flammable hydrocarbons occurred at the Mossmorran major hazard site (COMAH upper tier), all caused by corrosion under insulation; around 82 tonnes escaped in one leak. During a routine inspection in May 2019, inspectors of the Health and Safety Executive (HSE) smelled escaping gas – the company had known about this leak for around four months and had continued production without additional precautions. The inspection arrangements for insulated pipework were inadequate; fine of 267,000 GBP.

What organisations can take from it

Recurring damage patterns must change the inspection concept – visual inspections from the ground are not sufficient for insulated pipework.

Authority / court
Health and Safety Executive (Kirkcaldy Sheriff Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Provision and Use of Work Equipment Regulations 1998, reg. 6(2); Health and Safety at Work etc. Act 1974, s. 33(1)(c)
Action
Fine
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more
Published
26 Aug 2026

Original amount 267,000 GBP, converted at the ECB reference rate of 25 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Elizabeta Promet d.o.o., SolinCroatia: 10,000 EUR against Elizabeta Promet for deliveries without a written contract CroatiaAbuse of market power €10,000

As a buyer with significant bargaining power, the company from Solin purchased agricultural and food products from two suppliers without written contracts. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) considered this an unfair trading practice and, taking mitigating circumstances into account, imposed 10,000 EUR (date = publication).

What organisations can take from it

In food purchasing, the mere absence of written supply contracts is an infringement – a simple contract standard prevents this.

Relevance to training and awareness

Written form for supply contracts in food purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Several mitigating circumstances taken into account
Published
25 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Aug 2026 Container Manufacturing Ltd.Small US machinery supplier exported spare parts for can presses to Russia USAExport control and dual-use goods €857,339

Between March 2023 and March 2025, the Ohio manufacturer of presses for beverage can ends (nine employees) supplied, in ten instances, spare parts for aluminium forming tools worth around 264,700 USD – partly via the UAE and Turkey – without a licence to a Russian customer whose group also supplies defence precursors. In two instances, the company acted with knowledge of the violation; it admitted the allegations, which were brought by the US Commerce Department's Bureau of Industry and Security (BIS).

What organisations can take from it

Even small businesses with few employees must check tariff codes against Russia restrictions and treat deliveries via third countries as a warning sign.

Relevance to training and awareness

HTS-based export restrictions on Russia, diversion via third countries

Missing or inadequate training played a role in the decision.

Authority / court
U.S. Department of Commerce, Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations, § 746.8(a)(5) (HTS-Codes Supplement No. 4 to Part 746), §§ 764.2(a), 764.2(e)
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Employees
Under 50
Mitigating circumstances
Full cooperation; compliance programme subsequently expanded with screening, an approval process and additional export control training
Published
24 Aug 2026

Original amount 1,000,000 USD, converted at the ECB reference rate of 24 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Aug 2026 IPMF LLC (NaturPak)NaturPak: $364,100 proposed after three deaths caused by bursting kettle lids USAWorkplace safety and accidents €311,703

At the food plant in Janesville (Wisconsin), the lids of pressurised industrial kettles opened in February and March 2026, scalding workers with steam and hot liquid; three people died. The U.S. Occupational Safety and Health Administration (OSHA) proposed a total of $364,100 for both inspections combined, including repeat violations relating to fall protection and lockout/tagout.

What organisations can take from it

After a serious accident, the technical cause must be eliminated immediately – otherwise, as here, a second similar incident may follow.

Authority / court
U.S. Department of Labor – Occupational Safety and Health Administration (OSHA)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Occupational Safety and Health Act of 1970; 29 CFR 1910 (u. a. Lockout/Tagout, Absturzsicherung, persönliche Schutzausrüstung)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Repeat case
yes
Published
20 Aug 2026

Original amount 364,100 USD, converted at the ECB reference rate of 20 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 WH Media GmbHKommAustria penalises person responsible for W24 over advertising in news programme AustriaMisleading advertising and pricing €500

On 29 May 2024, the Vienna broadcaster W24 aired advertising in split screen within the programme ‘24 Stunden Wien’, did not adequately separate advertising from programming and, at around 50 minutes, significantly exceeded the permitted 12 minutes of advertising per hour. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) imposed fines totalling 500 EUR (plus 50 EUR in costs) on the body authorised to represent the company externally; the GmbH is jointly and severally liable under § 9 (7) VStG (Austrian Administrative Penal Act).

What organisations can take from it

Advertising time limits and the separation requirement also apply to small regional broadcasters – management is personally liable via § 9 VStG.

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 64 Abs. 2 Z 9 i. V. m. §§ 43 Abs. 2, 44 Abs. 1, 45 Abs. 1 AMD-G; § 9 VStG
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous record, duration of proceedings, remorseful confession and remedial measures initiated.
Liability of senior managers
Fine imposed on the body responsible externally (§ 9 (1) VStG); the company is jointly and severally liable.
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 Sioux Erosion Control Inc.DOJ: jury convicts erosion control firm of price fixing in Oklahoma road construction USACartels and collusion —

A jury found Sioux Erosion Control, co-owner BG Dale Biscoe and employee Randall David Shelton guilty of having fixed prices for erosion control services, allocated contracts regionally and rigged bids on publicly funded road construction projects in Oklahoma (more than 100 million USD) from 2017 to 2023. Sentencing was still pending.

What organisations can take from it

Subcontractors in public road construction are also targeted by prosecutors – up to and including jury convictions of individual employees.

Relevance to training and awareness

Price-fixing and territorial agreements for subcontracted services in road construction

Authority / court
U.S. Department of Justice, Antitrust Division
Area of law
Competition law · Cartels and collusion
Legal basis
Section 1 Sherman Act
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
Guilty verdict against co-owner BG Dale Biscoe and employee Randall David Shelton
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect CzechiaCartels and collusion €11.5m

From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.

What organisations can take from it

Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.

Relevance to training and awareness

Coordination of terms and conditions among competitors

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Published
17 Aug 2026

Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Aug 2026 Henkel AG & Co. KGaAHenkel/Liquid Nails: court blocks takeover of Loctite’s main competitor USAMerger control Order

Henkel wanted to buy the construction adhesive brand Liquid Nails for 725 million USD from the financial investor American Industrial Partners, thereby taking over the main competitor of its Loctite brand. After a seven-day trial, the federal court, on application by the Federal Trade Commission (FTC), issued a permanent injunction against the acquisition.

What organisations can take from it

Acquiring the closest competitor carries a high risk of prohibition, even at a moderate deal volume.

Authority / court
U.S. District Court for the Southern District of New York (auf Antrag der FTC)
Area of law
Competition law · Merger control
Legal basis
Section 7 Clayton Act; Section 13(b) FTC Act (Permanent Injunction)
Action
Order
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more
Published
17 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2026 Dante International S.A.; Extreme Digital-eMAG Kft. (Betreiber des eMAG-Webshops)eMAG: further 225 million HUF for unfulfilled commitments HungaryConsumer protection and online retail €620,091

In 2021, the operators of the online retailer eMAG had committed to a support programme for Hungarian businesses, but once again implemented it only partially and not with the prescribed content. In the follow-up review, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 225 million HUF; in total, the operators have already received fines of 710 million HUF.

What organisations can take from it

Commitments made binding by an authority require dedicated implementation and evidence controlling – otherwise the next fine follows.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Consumer protection and online retail
Legal basis
Nachprüfungsverfahren zu verbindlichen Zusagen (VJ/6/2025)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Repeat case
yes
Mitigating circumstances
The companies acknowledged the failures and waived legal remedies.
Published
13 Aug 2026

Original amount 225,000,000 HUF, converted at the ECB reference rate of 13 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2026 „О-Рент“ ЕООД (sowie „Инжконсулт“ ЕООД und „Земекоп“ ЕООД)Construction machinery cartel: fine for O-Rent, compliance programme for all participants BulgariaCartels and collusion €2,403

The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found a cartel in public tenders for mining and construction machinery (price fixing and market sharing, Art. 15 ZZK – Bulgarian Protection of Competition Act, Art. 101 TFEU). Inzhkonsult and Zemekop, as a single undertaking, were exempted from the fine; O-Rent received a sanction of 2,403.07 EUR. All three companies must introduce a competition law compliance programme within 60 days and report on it.

What organisations can take from it

The authority now expressly requires compliance programmes – anyone bidding in tenders should have one before it is ordered.

Relevance to training and awareness

Competition law in tenders; compliance programme

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 15 Abs. 1 Nr. 1 und 2 ZZK; Art. 101 Abs. 1 lit. a und c AEUV
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Mitigating circumstances
Immunity from fines for two participants (leniency programme)
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Aug 2026 Rice Lake Weighing Systems, Inc.Scale manufacturer Rice Lake liable for Italian subsidiary's indirect exports to Iran USABreaches of sanctions and embargoes €52,632

In eight instances in 2019–2021, the Italian subsidiary Dini Argeo supplied weighing equipment worth around 121,500 USD to a trader in the UAE, although it knew that the goods would be passed on to a former direct Iranian customer. The parent company had passed on the Iran ban only by an English-language e-mail without explanation; the US Treasury's Office of Foreign Assets Control (OFAC) considered it a non-egregious, voluntarily self-disclosed case.

What organisations can take from it

Implement sanctions requirements at foreign subsidiaries in an understandable way, in the local language and with training for all relevant employees – indirect supplies via traders are also prohibited.

Relevance to training and awareness

Sanctions training for foreign subsidiaries, indirect supplies via third countries

Missing or inadequate training played a role in the decision.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations, § 560.215 (Auslandstöchter von US-Personen)
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Culpability
negligent
Repeat case
no
Mitigating circumstances
Voluntary self-disclosure, immediate internal investigation, low significance for turnover, no prior violations, cooperation; subsequent training of the subsidiary's employees and screening of traders
Published
12 Aug 2026

Original amount 60,764 USD, converted at the ECB reference rate of 12 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Aug 2026 Citibank, N.A., London BranchOFSI imposes 4.7 million GBP on Citibank London over Russia payments United KingdomBreaches of sanctions and embargoes €5.54m

Mainly between February and November 2022, the London branch processed 970 payments totalling around 19.7 million GBP that breached Russia and anti-corruption sanctions. The causes were overloaded alert handling after the wave of designations, delayed escalation and human error; the bank voluntarily disclosed most of the breaches and received a 20% reduction from HM Treasury's Office of Financial Sanctions Implementation (OFSI).

What organisations can take from it

During waves of designations, alert handling needs additional trained capacity – backlogs and wrong decisions in screening are themselves sanctions breaches.

Relevance to training and awareness

Handling sanctions alerts, escalation and freezing

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019; Global Anti-Corruption Sanctions Regulations 2021; s. 146 Policing and Crime Act 2017
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Predominantly voluntary disclosure and cooperation (20% reduction); exceptional burden caused by the 2022 sanctions packages taken into account
Published
2 Sep 2026

Original amount 4,732,830.58 GBP, converted at the ECB reference rate of 11 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Aug 2026 Volga-Dnepr Airlines LLCFederal Court: cargo airline Volga-Dnepr remains on Canadian sanctions list CanadaBreaches of sanctions and embargoes Order

The Russian cargo airline had been added to the list of the Special Economic Measures (Russia) Regulations in April 2023; the Minister of Foreign Affairs rejected the application for delisting. The Federal Court (2026 FC 1048) dismissed the application for judicial review: the Minister had not exercised her broad discretion unreasonably, and there was no procedural error.

What organisations can take from it

Listed logistics partners often remain listed for years – anyone buying air freight must continuously screen carriers and parent companies against sanctions lists.

Relevance to training and awareness

Listings of transport service providers in partner screening

Authority / court
Federal Court (2026 FC 1048); Minister of Foreign Affairs
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Special Economic Measures Act; Special Economic Measures (Russia) Regulations, SOR/2014-58, ss. 2(a), 8
Action
Order
Status of proceedings
unknown
Sector
Transport, logistics and shipping

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Aug 2026 Your Neighbourhood Credit Union LimitedFINTRAC: CAD 16,500 penalty on Your Neighbourhood Credit Union Limited for one violation of anti-money laundering obligations CanadaInternal controls €10,243

According to FINTRAC, Your Neighbourhood Credit Union Limited is a provincially regulated credit union based in Kitchener, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 16,500 on the company on 10 August 2026. According to FINTRAC's findings, made during a compliance examination, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned written compliance policies and procedures. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Your Neighbourhood Credit Union Limited", published 24 September 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-09-24-2-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(b); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Sep 2026

Original amount 16,500 CAD, converted at the ECB reference rate of 10 Aug 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Aug 2026 Veloxis Pharmaceuticals Inc.Veloxis: over 46 million USD – luxury trips, dinners and gifts for transplant teams USAGifts, hospitality and benefits Other

From 2016 to 2023, Veloxis provided transplant professionals with expensive meals and alcohol, trips and stays at luxury resorts, gifts and consultancy fees without consideration, and paid specialty pharmacies concealed remuneration in order to promote prescriptions and purchases of the immunosuppressant Envarsus XR. The company entered into a Deferred Prosecution Agreement with a criminal payment of more than 10 million USD, is paying 34.45 million USD under civil law (21,211,251 USD to the federal government, 13,238,749 USD to states) and a penalty of 1.55 million USD under the Sunshine Act (Open Payments) – the highest to date – totalling over 46 million USD.

What organisations can take from it

Invitations and gifts to decision-makers must not only be limited but also fully reported to transparency registers.

Relevance to training and awareness

Gifts, travel and hospitality for healthcare professionals; transparency reporting

Authority / court
U.S. Department of Justice / U.S. Attorney's Office, District of Massachusetts
Area of law
Bribery and corruption · Gifts, hospitality and benefits
Legal basis
Anti-Kickback Statute; False Claims Act; Physician Payments Sunshine Act (Open Payments)
Action
Other
Status of proceedings
final
Sector
Chemicals and pharmaceuticals

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2026 Hair-Line Kft.Hair-Line: 68.5 million HUF for price and territorial restrictions on hairdressing supplies HungaryCartels and collusion €187,929

In 2018–2022, the distributor of professional hairdressing products (Alfaparf, Yellow) determined the prices at which its territorial representatives were allowed to sell to salons and retailers and restricted passive sales outside the territories. Under a settlement and with a commitment to a compliance programme, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 68.5 million HUF.

What organisations can take from it

Commercial agent systems with territorial protection must not restrict resale prices or passive sales either.

Relevance to training and awareness

Price and territorial restrictions in the distribution system

Missing or inadequate training played a role in the decision.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Cartels and collusion
Legal basis
Ungarisches Wettbewerbsgesetz, Verbot wettbewerbsbeschränkender Vereinbarungen (VJ/17/2022)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Cooperation, acknowledgement in the settlement and commitment to a comprehensive compliance programme.
Published
7 Aug 2026

Original amount 68,500,000 HUF, converted at the ECB reference rate of 7 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2026 ACRO Criminal Records OfficeICO: reprimand for ACRO Criminal Records Office after cyber incident United KingdomData breaches and data security Reprimand or warning

The UK Information Commissioner's Office (ICO) issued a reprimand to ACRO Criminal Records Office. According to the ICO, it followed a cyber incident that may have affected the personal data of around 10,000 people in the UK. The ICO found infringements of the duty to implement appropriate technical and organisational security measures under Article 32 UK GDPR. No fine was imposed.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32(1), 32(1)(b) und 32(1)(d) UK GDPR; Verwarnung nach Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AS Asphaltstraßensanierung GmbH, BITUNOVA GmbH, Kutter Spezialstraßenbau GmbH & Co. KG, Possehl Construction GmbH (inkl. VSI), Liesen…alles für den Bau GmbH, OAT GmbH/Otto Alte-Teigeler GmbHBundeskartellamt: 60.3 million EUR against DSK road repair cartel GermanyCartels and collusion €60.3m

From around 2010 to September 2019, six suppliers of thin cold-laid asphalt surface layers (Dünne Asphaltdeckschichten in Kaltbauweise, DSK) allocated customers – primarily public contracting authorities – and contracts among themselves nationwide and coordinated prices. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines of around 60.3 million EUR; all proceedings ended in settlements.

What organisations can take from it

Anyone who "shares out" public contracts regionally risks fines running into millions – calculations and bids must always be prepared independently.

Relevance to training and awareness

Customer allocation and bid rigging in public contracts

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB, Art. 101 AEUV
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Mitigating circumstances
Leniency bonus for Possehl/VSI, Bitunova, Kutter and AS; settlement
Published
6 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 Elderly Aids LimitedICO: £190,000 fine for Elderly Aids over unsolicited marketing calls United KingdomMarketing and consent €221,691

The ICO fined Elderly Aids Limited, a seller of call-blocking devices, £190,000 and also issued an enforcement notice. The ICO found that the company had made 758,053 unsolicited direct marketing calls to numbers registered with the TPS/CTPS whose subscribers had not agreed to such calls, leading to 20 complaints. The legal basis is regulations 21 and 24 of PECR. Under the notice, payment by 7 September 2026 reduces the amount by 20% to £152,000.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 21 und 24 PECR; section 55A DPA 1998 (Geldbuße), section 40 DPA 1998 (Anordnung)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Original amount 190,000 GBP, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 „Чили Хилс Фудс“ ООД (Chili Hills Foods OOD)Chili Hills Foods: 20,022 EUR for false copying allegations against competitor BulgariaCompetition law €20,022

From May 2024, in social media videos (campaign ‘Създавай! Не копирай!’), the company falsely accused a competing family business for hot chillies of having stolen its business, ideas and concept, and promoted the clips partly through paid advertising. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) regarded this as unfair damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act), imposed 4% of 2025 net turnover (500,555 EUR), i.e. 20,022 EUR, and ordered immediate cessation. Appeals have been lodged against the decision.

What organisations can take from it

Allegations against competitors on social media are only permissible if based on verifiable facts – paid reach aggravates the sanction.

Relevance to training and awareness

Statements about competitors on social media

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
Action
Fine
Status of proceedings
under appeal
Sector
Food and agriculture
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 Capwatt Retail Gás PT, S.A.Portugal: 12,000 EUR against Capwatt over gas reserves and dispute resolution notice PortugalOther €12,000

In several months of 2023 and 2024, the gas supplier did not hold the natural gas security reserves and did not name the competent alternative dispute resolution bodies in customer contracts. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) accepted the settlement proposal, set a fine of 24,000 EUR and reduced it to 12,000 EUR.

What organisations can take from it

Mandatory information in consumer contracts – for example on dispute resolution – belongs in a regularly reviewed contract template.

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Other
Legal basis
RSSE, Art. 29; Decreto-Lei n.º 62/2020, Art. 57, 96; Portaria n.º 59/2022; RRC Art. 22
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Settlement with admission and remediation

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies USA, NYSecurity measures and risk management €216,375

The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.

What organisations can take from it

Even small financial service providers must keep documented patch policies and regular risk assessments.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
Published
5 Aug 2026

Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2026 AS "Latvijas valsts meži"7.86 million EUR against Latvijas valsts meži for breach of competitive neutrality LatviaCompetition law €7.86m

From 2020 to April 2026, on the basis of old long-term logging contracts, the state forestry group supplied six wood processors with guaranteed quantities of roundwood outside public auctions, while all others could only buy through auctions. In its first decision on the competitive neutrality of public undertakings, the Konkurences padome (Latvian Competition Council) imposed 7,859,606.89 EUR and required equal sales conditions for all qualified bidders.

What organisations can take from it

State-owned companies must allocate resources without discrimination – review historical special contracts regularly for competitive neutrality.

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law
Legal basis
Art. 14.1 Konkurences likums (Wettbewerbsneutralität)
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
13 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2026 Lime Technology S.r.l., EmTransit S.r.l. (Dott), Bird Rides Italy S.r.l.Rome: 2.675 million EUR against e-scooter and e-bike sharing providers over blocked free rides ItalyInformation duties in online retail €2.68m

The three sharing providers made it difficult for holders of a Metrebus annual pass to access the free-ride passes promised when the concessions were awarded, through inadequate organisation, cumbersome activation and long waiting times, which shortened the usable time; Bird also deactivated accounts without prior notice. The AGCM imposed fines totalling 2.675 million EUR in three proceedings (Lime 1.4 million, Dott 525,000, Bird 750,000 EUR).

What organisations can take from it

Promised benefits must also be redeemable in organisational terms – sluggish processing can itself be unfair.

Relevance to training and awareness

Customer service and redemption of promised services

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Codice del Consumo (pratiche commerciali scorrette), Verfahren PS13028, PS13029, PS13030
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
6 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Aug 2026 UBS Financial Services Inc.FinCEN: 125 million USD against UBS Financial Services as a repeat offender USAInternal controls €108.4m

The US Financial Crimes Enforcement Network (FinCEN) imposed 125 million USD on the broker-dealer – the highest BSA penalty against a broker-dealer to date. UBSFS admitted wilful infringements: the AML programme was inadequate, more than 50,000 foreign currency transfers totalling more than 10 billion USD were not adequately monitored and suspicious activity reports were not filed; it is already the second enforcement action after 2018.

What organisations can take from it

Monitoring gaps left unremedied after an earlier enforcement action lead, the second time round, to a multiple of the original penalty.

Authority / court
Financial Crimes Enforcement Network (FinCEN)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Bank Secrecy Act (BSA)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Culpability
intentional
Repeat case
yes
Mitigating circumstances
Up to 15 million USD (remaining amount due by 31 May 2028) may be waived to the extent that UBSFS bears the costs of the independent review of its AML programme and implements its recommendations
Published
3 Aug 2026

Original amount 125,000,000 USD, converted at the ECB reference rate of 3 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Aug 2026 Zhengzhou Synear Food Co., Ltd.UFLPA list: frozen food manufacturer Zhengzhou Synear Food added USAForced and child labour Order

The U.S. Forced Labor Enforcement Task Force (FLETF) added the frozen food manufacturer to the Uyghur Forced Labor Prevention Act (UFLPA) Entity List because it works with the Xinjiang government to take in Uyghurs, Kazakhs, Kyrgyz or members of other persecuted groups under state labour transfer programmes. The company's goods are therefore presumed to have been produced with forced labour on import into the US unless the importer rebuts this.

What organisations can take from it

Food importers should also check suppliers outside Xinjiang for involvement in state labour transfer programmes.

Authority / court
U.S. Department of Homeland Security (Forced Labor Enforcement Task Force)
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
Uyghur Forced Labor Prevention Act, Section 2(d)(2)(B)(ii)
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Aug 2026 Guangxi Kelun Pharmaceutical Co., Ltd.UFLPA list: antibiotics manufacturer Guangxi Kelun Pharmaceutical added USAForced and child labour Order

The U.S. Forced Labor Enforcement Task Force (FLETF) listed the manufacturer of cephalosporin antibiotics because it sources antibiotic intermediates from Yili Chuanning Biotechnology in Xinjiang. The company's goods are therefore presumed to have been produced with forced labour on import into the US unless the importer rebuts this.

What organisations can take from it

Pharmaceutical companies must be able to trace their supply chains back to active ingredient intermediates.

Authority / court
U.S. Department of Homeland Security (Forced Labor Enforcement Task Force)
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
Uyghur Forced Labor Prevention Act, Section 2(d)(2)(B)(v)
Action
Order
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Aug 2026 Shandong Weiqiao Pioneering Group Co., Ltd.UFLPA list: textile group Shandong Weiqiao Pioneering Group over Xinjiang cotton USAForced and child labour Order

The U.S. Forced Labor Enforcement Task Force (FLETF) added the cotton and textile producer to the Uyghur Forced Labor Prevention Act (UFLPA) Entity List because it sources cotton from Xinjiang. The company's goods are therefore presumed to have been produced with forced labour on import into the US unless the importer rebuts this.

What organisations can take from it

Textile retailers need proof of origin for cotton down to the fibre, for example through isotope or traceability testing.

Authority / court
U.S. Department of Homeland Security (Forced Labor Enforcement Task Force)
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
Uyghur Forced Labor Prevention Act, Section 2(d)(2)(B)(v)
Action
Order
Status of proceedings
unknown
Sector
Other
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jul 2026 Access DX Laboratory, LLCAccess DX Laboratory: 36.4 million USD – kickbacks for unnecessary genetic tests USACommercial bribery €31.7m

The Houston laboratory, its former CEO Michael Stewart and the businessman Harold Shatz allegedly paid kickbacks and billed Medicare and Medicaid for medically unnecessary genetic tests. The three settlements add up to 36.4 million USD; the laboratory is subject to a Corporate Integrity Agreement.

What organisations can take from it

Commission models for intermediaries who bring in orders or patients are a classic gateway for bribery.

Relevance to training and awareness

Remuneration of intermediaries and referrers

Authority / court
U.S. Department of Justice
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Healthcare
Liability of senior managers
Former CEO pays under a separate settlement.

Original amount 36,400,000 USD, converted at the ECB reference rate of 30 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jul 2026 Airbus Operations LimitedAirbus Operations pays 6.4 million GBP for export control breaches in technology transfer United KingdomExport control and dual-use goods €7.48m

Over an extended period before November 2022, Airbus Operations Ltd breached the Export Control Order 2008: transfers of controlled technology under three open general export licences (OGEL) were not correctly documented, required registers were missing, and one individual licence was not complied with. The case came to light through voluntary disclosure and was concluded by HM Revenue & Customs (HMRC) by way of a compound settlement (date of publication).

What organisations can take from it

Technology transfers by e-mail or data room are also exports – conditions, registers and records of general licences must be put into practice day to day.

Relevance to training and awareness

Licence conditions and record-keeping obligations in technology transfer

Authority / court
HM Revenue & Customs (HMRC) / Export Control Joint Unit
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Control Order 2008, Art. 29(2) und 29(3) (Auflagen und Register bei OGELs) sowie Auflage einer SIEL; Straftaten nach Art. 38(1)(a) und (b); Compound Settlement durch HMRC
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Employees
10,000 or more
Mitigating circumstances
Voluntary disclosure, full cooperation, remedial measures
Published
30 Jul 2026

Original amount 6,409,388 GBP, converted at the ECB reference rate of 30 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 AvisAvis: maximum fine of 1 million EUR for handling fee on traffic fines SpainInformation duties in online retail €1m

The car rental company charged customers an "administration fee" of 33.88 to 45 EUR when a rental car incurred a traffic offence – even though naming the driver is a statutory obligation of the rental company. Spain's Ministry of Social Rights, Consumer Affairs and 2030 Agenda classified this as a very serious infringement and imposed the maximum fine of 1 million EUR; a court had already declared the clause void in 2020.

What organisations can take from it

No additional fee may be charged for fulfilling statutory obligations – least of all after a court has prohibited the clause.

Authority / court
Ministerio de Derechos Sociales, Consumo y Agenda 2030
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Artt. 82, 87.5 y 87.6 TRLGDCU (Real Decreto Legislativo 1/2007)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Repeat case
yes
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 Österreichischer Rundfunk (ORF)KommAustria finds unlabelled product placement in ORF's ‘Sport aktuell’ AustriaMisleading advertising and pricing Order

In the programme ‘Sport aktuell’ on ORF 1 on 29 July 2025, a logo wall was visible as product placement without being labelled. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) found, with final effect, a violation of the ORF Act (ORF-Gesetz).

What organisations can take from it

Product placements must be identified and labelled by the editorial team – including logo walls in the background.

Relevance to training and awareness

Labelling of advertising and product placement

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 16 Abs. 5 Z 4 ORF-G
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2026 TrenitaliaTrenitalia removes hurdles to refunds for delays following AGCM proceedings ItalyInformation duties in online retail Order

For refunds in the event of delays of 60 minutes or more or cancellations, Trenitalia required prior written confirmation from the call centre or ticket office. The AGCM accepted binding commitments: abolition of the confirmation requirement, strengthened refund channels, an information page on disruptions and an implementation report within three months; no infringement was found.

What organisations can take from it

Additional formalities before statutory refunds act as a hurdle and lead to proceedings.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Codice del Consumo (impegni); EU-Fahrgastrechte im Eisenbahnverkehr
Action
Order
Status of proceedings
final
Sector
Transport, logistics and shipping
Mitigating circumstances
Binding commitments, no finding of an infringement.
Published
30 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Jul 2026 Equity for Growth (Securities) Limited (in liquidation)FCA: Public censure for Equity for Growth (Securities) over misleading minibond promotions United KingdomMisleading advertising and pricing Reprimand or warning

The FCA publicly censured the corporate finance firm Equity for Growth (Securities) Limited. The FCA found that between January 2018 and August 2019 the firm approved seven information memoranda for four unregulated minibond issuers as financial promotions. In the FCA's view, these documents omitted key information, such as the level and range of commissions, so investors could not properly assess the risk. Because the firm was wound up by the court in March 2026 on the FCA's petition, no fine was imposed; the FCA stated that it would otherwise have been £386,467 (including disgorgement).

Authority / court
Financial Conduct Authority (FCA)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
COBS 4.2.1(1)R; section 205 FSMA 2000 (Public Censure)
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Jul 2026 Metropolitan Police ServiceICO: order and reprimand against London's Met Police after disclosure of sensitive data United KingdomData breaches and data security Order

The Metropolitan Police handed a defendant unredacted documents containing the new address and telephone number of a stalking victim, and in a circular e-mail disclosed 18 people with a parliamentary connection in an open recipient list. The UK Information Commissioner's Office (ICO) ordered improvements within 3 and 12 months, including in data protection training completion rates.

What organisations can take from it

Policies are not enough if mandatory training goes uncompleted for years – monitor and enforce training completion rates.

Relevance to training and awareness

Redacting documents, e-mail distribution lists (BCC), data protection training

Missing or inadequate training played a role in the decision.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Data Protection Act 2018, Section 40
Action
Order
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Culpability
negligent
Published
5 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jul 2026 The New Brunswick Lotteries and Gaming CorporationFINTRAC: CAD 399,712.50 penalty on The New Brunswick Lotteries and Gaming Corporation for one violation of anti-money laundering obligations CanadaSuspicious activity reports €249,415

According to FINTRAC, The New Brunswick Lotteries and Gaming Corporation is a reporting entity in the casino sector based in Fredericton, New Brunswick. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 399,712.50 on the company on 24 July 2026. According to FINTRAC's findings, made during a compliance examination, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned suspicious transaction reporting. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on the New Brunswick Lotteries and Gaming Corporation", published 3 September 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-09-03-2-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Other
Published
3 Sep 2026

Original amount 399,712.5 CAD, converted at the ECB reference rate of 24 Jul 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering EU levelPlatform obligations €890m

In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.

What organisations can take from it

Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2026 Caisse populaire acadienne ltéeFINTRAC: CAD 676,500 penalty on Caisse populaire acadienne ltée for 3 violations of anti-money laundering obligations CanadaSuspicious activity reports €421,916

According to FINTRAC, Caisse populaire acadienne ltée is a federally regulated credit union based in Caraquet, New Brunswick. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 676,500 on the company on 23 July 2026. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, written compliance policies and procedures and assessing and documenting money laundering and terrorist financing risks. Specifically, according to FINTRAC, the credit union failed in four instances to report multiple transactions that showed indicators of suspicion. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Caisse populaire acadienne ltée", published 24 September 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-09-24-4-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(2); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Sep 2026

Original amount 676,500 CAD, converted at the ECB reference rate of 23 Jul 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2026 Orchids Builders LLCFlorida roofer: $349,754 for repeatedly missing fall protection USAWorkplace safety and accidents €307,017

On 21.01. and 10 March 2026, the U.S. Occupational Safety and Health Administration (OSHA) found at two residential construction sites in Rockledge that employees of the roofing contractor were working on roofs without fall protection; training records, eye protection when using nail guns and ladders extending sufficiently above the roof edge were also missing. The company had been inspected seven times since 2023, each time with fall protection violations. Proposed: $349,754 (2 wilful, 4 repeat violations).

What organisations can take from it

Companies that allow the same fall hazards to recur after earlier inspections risk classification as a repeat or wilful violation with substantially higher penalties.

Relevance to training and awareness

Fall protection during roofing work

Missing or inadequate training played a role in the decision.

Authority / court
U.S. Department of Labor – Occupational Safety and Health Administration (OSHA)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
29 CFR 1926 Subpart M (Fall Protection), Subpart X (Ladders)
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
intentional
Repeat case
yes
Published
23 Jul 2026

Original amount 349,754 USD, converted at the ECB reference rate of 23 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2026 Nova Scotia Gaming CorporationFINTRAC: 231,826 CAD against Nova Scotia Gaming over missing suspicious transaction reports CanadaSuspicious activity reports €144,584

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 231,826 CAD on the Halifax gaming corporation (casino sector) because it failed to file suspicious transaction reports on attempted transactions despite reasonable grounds for suspicion, did not keep its compliance policies up to date and approved by a senior officer, and did not assess the money laundering risk as required. The penalty was paid in full.

What organisations can take from it

Even aborted or merely attempted transactions can be reportable – cashier staff must know this.

Relevance to training and awareness

Suspicious transaction reports even for merely attempted transactions

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
final
Sector
Other
Published
3 Sep 2026

Original amount 231,826 CAD, converted at the ECB reference rate of 23 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Maxxis International GmbH, Best4Tires Berlin GmbH, Reifen Müller GmbH & Co. KGBundeskartellamt: 11.9 million EUR over resale price maintenance in tyre distribution (Maxxis/CST) GermanyCartels and collusion €11.9m

Maxxis guaranteed wholesalers fixed margins per tyre sold of the Maxxis and CST brands, monitored prices in particular on the Tyre24 platform and intervened when prices were too low. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines totalling 11.9 million EUR on three companies and one responsible individual.

What organisations can take from it

Margin guarantees and price controls vis-à-vis dealers constitute prohibited resale price maintenance – sales teams need clear rules for price discussions.

Relevance to training and awareness

Influencing resale prices and price monitoring on platforms

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB (vertikale Preisbindung)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Settlement with Maxxis and Reifen Müller
Liability of senior managers
Fine imposed on one responsible natural person (not named)
Published
21 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products EU levelPlatform obligations €550m

AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.

What organisations can take from it

The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jul 2026 NeoGenomics Laboratories Inc.NeoGenomics: 9.8 million USD after self-disclosure – discounted consulting for referring physicians USACommercial bribery €8.59m

The Florida laboratory provided referring physicians with consulting services below market value and paid independent consultants referral-based remuneration for recruiting physicians. Following a self-disclosure, NeoGenomics paid 9,813,260 USD.

What organisations can take from it

Free or discounted services are also benefits – like cash payments, they belong in the anti-corruption review.

Relevance to training and awareness

Services with monetary value provided to customers below market value

Authority / court
U.S. Department of Justice
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
Self-disclosure of the remuneration arrangements.

Original amount 9,813,260 USD, converted at the ECB reference rate of 20 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jul 2026 EyePoint Pharmaceuticals, Inc.EyePoint: 4.66 million USD – kickbacks to surgery centres for purchasing an eye medicine USACommercial bribery €4.08m

Between January 2019 and March 2023, the pharmaceutical manufacturer allegedly paid kickbacks to ambulatory surgery centres to induce them to purchase and use the injectable drug DEXYCU for cataract surgery. To resolve the False Claims Act allegations, EyePoint paid 4,657,463.18 USD and entered into a Corporate Integrity Agreement with HHS-OIG.

What organisations can take from it

Discounts, payments or services to institutions that make purchasing decisions require a documented consideration at market value.

Relevance to training and awareness

Granting benefits to customers and purchasing decision-makers

Authority / court
U.S. Department of Justice
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Chemicals and pharmaceuticals

Original amount 4,657,463.18 USD, converted at the ECB reference rate of 20 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 The Scoular CompanyAgricultural trader Scoular pays 10 million USD over bribes to Mexican border officials USABribery of public officials €8.91m

From 2013 to 2019, Scoular had customs brokers pay around 400,000 USD to Mexican border and inspection officials so that trains carrying contaminated maize and grain would pass inspections; some of the money went to individuals close to cartels. Three-year DPA with a criminal penalty of 9,769,521 USD and forfeiture of 414,351 USD.

What organisations can take from it

Customs agents and freight forwarders are high-risk third parties: question conspicuous flat fees per shipment, even if they appear to be customary charges.

Relevance to training and awareness

Facilitation payments via customs agents and logistics service providers

Missing or inadequate training played a role in the decision.

Authority / court
U.S. Department of Justice (Criminal Division, Fraud Section; USAO Western District of Texas)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA (Verschwörung zur Verletzung der Anti-Bestechungsvorschriften); Deferred Prosecution Agreement
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Culpability
intentional
Mitigating circumstances
Cooperation and remediation (including an overhaul of compliance, third-party management, financial controls and anti-corruption training); 25 % reduction off the low end of the sentencing guidelines range.
Liability of senior managers
The customs broker Carlos Leopoldo Alvelais has pleaded guilty.
Published
17 Jul 2026

Original amount 10,183,872 USD, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Puratos LimitedPuratos: 120,000 GBP for flour dust above exposure limits and heavy sack handling United KingdomWorkplace safety and accidents €141,014

During an inspection in December 2024, the Health and Safety Executive (HSE) found dust escaping from machinery, blowing down with compressed air and dry sweeping at the bakery ingredients factory; measurements confirmed that workplace exposure limits had been exceeded, with a risk of asthma. In addition, employees lifted 25 kg sacks by hand every day. The site had already been cited in 2021 for the same deficiencies; fine of 120,000 GBP plus 6,270 GBP in costs.

What organisations can take from it

Companies that do not permanently remedy deficiencies after a citation pay significantly more the next time – flour dust is a recognised cause of asthma.

Relevance to training and awareness

Dust exposure and lifting heavy loads

Authority / court
Health and Safety Executive (Milton Keynes Magistrates' Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Health and Safety at Work etc. Act 1974, s. 2(1)
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Repeat case
yes
Published
20 Jul 2026

Original amount 120,000 GBP, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay GermanyDisclosure and reporting obligations €240,000

Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.

What organisations can take from it

Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.

Relevance to training and awareness

Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 Royal Mail Group LtdTribunal: Royal Mail subjected whistleblower to detriment – £6,978 compensation United KingdomRetaliation against whistleblowers €8,222

The Employment Tribunal in Manchester found that the claimant had been subjected to detriment because of a protected disclosure and awarded her the agreed amount of £6,978.20. The claims for disability discrimination and constructive dismissal were dismissed.

What organisations can take from it

Large organisations, too, must ensure that whistleblowers do not suffer disadvantages in their day-to-day work.

Relevance to training and awareness

How managers handle internal reports

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, s. 47B (Benachteiligung wegen geschützter Offenlegung)
Action
Other
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Published
7 Sep 2026

Original amount 6,978.2 GBP, converted at the ECB reference rate of 16 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative GermanyInformation duties in online retail Order

On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.

What organisations can take from it

Keep retention or pause offers off the confirmation page of the online cancellation process.

Relevance to training and awareness

Design of the cancellation process (cancellation button, retention offers)

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
Action
Order
Status of proceedings
final
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2026 Vanilla Chip LLC (TruHeight)TruHeight: FTC settlement over allegedly fake reviews for growth supplement USAFake reviews €657,549

According to the FTC, employees of the dietary supplement provider wrote thousands of five-star reviews, customers received free products or discounts in return for five-star reviews, and bot profiles posed as real users; in addition, there were unsubstantiated growth claims for children and adolescents. The final settlement order provides for a judgment of 4 million USD, which is partially suspended on account of limited ability to pay after payment of 750,000 USD.

What organisations can take from it

Reviews by employees or reviews rewarded for positive star ratings are prohibited and, since 2024, subject to civil penalties.

Relevance to training and awareness

Fake and purchased customer reviews

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Section 5 FTC Act; FTC Rule on the Use of Consumer Reviews and Testimonials
Action
Disgorgement of profits
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Partial suspension of the judgment on account of limited ability to pay.
Liability of senior managers
The co-founders and co-CEOs Eden Stelmach and Justin Rapoport are personally parties to the order.
Published
15 Jul 2026

Original amount 750,000 USD, converted at the ECB reference rate of 15 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2026 CalPlus GmbH, Elektronik-Kontor Messtechnik GmbH, TVW Meßtechnik GmbHBundeskartellamt: 453,000 EUR against distributors of test and measuring equipment GermanyCartels and collusion €453,000

From 2016 to 2022, three distributors of test and measuring equipment coordinated discounts as essential price components and informed each other of customer contacts, usually with a request for "restraint". This was evidenced by more than 400 emails; the proceedings ended in settlements.

What organisations can take from it

Small distributors are liable too: merely asking a competitor to "hold back" with a customer is a prohibited customer allocation agreement.

Relevance to training and awareness

Email contacts with competitors about customers and discounts

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Mitigating circumstances
Settlement; cooperation by Elektronik-Kontor Messtechnik taken into account
Published
15 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2026 FleetPride Inc.FleetPride: $264,380 after asphyxiation death during tank trailer inspection USAWorkplace safety and accidents €231,790

At the truck parts distributor's Corpus Christi (Texas) site, an employee was asphyxiated while inspecting a tank trailer. The U.S. Occupational Safety and Health Administration (OSHA) found no confined space programme, deficiencies in the respiratory protection programme and electrical hazards, and proposed $264,380 (16 serious, 3 other violations).

What organisations can take from it

Tanks and vessels are confined spaces with a risk of asphyxiation – no one may enter without a permit, atmospheric testing and an attendant.

Relevance to training and awareness

Working in confined spaces and vessels

Authority / court
U.S. Department of Labor – Occupational Safety and Health Administration (OSHA)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
29 CFR 1910.146 (Permit-required confined spaces); 29 CFR 1910.134 (Respiratory protection)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
15 Jul 2026

Original amount 264,380 USD, converted at the ECB reference rate of 15 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2026 Colonial Farms Ltd.Colonial Farms: CFIA administrative monetary penalty of 11,000 CAD under SFCR s. 88 CanadaOther €6,852

On 15 July 2026, the Canadian Food Inspection Agency (CFIA) imposed an administrative monetary penalty of 11,000 CAD on the company in Western Canada for a violation of s. 88 of the Safe Food for Canadians Regulations. An earlier penalty under the same provision from May 2025 was set aside in review proceedings.

What organisations can take from it

Companies that do not eliminate the cause after a first penalty risk repeat penalties and stricter supervision.

Authority / court
Canadian Food Inspection Agency (CFIA)
Area of law
Other
Legal basis
Safe Food for Canadians Regulations, s. 88
Action
Fine
Status of proceedings
final
Sector
Food and agriculture

Original amount 11,000 CAD, converted at the ECB reference rate of 15 Jul 2026.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment MaltaCustomer due diligence €80,907

The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.

What organisations can take from it

Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.

Relevance to training and awareness

Risk-based customer assessment in gambling

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps GermanyCustomer due diligence €210,000

Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.

What organisations can take from it

Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.

Relevance to training and awareness

Ongoing monitoring of business relationships and suspicious activity reporting

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time GermanyDisclosure and reporting obligations €187,500

The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.

What organisations can take from it

Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.

Relevance to training and awareness

Threshold monitoring and notification deadlines for shareholdings

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 33 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
22 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jul 2026 Hutchison Technologies LtdTribunal: Hutchison Technologies dismissed employee after she raised holiday pay concerns United KingdomRetaliation against whistleblowers Other

An employee of the Dundee-based electrical services provider for gyms (around 140 employees) had pointed out that the technicians' holiday pay was being calculated incorrectly; a few days later her home working arrangement was withdrawn, and on 11 June 2025 she was dismissed. The Employment Tribunal upheld her claims for automatically unfair dismissal (s. 103A) and detriment (s. 47B); compensation will be decided separately.

What organisations can take from it

Employers who worsen working conditions shortly after a disclosure must be able to prove a documented reason unrelated to the disclosure.

Relevance to training and awareness

How managers handle internal reports

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, ss. 43B, 47B, 103A
Action
Other
Status of proceedings
unknown
Sector
Other
Employees
50 to 249
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles SloveniaEmployee data Order

The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.

What organisations can take from it

Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.

Relevance to training and awareness

Consent and proportionality in employee monitoring

Authority / court
Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
Area of law
Data protection · Employee data
Legal basis
Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
7 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR LatviaCookies and tracking €1,000

In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.

What organisations can take from it

Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.

Relevance to training and awareness

Cookie banners and cooperation with the supervisory authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR EU levelOrganisational requirements €2.15m

The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.

What organisations can take from it

Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR LithuaniaDisclosure and reporting obligations €362,000

Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.

What organisations can take from it

Running daily fines make every delay expensive – supervisory orders need top-management priority.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Published
30 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options BelgiumOrganisational requirements €1m

In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.

What organisations can take from it

Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Neonet S.A.Neonet: 3 million PLN over false delivery and availability information on Allegro PolandInformation duties in online retail €709,854

On its Allegro account, the electronics retailer promised dispatch within 24 hours even for goods not in stock and did not inform customers in good time of delays or unavailability. UOKiK imposed a fine of 3,043,000 PLN; the decision is not final.

What organisations can take from it

Link delivery and availability information to stock levels; in the event of delays, inform customers immediately.

Relevance to training and awareness

Availability and delivery information on marketplaces

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
26 Jun 2026

Original amount 3,043,000 PLN, converted at the ECB reference rate of 26 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition BulgariaCompetition law €52,097

On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.

What organisations can take from it

Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Published
2 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 TotalEnergiesParis Judicial Court: TotalEnergies must include Scope 3 emissions in vigilance plan FranceSupply chain due diligence Order

In an action brought by Notre Affaire à Tous, Sherpa, ZEA, France Nature Environnement and the City of Paris, the Paris Judicial Court (Tribunal judiciaire de Paris, 34th chamber) ruled that climate risks fall under the French duty of vigilance law and that Scope 3 emissions are part of the oil and gas group's activities. The vigilance plan without Scope 3 is incomplete, the court held; TotalEnergies must supplement it within six months, with provisional enforceability, and implementation will be reviewed by the court in January 2027.

What organisations can take from it

Risk analyses under due diligence laws must also cover the climate impact of the products sold (Scope 3).

Authority / court
Tribunal judiciaire de Paris (34. Kammer)
Area of law
Supply chain and human rights · Supply chain due diligence
Legal basis
Art. L.225-102-1 und L.225-102-2 Code de commerce (Loi n° 2017-399, devoir de vigilance); Art. 1252 Code civil
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Employees
10,000 or more
Published
25 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Kaufland Hrvatska k.d.Croatia: 300,000 EUR against Kaufland for unfair practices towards suppliers CroatiaAbuse of market power €300,000

The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) found that Kaufland Hrvatska charged food suppliers fees for services not provided and for advertising not commissioned, and paid for perishable goods only after more than 30 days. For these unfair trading practices, and with repeat offending as an aggravating factor (final penalty already in 2020), it imposed 300,000 EUR (date = publication).

What organisations can take from it

Purchasing departments must know the payment deadlines and fee prohibitions of UTP law – repeat offences become significantly more expensive.

Relevance to training and awareness

Fair terms towards suppliers in purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 4, 11, 12 Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Repeat case
yes
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked DenmarkPlatform obligations Order

After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.

What organisations can take from it

Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Deghi S.p.A.Deghi: 2 million EUR for endlessly renewing countdown discounts ItalyMisleading advertising and pricing €2m

From January 2024 to December 2025, the online retailer advertised time-limited discounts with countdown timers which, once they had expired, restarted with a new timer on identical terms. The AGCM classified this artificial scarcity as a particularly insidious dark pattern and imposed a fine of 2 million EUR.

What organisations can take from it

A countdown must genuinely expire – an automatically restarting timer creates misleading scarcity.

Relevance to training and awareness

False urgency and countdown timers in online marketing

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Codice del Consumo (pratiche commerciali scorrette)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
25 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 TICKETBIS S.L. (StubHub UK)StubHub UK: 889,200 GBP penalty over mandatory fees added later United KingdomMisleading advertising and pricing €1.03m

The ticket exchange did not include mandatory fees in the total price at the start of the purchasing process. By way of a final infringement notice, the CMA imposed a penalty of 889,200 GBP (including a 40 % settlement discount) and required the company to refund the mandatory fees.

What organisations can take from it

Ticket marketplaces must also show the total price including mandatory fees from the outset.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Digital Markets, Competition and Consumers Act 2024
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Settlement with a 40 % discount and waiver of appeal.
Published
23 Jun 2026

Original amount 889,200 GBP, converted at the ECB reference rate of 23 Jun 2026.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 VARTA AGVARTA: late ad hoc announcement and missing half-yearly financial report GermanyDisclosure and reporting obligations €620,000

BaFin imposed fines on the battery manufacturer because it had not disclosed inside information without delay and had not published the half-yearly financial report for the 2024 financial year.

What organisations can take from it

Ad hoc assessments and periodic disclosure require fixed responsibilities and deadline controls so that neither inside information nor mandatory reports are left pending.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR; § 115 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Published
1 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies ItalyCustomer due diligence €40,000

Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.

What organisations can take from it

Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.

Relevance to training and awareness

Customer due diligence and suspicious transaction reports

Authority / court
Banca d'Italia
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Corrective measures initiated

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Needle Craft Ltd.; Casual Wear Apparel LLCCBP import stop for textiles from Jordan's Needle Craft and Casual Wear Apparel USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: clothing from Needle Craft Ltd.; Casual Wear Apparel LLC (Jordan) is being detained at all US ports of entry because there are indications of forced labour (ILO indicators including physical and sexual violence, retention of identity documents, restriction of movement and withholding of wages). These are two parallel orders against both manufacturers.

What organisations can take from it

Fashion brands should supplement social audits at garment makers with confidential worker interviews, because violence and confiscation of identity documents remain invisible in paper-based checks.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Other
Published
23 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jun 2026 Inkasso-Team AGFederal Administrative Court upholds FDPIC: Inkasso-Team was not allowed to publish debtor data SwitzerlandData subject rights and transparency Order

The debt collection company posted personal data of alleged debtors on the internet, some of it particularly sensitive, in order to obtain information on their whereabouts and to warn third parties. The Swiss Federal Administrative Court (Bundesverwaltungsgericht, A-3891/2025) upheld the ruling of the Federal Data Protection and Information Commissioner (EDÖB) of 28 April 2025, according to which this constitutes an unjustified violation of privacy.

What organisations can take from it

Publicly naming and shaming debtors cannot be justified under data protection law – debt collection must use less intrusive means.

Authority / court
Bundesverwaltungsgericht (A-3891/2025) auf Verfügung des EDÖB vom 28.04.2025
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 6, Art. 19, Art. 31
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jun 2026 CACEIS Bank (UK Branch)FCA: public censure for CACEIS UK over deficient checks on a custody client United KingdomCustomer due diligence Reprimand or warning

The UK Financial Conduct Authority (FCA) issued a public censure because the London branch opened and operated accounts for the wealth manager WealthTek, although its own register searches showed that it lacked permissions to hold client assets, and overlooked a restriction noted in the register; 16 monitoring alerts were not worked through over two years, and more than £314 million flowed through the accounts. In view of cooperation and a voluntary payment of £31.7 million to WealthTek clients, the FCA refrained from imposing a fine (otherwise £23.1 million after discount).

What organisations can take from it

Anyone who notices a discrepancy in the register must clarify and document it before accounts are activated.

Relevance to training and awareness

Register checks and follow-up on identified KYC gaps

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Section 205 FSMA (Public Censure) wegen Verstoßes gegen FCA Principle 2; Maßstab u. a. SYSC 6.1.1R, 6.3.1R, 6.3.3R und Regulations 18, 27, 28 MLR 2017
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Cooperation, acknowledgement of the deficiencies and a voluntary payment of £31,714,068 to those harmed
Published
25 Jun 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2026 LOGZONE Inc.LOGZONE pays 507,144 USD over lack of cybersecurity in Navy contracts USAOther €442,495

The Huntsville-based defence services provider allegedly invoiced two Navy contracts from May 2021 to March 2025 even though it had not implemented the security controls under NIST SP 800-171 required by the contracts. The settlement under the False Claims Act with the U.S. Department of Justice amounts to 507,144 USD.

What organisations can take from it

Companies that commit to cybersecurity requirements in government contracts must document their implementation verifiably – otherwise every invoice becomes a liability risk.

Authority / court
U.S. Department of Justice (Civil Division) / USAO Northern District of Alabama
Area of law
Other
Legal basis
False Claims Act (31 U.S.C. §§ 3729 ff.); DFARS-Cybersicherheitsklauseln
Action
Other
Status of proceedings
final
Sector
Defence and security
Published
18 Jun 2026

Original amount 507,144 USD, converted at the ECB reference rate of 18 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2026 Ideal Supply Inc.Ladder fall in warehouse: industrial supplies distributor pays CA$70,000 Canada, ONWorkplace safety and accidents €43,239

At the warehouse and distribution centre in Listowel (around 130 employees at the site), a worker fell around 1.2 m while climbing down a ladder at high-bay racking. He had not been adequately informed, instructed and supervised on the safe use of ladders. Fine of CA$70,000 plus victim fine surcharge.

What organisations can take from it

Even everyday tasks such as working from ladders at racking require documented instruction – otherwise there is no evidence whatsoever if an incident occurs.

Relevance to training and awareness

Safe use of ladders in the warehouse

Missing or inadequate training played a role in the decision.

Authority / court
Provincial Offences Court Stratford (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Sections 25(2)(a), 66(1) Occupational Health and Safety Act (Ontario)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Mitigating circumstances
Guilty plea.
Published
8 Jul 2026

Original amount 70,000 CAD, converted at the ECB reference rate of 18 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2026 St. Joseph's Healthcare HamiltonHamilton hospital: CA$65,000 after injury caused by known centrifuge defect Canada, ONWorkplace safety and accidents €40,151

In the teaching hospital's virology laboratory, the lid of a centrifuge fell on an employee who had to hold it open by hand because of a defective gas spring; she was seriously injured. Maintenance reports from 2023 and 2024 had already called for the spring to be replaced. Fine of CA$65,000 plus victim fine surcharge.

What organisations can take from it

A defect documented in maintenance reports that is not remedied makes every subsequent accident foreseeable – defective equipment must be taken out of use.

Relevance to training and awareness

Reporting defective equipment and taking it out of service

Authority / court
Provincial Offences Court Hamilton (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 25(1)(b) Occupational Health and Safety Act (Ontario)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
Guilty plea; repair two days after the accident.
Published
21 Jul 2026

Original amount 65,000 CAD, converted at the ECB reference rate of 18 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2026 Advanced Pathology Solutions PLLC und APS MSO LLCAdvanced Pathology Solutions: 30 million USD for kickbacks and unnecessary laboratory tests USACommercial bribery €25.9m

The Arkansas pathology laboratory, its management company and the owners Kevin Hannah, Donell Burkett and Daniel Hunter Pledger allegedly granted unlawful kickbacks and ordered medically unnecessary tests. Together they paid 30 million USD; the laboratory entered into a Corporate Integrity Agreement.

What organisations can take from it

Where services are sold through referrals, all benefits to referrers belong in a central approval and review procedure.

Relevance to training and awareness

Benefits to clients in healthcare

Authority / court
U.S. Department of Justice
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Healthcare
Liability of senior managers
The owners contribute personally as parties to the settlement.

Original amount 30,000,000 USD, converted at the ECB reference rate of 17 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence SwedenCustomer due diligence €12.9m

For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.

What organisations can take from it

The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.

Relevance to training and awareness

Enhanced due diligence for high-risk customers

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Jun 2026

Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Robert Bosch GmbHBosch pays 36 million USD for sensor supplies to Huawei USAExport control and dual-use goods €31.2m

Between September 2020 and September 2024, Bosch exported MEMS sensors and vehicle software worth around 72.4 million USD from outside the US without a licence to Huawei and affiliated companies on the Entity List (Foreign Direct Product Rule). Bosch voluntarily disclosed the violations; around 3.6 million USD of the penalty imposed by the US Commerce Department's Bureau of Industry and Security (BIS) is credited against a disgorgement agreed with the DOJ.

What organisations can take from it

Even products manufactured outside the US can be subject to US export controls via US technology – supplies to Entity List customers need their own review.

Relevance to training and awareness

US export law for foreign-made products (Foreign Direct Product Rule)

Authority / court
U.S. Department of Commerce, Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations (Foreign Direct Product Rule, Entity List)
Action
Fine
Status of proceedings
final
Sector
Automotive
Employees
10,000 or more
Mitigating circumstances
Voluntary self-disclosure and cooperation
Published
17 Jun 2026

Original amount 36,184,680 USD, converted at the ECB reference rate of 16 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Samson Containers LtdContainer manufacturer ignores notices on welding fume and hearing protection – £30,000 United KingdomWorkplace safety and accidents €34,694

Despite improvement notices from September 2024 and February 2025, the manufacturer of skips and metal containers failed to implement any measures against carcinogenic welding fume (mild steel) – with neither extraction nor respiratory protection; in addition, there was no health surveillance for hearing for employees exposed to noise. Fine of £30,000 plus costs.

What organisations can take from it

Regulatory orders on hazardous substances have deadlines – companies that let them lapse will be prosecuted regardless of whether an accident occurs.

Authority / court
Warrington Magistrates' Court (Anklage: Health and Safety Executive)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 33(1)(g) Health and Safety at Work etc. Act 1974 (Nichtbefolgung von Improvement Notices)
Action
Fine
Status of proceedings
unknown
Sector
Steel and metals
Repeat case
yes
Published
18 Jun 2026

Original amount 30,000 GBP, converted at the ECB reference rate of 16 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Serbia Zijin Copper D.O.O.CBP import stop for copper from Serbia Zijin Copper over forced labour indicators USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: copper and copper products from Serbia Zijin Copper D.O.O. (Serbia) are being detained at all US ports of entry because there are indications of forced labour (ILO indicators including withholding of wages, intimidation, restriction of movement and retention of identity documents).

What organisations can take from it

Production in Europe is no free pass either: raw material and metal supply chains need their own forced labour checks.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Steel and metals
Published
16 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis SwedenVideo surveillance Reprimand or warning

The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.

What organisations can take from it

Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.

Relevance to training and awareness

Use of cameras in vehicles

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 6 Abs. 1
Action
Reprimand or warning
Status of proceedings
final
Sector
Defence and security
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit FinlandData subject rights and transparency €792,639

The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.

What organisations can take from it

Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.

Authority / court
Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
18 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage GreeceVideo surveillance €95,000

A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.

What organisations can take from it

Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.

Relevance to training and awareness

Handling video footage and access requests

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function GermanyData breaches and data security Fine

In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.

What organisations can take from it

Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.

Authority / court
Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5, Art. 25 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
Published
10 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report CyprusDisclosure and reporting obligations €16,500

The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.

What organisations can take from it

Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes
Published
7 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Portugal: 8.18 million EUR against three companies over advertising in TV recordings PortugalCartels and collusion €8.18m

With the support of a consultancy, the three largest pay-TV providers agreed from 2019 to May 2025 to introduce advertising as a condition for accessing recordings and to standardise the marketing of this advertising space. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,181,000 EUR on three companies; together with the fourth participant, already sanctioned earlier under a settlement, the fines add up to 13,351,000 EUR. Owing to ongoing court proceedings, the AdC did not publish the names in its announcement.

What organisations can take from it

Jointly coordinated ‘industry solutions’ at customers’ expense are cartels – even when a service provider takes on the coordination.

Relevance to training and awareness

Coordinated product changes among competitors

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º (Processo PRC/2020/4)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) GreeceData subject rights and transparency €110,000

Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.

What organisations can take from it

Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Caisse populaire Alliance limitéeFINTRAC: CAD 82,500 penalty on Caisse populaire Alliance limitée for 4 violations of anti-money laundering obligations CanadaCustomer due diligence €51,055

According to FINTRAC, Caisse populaire Alliance limitée is a provincially regulated credit union based in North Bay, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 82,500 on the company on 5 June 2026. According to FINTRAC's findings, made during a compliance examination, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, enhanced measures for high-risk situations, assessing and documenting money laundering and terrorist financing risks and the prescribed review of the compliance programme. Specifically, according to FINTRAC, 46 of 118 high-risk clients were not reviewed annually, contrary to the credit union's own policies. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Caisse populaire Alliance limitée", published 24 September 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-09-24-1-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
PCMLTFA s. 9.6(1), 9.6(3); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(f), 156(2), 156(3), 157; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Sep 2026

Original amount 82,500 CAD, converted at the ECB reference rate of 5 Jun 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students USAData breaches and data security Order

According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.

What organisations can take from it

Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.

Authority / court
Federal Trade Commission (FTC)
Area of law
Data protection · Data breaches and data security
Legal basis
FTC Act (Verbot unlauterer und irreführender Praktiken)
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Jun 2026 Pathwise Credit UnionFINTRAC: CAD 41,250 penalty on Pathwise Credit Union for 2 violations of anti-money laundering obligations CanadaInternal controls €25,501

According to FINTRAC, Pathwise Credit Union is a provincially regulated credit union based in Oshawa, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 41,250 on the company on 4 June 2026. According to FINTRAC's findings, made during a compliance examination, the company committed 2 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures and assessing and documenting money laundering and terrorist financing risks. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Pathwise Credit Union", published 24 September 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-09-24-3-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Sep 2026

Original amount 41,250 CAD, converted at the ECB reference rate of 4 Jun 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2026 VF Hellas Ενδυμάτων Ε.Π.Ε. (VF Hellas, Tochter der VF Corporation)Greece: 954,485 EUR against VF Hellas for banning price comparison and Google Ads GreeceCartels and collusion €954,485

The importer and wholesaler of the Vans, Eastpak and The North Face brands contractually prohibited its retailers from using price comparison portals and search engine advertising (in particular Google Ads). The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) regarded this as a hardcore restriction in online sales and, in a settlement procedure (Decision 913/2026), set a reduced fine of 954,485 EUR; date = press release.

What organisations can take from it

Prohibiting retailers from using price comparison sites or search engine advertising is a hardcore restriction – distribution agreements should regularly undergo competition law review.

Relevance to training and awareness

Competition-law-compliant design of dealer agreements in online sales

Authority / court
Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 1 Gesetz 3959/2011; Art. 101 AEUV; Art. 4 lit. e VO (EU) 2022/720
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Settlement procedure (Diettheti Diaforon) with fine reduction
Published
3 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2026 Sonus Public Relations LtdTribunal: PR agency Sonus must pay £71,052 after subjecting whistleblower to detriment United KingdomRetaliation against whistleblowers €82,264

The PR agency, which did not appear, lost on all claims: detriment on grounds of whistleblowing (£20,000 for injury to feelings), wrongful termination without notice pay (£3,547.60) and constructive unfair dismissal (basic and compensatory award including a 25 % ACAS uplift). A total of £71,051.82 was awarded.

What organisations can take from it

Employers who do not take part in the proceedings risk, in addition to whistleblower compensation, an uplift for failing to follow the ACAS Code of Practice.

Relevance to training and awareness

How managers handle internal reports

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, s. 47B (Benachteiligung wegen geschützter Offenlegung); konstruktive unfaire Kündigung; wrongful dismissal
Action
Other
Status of proceedings
unknown
Sector
Other
Published
22 Jul 2026

Original amount 71,051.82 GBP, converted at the ECB reference rate of 3 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jun 2026 Ascension Health Alliance; AmSurg LLC / Ambulatory Topco LLCAscension/AmSurg: seven ambulatory surgery centres must be sold USAMerger control Order

The non-profit hospital group Ascension wanted to acquire AmSurg for 3.9 billion USD. Owing to overlaps in outpatient surgery in five regions, the Federal Trade Commission (FTC) requires the sale of seven AmSurg centres to SC Affiliates and a gastroenterology practice, as well as transitional support.

What organisations can take from it

Non-profit healthcare providers are also subject to merger control – regional market shares determine divestitures.

Authority / court
Federal Trade Commission (FTC)
Area of law
Competition law · Merger control
Legal basis
Section 7 Clayton Act; Section 5 FTC Act (Consent Order)
Action
Order
Status of proceedings
unknown
Sector
Healthcare
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Jun 2026 FTI Consulting, Inc.OFAC: USD 1.05 million settlement with FTI Consulting over prohibited extension of credit to a Russian state-owned bank USABreaches of sanctions and embargoes €901,597

Consulting firm FTI Consulting, Inc. of Washington, D.C. is paying USD 1,050,000 under a settlement with OFAC for apparent violations of the Russia financial sector sanctions. According to OFAC's findings, between April 2019 and May 2021 FTI indirectly extended prohibited debt on six occasions to a Russian state-owned bank subject to Directive 1 under Executive Order 13662: invoices remained unpaid beyond the permitted 14 days or were paid long afterwards while FTI continued to provide services. OFAC treated the apparent violations as non-egregious and not voluntarily self-disclosed; the base penalty was USD 525,000. The settlement amount is above the base penalty; OFAC cited in particular the anticipated impact on future compliance by similarly situated firms. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "FTI Consulting, Inc., a Global Business Advisory Firm, Settles with OFAC for $1,050,000 Related to Apparent Violations of Dealing in Prohibited Debt of Sanctioned Russian Bank", 1 June 2026, https://ofac.treasury.gov/media/935651/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Ukraine-/Russia-Related Sanctions Regulations, 31 C.F.R. §§ 589.202, 589.213 i. V. m. Directive 1 zu E.O. 13662 (sechs mutmaßliche Verstöße); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Other
Published
1 Jun 2026

Original amount 1,050,000 USD, converted at the ECB reference rate of 1 Jun 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 May 2026 Atlantic Lottery Corporation Inc.FINTRAC: CAD 212,025 penalty on Atlantic Lottery Corporation Inc. for 3 violations of anti-money laundering obligations CanadaSuspicious activity reports €131,906

According to FINTRAC, Atlantic Lottery Corporation Inc. is a reporting entity in the casino sector based in Moncton, New Brunswick. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 212,025 on the company on 29 May 2026. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, written compliance policies and procedures and assessing and documenting money laundering and terrorist financing risks. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Atlantic Lottery Corporation Inc.", published 9 July 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-07-09-1-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Other
Published
9 Jul 2026

Original amount 212,025 CAD, converted at the ECB reference rate of 29 May 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products EU levelPlatform obligations €200m

Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.

What organisations can take from it

Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
28 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 May 2026 Thermotech Wall and Loft Surveys LtdICO: £240,000 fine for Thermotech over marketing calls to TPS numbers United KingdomMarketing and consent €276,928

The ICO fined Thermotech Wall and Loft Surveys Ltd £240,000 and issued an enforcement notice. After executing a search warrant in April 2025, the regulator found that between October 2024 and March 2025 the company had instigated 575,062 unsolicited marketing calls to numbers that had been on the TPS register for more than 28 days. There were 132 complaints. The legal basis is regulations 21 and 24 of PECR.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 21 und 24 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate

Original amount 240,000 GBP, converted at the ECB reference rate of 28 May 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2026 Soltec Power Holdings, SASoltec: incorrect 2023 annual figures reported to the market SpainDisclosure and reporting obligations €190,000

The manufacturer of solar tracking systems disseminated its results for 2023 by way of an "Otra Información Relevante" announcement containing inaccurate information. Spain's National Securities Market Commission (CNMV) imposed a fine of 190,000 EUR for a serious infringement; the company waived administrative appeals.

What organisations can take from it

Voluntary market announcements on results are also subject to MAR – figures must be reconciled before publication.

Authority / court
Comisión Nacional del Mercado de Valores (CNMV)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 297.1.e i. V. m. 297.2.d Ley 6/2023; Art. 17 i. V. m. Art. 7 MAR
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Sabre Global Technologies LimitedSabre subsidiary accepted payments from designated Ural Airlines United KingdomBreaches of sanctions and embargoes €1.16m

The provider of a travel booking system continued to provide services to Ural Airlines, designated in May 2022, requested payments of around 906,600 USD and, after the funds were frozen by the bank, looked for alternative payment routes, which HM Treasury's Office of Financial Sanctions Implementation (OFSI) regarded as circumvention. A lack of escalation during a change of roles, vacant leadership positions in legal and compliance, policies focused on US law and screening that did not flag the designation all contributed.

What organisations can take from it

If an existing customer is designated, escalate this immediately; looking for alternative payment routes after the bank has frozen funds is itself a breach.

Relevance to training and awareness

Responding to new designations of existing customers, prohibition of circumvention

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, regs. 13, 14, 19
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Voluntary disclosure (31 October 2022) and full cooperation; settlement under the new settlement procedure
Published
17 Jun 2026

Original amount 1,000,920.59 GBP, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters HungaryData protection €140,706

On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.

What organisations can take from it

Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.

Relevance to training and awareness

Handling leaked personal data in newsrooms

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection
Legal basis
DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
intentional
Published
26 May 2026

Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients CyprusOrganisational requirements €100,000

For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.

What organisations can take from it

When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.

Relevance to training and awareness

Appropriateness assessment when selling complex products

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Aug 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2026 Streamline Shipping Agencies LimitedAberdeen port agency: £146,700 after forklift accident without traffic separation United KingdomWorkplace safety and accidents €169,756

At the Port of Aberdeen, an employee loosening a lorry curtain was struck by a reversing forklift truck and suffered multiple fractures and a degloving injury. Pedestrians and vehicles were not separated during simultaneous loading and unloading. Fine of £146,700.

What organisations can take from it

Loading and manoeuvring areas need firm rules on who may be where and when if forklifts and pedestrians are working at the same time.

Authority / court
Aberdeen Sheriff Court (Ermittlung: Health and Safety Executive)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Regulation 17(1) Workplace (Health, Safety and Welfare) Regulations 1992; Section 33(1)(c) Health and Safety at Work etc. Act 1974
Action
Fine
Status of proceedings
final
Sector
Transport, logistics and shipping
Published
28 May 2026

Original amount 146,700 GBP, converted at the ECB reference rate of 22 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2026 Foot Locker, Inc.SEC: Foot Locker pays 148,000 US dollars over award waivers in separation agreements USARetaliation against whistleblowers €127,641

From July 2020 to June 2024, around 148 departing employees – including managers and staff from finance, legal and supply chain – signed separation agreements containing a waiver of SEC whistleblower awards. Foot Locker had itself phased out the clause from March 2024 but had not amended all templates; the U.S. Securities and Exchange Commission (SEC) imposed 148,000 US dollars.

What organisations can take from it

When cleaning up clauses, all contract templates must be covered – a single forgotten template is enough for a violation.

Relevance to training and awareness

Whistleblower protection in contract templates (HR/Legal)

Authority / court
U.S. Securities and Exchange Commission
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Securities Exchange Act of 1934, Rule 21F-17(a)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Clause phased out before contact by the SEC; cooperation and prompt remediation
Published
22 May 2026

Original amount 148,000 USD, converted at the ECB reference rate of 22 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2026 Parrish & Heimbecker, Limited; GrainsConnect Canada Operations Inc.Canada: grain elevator must be sold in the takeover of GrainsConnect CanadaMerger control Order

The planned acquisition of GrainsConnect by Parrish & Heimbecker would have reduced competition for the purchase of wheat from farmers around Reford (Saskatchewan). The Competition Bureau reached an agreement under which P&H must divest the grain elevator in Reford to an approved buyer and continue to operate it normally until then.

What organisations can take from it

Merger control also has local effects: even a single site can trigger a divestiture requirement.

Authority / court
Competition Bureau Canada (Consent Agreement beim Competition Tribunal)
Area of law
Competition law · Merger control
Legal basis
Competition Act (Kanada), Fusionskontrolle
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Published
22 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 May 2026 Marketing-Unternehmen, UK (anonymisiert)ICO: £300,000 fine for a marketing firm over spam and fake bailiff texts United KingdomMarketing and consent €346,600

The ICO fined a UK marketing company £300,000 and issued an enforcement notice. The ICO found that the company had sent more than 5.5 million unsolicited marketing text messages, including messages styled as if they came from bailiffs. The 7726 spam reporting service received over 60,000 complaints. The ICO relied on regulations 22 and 23 of PECR (electronic marketing without consent and concealed sender identity).

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 22 und 23 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 300,000 GBP, converted at the ECB reference rate of 20 May 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 May 2026 Jusan Technologies LtdTribunal: Jusan Technologies and CEO liable for withheld 600,000 US dollars United KingdomRetaliation against whistleblowers Other

In August 2023, an employee had raised concerns about a possible diversion of funds earmarked for charitable purposes for self-enrichment and about breaches of duty by the CEO. The London South Employment Tribunal found that the company and its CEO personally had withheld from him, for that reason, a payment of 600,000 US dollars owed at the end of his contract (s. 47B (1) and (1A)); compensation will be determined separately.

What organisations can take from it

In the United Kingdom, managers are personally liable if they subject whistleblowers to detriment – for example by withholding contractual payments.

Relevance to training and awareness

How managers handle internal reports

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, ss. 43B, 43C, 43G, 47B(1) und (1A)
Action
Other
Status of proceedings
unknown
Liability of senior managers
The CEO (referred to in the judgment as the ‘controlling mind’) is personally liable under s. 47B(1A) ERA 1996 (Employment Rights Act 1996).
Published
10 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 May 2026 Adani Enterprises LimitedAdani Enterprises pays 275 million USD over Iranian liquefied petroleum gas USABreaches of sanctions and embargoes €236.1m

From November 2023 to June 2025, the Indian conglomerate bought allegedly Omani and Iraqi liquefied petroleum gas (LPG) via a trader in Dubai which in fact originated from Iran; 32 payments totalling around 192 million USD were routed through US banks. The US Treasury's Office of Foreign Assets Control (OFAC) assessed the violations as egregious and not voluntarily self-disclosed; Adani had recklessly ignored numerous warning signs (AIS manipulation by the tankers, implausible loading ports, conspicuous price discounts, irregularities in the certificates of origin).

What organisations can take from it

Companies that source commodities below market price via intermediaries must actively check origin, vessel movements and documents – mere name screening against sanctions lists is not enough.

Relevance to training and awareness

Warning signs in commodity and shipping transactions (origin, AIS gaps, price discounts)

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations (31 C.F.R. part 560); IEEPA
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Mitigating circumstances
Remedial measures after discovery and cooperation with OFAC
Published
18 May 2026

Original amount 275,000,000 USD, converted at the ECB reference rate of 18 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 May 2026 Volvo Group North America, LLCVolvo Group North America: settlement of around 197 million USD over undisclosed emission control devices USA, CAEmissions and permits €168.7m

Around 10,000 heavy-duty Volvo diesel engines from model years 2010 to 2016 used auxiliary emission control devices (AECDs) that were not disclosed during certification and emitted more NOx than permitted. The settlement with the California Air Resources Board (CARB) comprises 17.5 million USD in penalties and costs, 71 million USD for mitigation measures and 108 million USD for emission reduction projects in California.

What organisations can take from it

Every emissions-relevant control function must be fully disclosed in the certification application; otherwise high settlement payments may follow years later.

Authority / court
California Air Resources Board (CARB)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Kalifornische Emissions- und Zertifizierungsvorschriften für schwere Nutzfahrzeugmotoren
Action
Fine
Status of proceedings
final
Sector
Automotive
Employees
10,000 or more
Mitigating circumstances
Cooperation during the investigation; recall and extended warranty for engines from model years 2014 to 2016.
Published
18 May 2026

Original amount 196,500,000 USD, converted at the ECB reference rate of 18 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 May 2026 ArcelorMittal Exploitation Minière Canada s.e.n.c.ArcelorMittal mining subsidiary in Québec: 100 million CAD fine for acidic mine effluent Canada, QCWaste and hazardous substances €62.5m

From May 2014 to May 2022, acidic effluent, effluent with elevated zinc, nickel or suspended solids content, and effluent that was acutely lethal to fish entered fish-bearing waters from the Mont-Wright mining complex and the Fire Lake mine in the Fermont region. The company pleaded guilty to 100 counts; the fine of 100 million CAD goes almost entirely to the Environmental Damages Fund, and an action plan on wastewater management must also be submitted by mid-February 2027.

What organisations can take from it

Long-standing exceedances of limit values add up to hundreds of individual offences; effluent monitoring must lead to immediate corrective action.

Authority / court
Court of Québec (Ermittlungen: Environment and Climate Change Canada)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Fisheries Act, Subsection 36(3)
Action
Fine
Status of proceedings
unknown
Sector
Steel and metals
Published
15 May 2026

Original amount 100,000,000 CAD, converted at the ECB reference rate of 15 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Takeda Pharmaceuticals U.S.A., Inc.Takeda: 13.7 million USD – speaker fees and luxury meals for prescribing physicians USAGifts, hospitality and benefits €11.7m

From 2014 to 2020, Takeda allegedly selected physicians specifically for its speaker programme for the antidepressant Trintellix and provided them with fees and meals at expensive restaurants to promote prescriptions; some participants attended the same event several times without any educational benefit. Takeda paid 13,670,921 USD.

What organisations can take from it

Speaker programmes need a demonstrable educational purpose – repeated attendance and expensive hospitality turn them into inducements.

Relevance to training and awareness

Invitations, hospitality and fees for healthcare professionals

Authority / court
U.S. Department of Justice / U.S. Attorney's Office, Eastern District of California
Area of law
Bribery and corruption · Gifts, hospitality and benefits
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more

Original amount 13,670,921 USD, converted at the ECB reference rate of 14 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff ItalyData breaches and data security €1.72m

Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.

What organisations can take from it

Staff in branches and partner shops must verify alleged support calls before granting access.

Relevance to training and awareness

Social engineering / fake IT support

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO (Integrität und Vertraulichkeit, Art. 32)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists FinlandMarket abuse and insider dealing €400,000

The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.

What organisations can take from it

Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.

Relevance to training and awareness

Insider lists and handling of inside information

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
Published
15 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency BelgiumData subject rights and transparency €86,000

The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.

What organisations can take from it

Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.

Relevance to training and awareness

Recording of customer calls

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Transport Desgagnés Inc.Transport Desgagnés: 40,000 CAD because a tanker entered an Arctic protected area without a permit Canada, NUEnvironment and sustainability €24,902

The tanker M/T Sarah Desgagnés, operated by the company, entered the Akpait National Wildlife Area in Nunavut on 29 September and 6 October 2024 without the required access permit. The Nunavut Court of Justice imposed 40,000 CAD for the Environmental Damages Fund; the company must publish a notice in a local newspaper and is listed in the Environmental Offenders Registry.

What organisations can take from it

Protected area boundaries belong in every vessel's voyage planning; missing access permits are prosecuted even in remote areas.

Relevance to training and awareness

Protected areas in voyage planning and bridge practice

Authority / court
Nunavut Court of Justice (Ermittlungen: Environment and Climate Change Canada)
Area of law
Environment and sustainability
Legal basis
Wildlife Area Regulations (Canada Wildlife Act), Paragraph 3.3(1)(h)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
8 May 2026

Original amount 40,000 CAD, converted at the ECB reference rate of 8 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2026 South Staffordshire Plc und South Staffordshire Water PlcICO: almost £1 million against water supplier South Staffordshire after cyber attack United KingdomData breaches and data security €1.12m

In 2020, malware entered the water supplier's network via a phishing e-mail and remained undetected for around 20 months; in 2022, attackers obtained administrator rights and stole data on 633,887 people, which ended up on the dark web. The UK Information Commissioner's Office (ICO) criticised, among other things, monitoring of only 5% of the IT environment, outdated software such as Windows Server 2003 and a lack of vulnerability and patch management.

What organisations can take from it

Utilities in critical infrastructure must also monitor their entire IT estate and replace legacy systems – an attack must not only come to light through performance problems.

Relevance to training and awareness

Recognising phishing

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
40% reduction for early admission of liability; payment agreed without appeal.
Published
11 May 2026

Original amount 963,900 GBP, converted at the ECB reference rate of 7 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2026 Duncan Farms LimitedDuncan Farms: 53,000 GBP because a worker was caught in an unguarded conveyor United KingdomWorkplace safety and accidents €61,335

In October 2024, an employee of the egg producer climbed between two running manure conveyors to check a noise and was caught at the in-running nip; he suffered nerve damage to both arms. The drive had no fixed or interlocked guards – instruction and clothing rules alone were not sufficient. The Health and Safety Executive (HSE) prosecution resulted in a fine of 53,000 GBP.

What organisations can take from it

Instruction is no substitute for technical safeguards: in-running nips must be protected by fixed or interlocked guards.

Relevance to training and awareness

Stopping machinery before intervening

Authority / court
Health and Safety Executive (Aberdeen Sheriff Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Provision and Use of Work Equipment Regulations 1998, reg. 11(1) und (2); Health and Safety at Work etc. Act 1974, s. 33(1)(c)
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Published
13 May 2026

Original amount 53,000 GBP, converted at the ECB reference rate of 7 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers CanadaData breaches and data security Other

Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.

What organisations can take from it

Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act (Kanada)
Action
Other
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
7 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 May 2026 HP TRONIC Zlín, spol. s r.o.HP TRONIC Zlín: 39 million CZK for price requirements imposed on electronics retailers CzechiaCartels and collusion €1.6m

For more than ten years from 2012, the distributor and retailer of consumer electronics and household appliances set minimum resale prices for its retail customers, monitored them and sanctioned deviations. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 38.971 million CZK; a leniency application, settlement and an improved compliance programme reduced the fine, and the company appealed against the amount.

What organisations can take from it

Reprimanding retailers over low prices risks high fines – an effective compliance programme can reduce them but is no substitute for ending the practice.

Relevance to training and awareness

Resale price maintenance in sales

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0551/2023)
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Leniency application, settlement and expansion of the internal compliance programme.
Published
6 May 2026

Original amount 38,971,000 CZK, converted at the ECB reference rate of 6 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary BelgiumOrganisational requirements €150,000

One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.

What organisations can take from it

Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.

Relevance to training and awareness

Care in master data maintenance / register reconciliation

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 4 avril 2014 relative aux assurances, Art. 259
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
IT adjustments to prevent recurrence.
Published
5 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection MaltaMarketing and consent €1,000

Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.

What organisations can take from it

An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.

Relevance to training and awareness

Passing marketing objections on to service providers (suppression lists)

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late GermanyData processors Reprimand or warning

A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.

What organisations can take from it

Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.

Relevance to training and awareness

Reporting process for data breaches and management of service providers

Authority / court
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Mitigating circumstances
BVG has announced measures against similar incidents.
Published
4 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2026 Ultra Electronics Holdings Limited (vormals plc)Ultra Electronics: DPA of around 10.1 million GBP over bribery in Algeria and Oman United KingdomBribery of public officials €11.6m

The British defence supplier failed to prevent bribery by agents in connection with three public contracts in Oman and Algeria (including a contract with the Omani Ministry of Transport worth up to 200 million GBP). The DPA approved by Southwark Crown Court provides for a penalty of 10,083,150 GBP; in addition, the company is bearing around 4.8 million GBP of the SFO's investigation costs and must report on its compliance programme for three years.

What organisations can take from it

Companies that use agents for government contracts must be able to demonstrate adequate procedures – otherwise the company is liable under Section 7 Bribery Act even without any intent to bribe on its own part.

Relevance to training and awareness

Use of sales agents in public contracts

Authority / court
Serious Fraud Office (SFO)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Section 7 Bribery Act 2010 (Failure to prevent bribery); Deferred Prosecution Agreement
Action
Fine
Status of proceedings
final
Sector
Defence and security
Culpability
intentional
Mitigating circumstances
Self-report of the Algerian matters in 2018; restructuring of ownership and leadership; 45 % discount on the penalty.
Published
1 May 2026

Original amount 10,083,150 GBP, converted at the ECB reference rate of 30 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2026 Modern Nuclear Inc.Modern Nuclear: 8.33 million USD – excessive supervision fees paid to referring cardiologists USACommercial bribery €7.12m

The Californian provider of mobile PET scans allegedly paid referring cardiologists excessive fees for supervising the examinations in order to secure referrals. The settlement of 8,334,350.71 USD plus revenue-based payments is based on ability to pay; in addition, there is a Corporate Integrity Agreement.

What organisations can take from it

Remuneration of business partners who refer work must correspond to the market value of the service – any overpayment acts as a bribe.

Relevance to training and awareness

Checking fee agreements with referrers for market conformity

Authority / court
U.S. Department of Justice / U.S. Attorney's Office, Central District of California
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Healthcare

Original amount 8,334,350.71 USD, converted at the ECB reference rate of 30 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Apr 2026 Deutsche Bank AG London BranchOFSI: GBP 165,000 settlement penalty for Deutsche Bank AG London Branch over payments to an app developer United KingdomBreaches of sanctions and embargoes €190,476

On 30 April 2026 OFSI imposed a monetary penalty of GBP 165,000 on the London branch of Deutsche Bank AG by way of settlement. According to OFSI's findings, in June and July 2022 the branch processed two payments totalling GBP 635,618.75 for a customer to a Russian app developer owned by a designated entity. According to OFSI, its screening provider's list did not contain ownership information on the designated entity, so the beneficiary was not identified. The bank had voluntarily disclosed the payments on 20 September 2022. After a notice of intent of 12 September 2025, which OFSI upheld on 2 December 2025, the bank requested a ministerial review on 23 January 2026; the proceedings ended in settlement. The publication does not state the amount originally proposed. Source: Office of Financial Sanctions Implementation (OFSI), HM Treasury, "Imposition of Monetary Penalty – Deutsche Bank AG London Branch (“DBLB”)", 19 May 2026, https://www.gov.uk/government/publications/imposition-of-monetary-penalty-deutsche-bank-ag-london-branch-dblb. Contains public sector information licensed under the Open Government Licence v3.0 (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/).

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, reg. 12; Geldbuße nach s. 146 Policing and Crime Act 2017
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
19 May 2026

Original amount 165,000 GBP, converted at the ECB reference rate of 30 Apr 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Apr 2026 „Вазовски машиностроителни заводи“ ЕАД (VMZ)Arms manufacturer VMZ used a partner’s know-how for disposable grenade launchers – 50,855 EUR BulgariaCompetition law €50,855

On application by the client Armar, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that VMZ had used technical documentation on disposable grenade launchers that had been provided in confidence (trade secret) contrary to the confidentiality agreements and good commercial practice (Art. 37(1) ZZK – Bulgarian Protection of Competition Act). Sanction of 50,855.09 EUR and obligation to cease, with immediate enforceability. Appeals have been lodged against the decision.

What organisations can take from it

Design documents provided in confidence may only be used within the agreed scope – especially in sensitive industries.

Relevance to training and awareness

Handling confidential know-how of business partners

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 37 Abs. 1 ZZK (Geschäftsgeheimnisse)
Action
Fine
Status of proceedings
under appeal
Sector
Defence and security

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification USA, NYSecurity measures and risk management €1.92m

In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.

What organisations can take from it

Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent
Published
30 Apr 2026

Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Apr 2026 Purdue Pharma L.P.Purdue Pharma: 5.544 billion USD penalty – including kickbacks via the speaker programme USAGifts, hospitality and benefits €4.75bn

Following its 2020 guilty plea, the opioid manufacturer was sentenced in Newark to a criminal fine of 3.544 billion USD (asserted in the insolvency proceedings) and forfeiture of 2 billion USD; up to 1.775 billion USD can be credited against the forfeiture if Purdue emerges from insolvency as a public benefit company. Purdue had deceived the DEA and paid kickbacks to prescribers via its speaker programme and to an electronic health records platform in order to increase opioid prescriptions.

What organisations can take from it

Fee programmes for customers who drive revenue can become part of a criminal overall scheme – with consequences that threaten the company’s existence.

Relevance to training and awareness

Speaker fees and benefits for prescribing physicians

Authority / court
U.S. District Court, District of New Jersey (Anklage: U.S. Department of Justice)
Area of law
Bribery and corruption · Gifts, hospitality and benefits
Legal basis
Verschwörung zum Betrug der USA und zur Verletzung des Food, Drug, and Cosmetic Act; zwei Fälle Verschwörung zur Verletzung des Anti-Kickback Statute (Schuldbekenntnis vom 24.11.2020)
Action
Fine
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Culpability
intentional

Original amount 5,544,000,000 USD, converted at the ECB reference rate of 28 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Apr 2026 Amica Chips S.p.A., Pata S.p.A., Preziosi Food S.p.A.Italy: 23.3 million EUR against Amica Chips, Pata and Preziosi Food over snack cartel ItalyCartels and collusion €23.3m

In a secret, continuing agreement, three manufacturers of salty snacks and crisps divided up among themselves the supply of private-label snacks to food retailers. Fines: Amica Chips 8,239,210 EUR, Pata 7,555,387 EUR, Preziosi Food 7,503,550 EUR; this was the first time Italy's competition authority (Autorità Garante della Concorrenza e del Mercato, AGCM) applied its settlement procedure.

What organisations can take from it

Retailers' tenders for private labels are competition – coordinated sham bids to retailers constitute a cartel.

Relevance to training and awareness

Sham bids in retailers' private-label tenders

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV; Art. 14-quater Gesetz 287/1990 (Settlement)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Leniency reduction for Pata and Amica Chips; 10 % settlement discount for all
Published
28 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2026 12066424 Canada Inc.Temporary staffing agency and director: CA$150,000 over unpaid wages Canada, ONMinimum wage and undeclared work €93,832

Following complaints, the labour inspectorate found, among other things, outstanding minimum wages at the temporary staffing agency in Leamington; an audit for 2022 showed that hundreds of employees were owed a total of CA$234,212 in regular wages, public holiday pay and vacation pay. The company and its director did not comply with the 2023 orders to pay; in proceedings held in their absence, the court imposed CA$100,000 on the company and CA$50,000 on the director (plus victim fine surcharge).

What organisations can take from it

Companies that ignore regulatory orders to pay outstanding wages risk not only a corporate fine but also personal liability for management.

Authority / court
Provincial Offences Court Windsor (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Employment Standards Act, 2000 (Ontario), ss. 103(8), 106, 132, 136
Action
Fine
Status of proceedings
unknown
Sector
Other
Liability of senior managers
Director Son-Van Duong personally fined CA$50,000.
Published
3 Jun 2026

Original amount 150,000 CAD, converted at the ECB reference rate of 23 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Apr 2026 Industrial Chemicals LimitedIndustrial Chemicals: 3.8 million GBP after caustic soda burns – one leg amputated United KingdomWorkplace safety and accidents €4.37m

In 2019, an employee stepped into a puddle of caustic soda; his safety boots offered no protection, and his leg had to be amputated below the knee. In 2022, another worker suffered chemical burns during manual decanting. The Health and Safety Executive (HSE) found leaking pipes and valves, a lack of maintenance, no risk assessment for decanting and untested safety footwear; fine of 3.8 million GBP plus 124,748 GBP in costs.

What organisations can take from it

Leaks of hazardous substances are not a normal state of affairs – maintenance, spill management and tested protective equipment go hand in hand.

Relevance to training and awareness

Handling corrosive hazardous substances and PPE

Authority / court
Health and Safety Executive (Southwark Crown Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Control of Substances Hazardous to Health Regulations 2002, reg. 7(1)
Action
Fine
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Published
24 Apr 2026

Original amount 3,800,000 GBP, converted at the ECB reference rate of 21 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Apr 2026 Unternehmen (Anrufe zur Schadensregulierung), UK (anonymisiert)ICO: enforcement notice against a UK company over claims management calls without consent United KingdomMarketing and consent Order

The ICO issued an enforcement notice to a UK company. The ICO found that the company had instigated calls about claims management services without the consent of the people called. Under regulation 21A of PECR such calls are only permitted with prior consent; the ICO also found a breach of regulation 24. The notice is an enforcement notice and does not impose a fine.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 21A und 24 PECR; section 40 DPA 1998
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Apr 2026 Sapia Partners LLPFCA: Public censure for Sapia Partners over lack of segregation for client money United KingdomOrganisational requirements Reprimand or warning

The FCA publicly censured Sapia Partners LLP. Sapia was responsible for client money accounts operated in connection with its appointed representative, a wealth manager, but the FCA found that from 2014 to 2020 it did not ensure effective segregation between those making payments and those reconciling the accounts. About £150 million was deposited into the accounts in that period, exposing clients to a risk of loss. Sapia agreed to a voluntary payment of £19,637,950 to that representative's clients; for this reason the FCA did not impose a fine, which it said would otherwise have been £7,412,000 (after discount).

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
FCA Principle 10; CASS 7.12.2R bzw. CASS 7.3.2R; section 205 FSMA 2000
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratóriíLaboratory cartel: 14.6 million EUR and procurement bans against diagnostic laboratories SlovakiaCartels and collusion €14.6m

Four laboratories and their association coordinated negotiations on prices with health insurers, coordinated in tenders, exchanged sensitive information and allocated customers. At first instance, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 14,551,800 EUR and three-year procurement bans; Unilabs received a substantially reduced fine as leniency applicant and under a settlement.

What organisations can take from it

Common negotiating positions towards payers via an association are a cartel – association meetings need minutes and a review of the agenda.

Relevance to training and awareness

Information exchange among competitors and association work

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Unilabs: leniency reduction (50%) and settlement (a further 30%).
Published
12 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Cream della Cream Switzerland GmbH und Philipp Plein International AGFDPIC ruling: Philipp Plein and Cream della Cream ignored objections to advertising SwitzerlandMarketing and consent Order

Both companies continued to use e-mail addresses and telephone numbers from online purchases for advertising, although data subjects had objected – in some cases after deletion had been confirmed. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) ordered the processing for advertising to cease and the data to be deleted on request.

What organisations can take from it

An objection to advertising must take effect across all systems – a confirmed deletion followed by further advertising violates the principle of good faith.

Relevance to training and awareness

Handling objections to advertising and deletion requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Marketing and consent
Legal basis
DSG Art. 6, Art. 30 Abs. 2 lit. b, Art. 31
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Synadis Bio, Greenweez (mit Carrefour SA), ITM Entreprises (mit Les Mousquetaires), Les Comptoirs de la BioFrance: 12.67 million EUR over allocation of distribution channels for organic food FranceCartels and collusion €12.7m

Through the association Synadis Bio, market participants ensured for more than seven years that organic brands were not sold simultaneously in specialist organic shops and in conventional supermarkets, in order to prevent price comparisons (decision 26-D-05). Fines: Synadis Bio 10 million EUR, Greenweez/Carrefour 1.85 million EUR, ITM 740,000 EUR, Les Comptoirs de la Bio 80,000 EUR.

What organisations can take from it

Association decisions that tie members to particular distribution channels amount to market sharing – even if they are justified as a quality or positioning policy.

Relevance to training and awareness

Association rules to foreclose distribution channels

Authority / court
Autorité de la concurrence
Area of law
Competition law · Cartels and collusion
Legal basis
Art. L.420-1 Code de commerce, Art. 101 Abs. 1 AEUV; Bußgeldbemessung nach Art. L.464-2 Code de commerce
Action
Fine
Status of proceedings
under appeal
Sector
Food and agriculture
Published
16 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment EstoniaData processors Order

The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.

What organisations can take from it

Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.

Relevance to training and awareness

Consent and transparency for health data; cooperation with the supervisory authority

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data processors
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Automobile Association Developments Limited (AA Driving School, BSM Driving School)AA and BSM driving schools: 4.2 million GBP for drip pricing – CMA's first consumer fine United KingdomMisleading advertising and pricing €4.83m

For online bookings, the driving schools only showed a mandatory booking fee at checkout instead of in the initial price. Following an admission and settlement, the CMA imposed a penalty of 4.2 million GBP (40 % discount on 7 million GBP) and ordered refunds of more than 760,000 GBP to more than 80,000 customers.

What organisations can take from it

Mandatory fees must be included from the very first price – in the United Kingdom, the CMA has been able to impose fines for this itself since 2025.

Relevance to training and awareness

Price disclosures and mandatory fees at online checkout

Authority / court
Competition and Markets Authority (CMA)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Digital Markets, Competition and Consumers Act 2024
Action
Fine
Status of proceedings
final
Sector
Other
Mitigating circumstances
Admission and early settlement (40 % discount).
Published
15 Apr 2026

Original amount 4,200,000 GBP, converted at the ECB reference rate of 15 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Liquidnet Canada Inc.Liquidnet Canada: confidential order data passed on to unauthorised persons Canada, ONOrganisational requirements €369,572

The operator of alternative trading systems passed on confidential order and trading information from its fixed income and equity platforms to unauthorised employees, lacked adequate safeguards and was initially not forthcoming with the regulator. Sanctions: administrative penalty of 600,000 CAD, 75,000 CAD in costs, a reprimand and an external review.

What organisations can take from it

Technically restrict access rights to confidential client data and review them regularly – and make complete reports to the regulator.

Relevance to training and awareness

Need-to-know principle and protection of confidential trading data

Authority / court
Capital Markets Tribunal (Ontario) auf Antrag der Ontario Securities Commission
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
National Instrument 21-101, s. 5.10(1)-(3); Securities Act (Ontario) ss. 127(1), 127.1
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Cooperation, self-report, no prior record

Original amount 600,000 CAD, converted at the ECB reference rate of 15 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles SloveniaEmployee data €6,000

A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.

What organisations can take from it

GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.

Relevance to training and awareness

GPS tracking and employee data protection

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Liability of senior managers
Additional fine of 600 EUR on the responsible person.
Published
15 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years DenmarkData protection Fine

The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.

What organisations can take from it

‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware SloveniaEmployee data €71,474

An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.

What organisations can take from it

Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.

Relevance to training and awareness

Permissible monitoring of employees and IT use

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Liability of senior managers
Additional fine of 4,000 EUR on the responsible person.
Published
9 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified PolandIncident reporting obligations €1,135

Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.

What organisations can take from it

Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.

Relevance to training and awareness

Recognising misdirected mail as a data breach – including at service providers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Construction and real estate

Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia NetherlandsInternational data transfers €100m

Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.

What organisations can take from it

Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Mar 2026 Energy Prices Direct LimitedICO: £160,000 fine for Energy Prices Direct over calls without TPS screening United KingdomMarketing and consent €184,325

The ICO fined Energy Prices Direct Limited, an energy switching broker, £160,000. The ICO found that the company had obtained contact details from public sources and list providers and did not screen them against the TPS/CTPS registers before making marketing calls. The legal basis is regulations 21 and 24 of PECR. Under the notice, timely payment reduces the amount by 20% to £128,000.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 21 und 24 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Original amount 160,000 GBP, converted at the ECB reference rate of 30 Mar 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Mar 2026 13010431 Canada Inc. (Necosmart)FINTRAC: 693,742 CAD against crypto service provider Necosmart over missing suspicious transaction reports CanadaSuspicious activity reports €434,295

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 693,742.50 CAD on the Edmonton money services business, which also exchanges virtual currencies, for five violations: repeated failure to file suspicious transaction reports, lack of written compliance policies, insufficient enhanced measures for high-risk transactions, lack of a risk assessment and incomplete records of occupation and transactions for crypto exchanges.

What organisations can take from it

Small crypto exchange offices need the same basic framework as banks: risk analysis, policies, enhanced scrutiny and reporting.

Relevance to training and awareness

Recognising and reporting grounds for suspicion in crypto exchange

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
14 May 2026

Original amount 693,742.5 CAD, converted at the ECB reference rate of 27 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Mar 2026 Dinosaur Merchant Bank LimitedDinosaur Merchant Bank: 338,000 GBP – CFD trading without market abuse surveillance United KingdomOrganisational requirements €389,760

After a new order management system was introduced in June 2024, CFD transactions with an underlying value of around 3.05 billion USD were not captured by automated trade surveillance. The bank identified the error in October 2024 but only remedied it in May 2025; the Financial Conduct Authority (FCA) imposed 338,000 GBP after a 30% cooperation discount.

What organisations can take from it

With every system migration, check whether surveillance systems actually capture the new data flows.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 16 Abs. 2 UK MAR; SYSC 6.1.1R; FCA Principle 3
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Full cooperation (30% discount); CFD business discontinued in May 2025.

Original amount 338,000 GBP, converted at the ECB reference rate of 27 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR RomaniaData processors €125,083

In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).

What organisations can take from it

Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data processors
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
25 Mar 2026

Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions FinlandDisclosure and reporting obligations €70,000

Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.

What organisations can take from it

Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.

Relevance to training and awareness

Regulatory reporting

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Admission of the failures / cooperation.
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 3R Technology UK Ltd3R Technology UK: penalty for exporting contaminated plastic waste despite prohibition United KingdomWaste and hazardous substances €164,216

From 2022 to 2025, the company exported containers of supposedly clean plastic that was in fact contaminated with electronic waste such as cables and circuit boards; in some cases, the waste was hidden at the back of the container, and further containers were shipped despite prohibition notices from August 2024. The company and its director pleaded guilty to 16 counts: a fine of 80,000 GBP, 45,000 GBP in costs and a 2,000 GBP surcharge for the company; 120 hours of community service, 15,000 GBP in costs and a 114 GBP surcharge for the director.

What organisations can take from it

Incorrectly declared waste exports are detected during port inspections; those who ignore regulatory prohibitions also risk the personal conviction of management.

Relevance to training and awareness

Correct classification and declaration of waste for export

Authority / court
Preston Magistrates' Court (Anklage: Environment Agency)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Vorschriften zur grenzüberschreitenden Abfallverbringung (Notifizierung und Zustimmung); Verstoß gegen Untersagungsverfügungen
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Repeat case
yes
Mitigating circumstances
Guilty plea.
Liability of senior managers
Director Yulin Wang personally sentenced to 120 hours of community service, 15,000 GBP in costs and a 114 GBP surcharge.
Published
2 Apr 2026

Original amount 142,114 GBP, converted at the ECB reference rate of 24 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR LatviaData subject rights and transparency €1,500

A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.

What organisations can take from it

Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.

Relevance to training and awareness

Handling data subject requests and correspondence from authorities

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops MaltaCustomer due diligence €225,730

Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.

What organisations can take from it

Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.

Relevance to training and awareness

Recognising structured deposits below the checking threshold

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
16 Apr 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis HungaryData subject rights and transparency €1,274

A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.

What organisations can take from it

Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.

Relevance to training and awareness

Access to health data and access requests

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
20 Mar 2026

Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Colas Rail Asia Sdn Bhd (Colas-Gruppe)Colas Rail Asia: CJIP of 29.7 million EUR over bribery in metro contracts in Malaysia FranceBribery of public officials €29.7m

The Malaysian subsidiary of Colas Rail paid large, undocumented sums via intermediaries in connection with public contracts for urban rail lines in Kuala Lumpur (Kelana Jaya extension, MRT2). Following an internal investigation, Colas Rail self-reported the matter in 2017; the CJIP (Convention judiciaire d'intérêt public, a French deferred prosecution agreement) provides for a public interest fine of 29,745,974 EUR and a three-year compliance programme monitored by the French Anti-Corruption Agency (AFA) (costs of up to 1.9 million EUR).

What organisations can take from it

Undocumented payments to intermediaries on foreign projects must be stopped early by the finance and compliance functions – self-reporting after an internal investigation is rewarded.

Relevance to training and awareness

Intermediaries and consultants in public tenders

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Employees
10,000 or more
Culpability
intentional
Mitigating circumstances
Self-report (criminal complaint filed by Colas Rail on 31 May 2017) following an internal forensic investigation.
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician FranceBribery of public officials €1.77m

In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.

What organisations can take from it

Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.

Relevance to training and awareness

Benefits to hospital physicians, integration of acquired companies

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
250 to 999
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Apple Distribution International LimitedOFSI: GBP 390,000 settlement penalty for Apple Distribution International over payments to an app developer United KingdomBreaches of sanctions and embargoes €451,452

On 19 March 2026 OFSI imposed a monetary penalty of GBP 390,000 on Ireland-based Apple Distribution International Limited by way of settlement. According to OFSI's findings, the company, which pays out revenues to software developers on an app marketplace, instructed two payments totalling GBP 635,618.75 in June and July 2022 from a UK bank account to a Russian app developer owned by a designated entity, and did not cancel the instructions. OFSI identified reliance on developers' self-declarations and on third-party data, among other things, as causes. The company had voluntarily disclosed the payments on 4 October 2022. The settlement followed a notice of intent of 11 November 2025 and was reached under the settlement process introduced in February 2026; OFSI made no findings against the parent company. Source: Office of Financial Sanctions Implementation (OFSI), HM Treasury, "Imposition of monetary penalty: Apple Distribution International Limited", 30 March 2026, https://www.gov.uk/government/publications/imposition-of-monetary-penalty-apple-distribution-international-limited. Contains public sector information licensed under the Open Government Licence v3.0 (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/).

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, reg. 12; Geldbuße nach s. 146 Policing and Crime Act 2017 (Settlement)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
30 Mar 2026

Original amount 390,000 GBP, converted at the ECB reference rate of 19 Mar 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Mar 2026 W International LLC; W International SC LLC; Precision Metal Equipment Handling LLCW International pays 10.5 million USD for overpriced welding tables for Air Force and Navy USAOther €9.11m

The metal fabrication companies and their CEO Edward Walker allegedly knowingly overcharged the Air Force and the Navy for welding tables for the modernisation of a large welding facility; the project was financed in part with funds under the Defense Production Act. The settlement under the False Claims Act amounts to 10.5 million USD; a former employee received 1,863,750 USD as a whistleblower.

What organisations can take from it

Price information provided to public contracting authorities must be calculated on a sound basis; internal whistleblowers regularly bring such cases to the authorities.

Authority / court
U.S. Department of Justice (Civil Division) / USAO District of South Carolina
Area of law
Other
Legal basis
False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Steel and metals
Liability of senior managers
CEO Edward Walker is personally a party to the settlement.
Published
17 Mar 2026

Original amount 10,500,000 USD, converted at the ECB reference rate of 17 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Mar 2026 Trustpilot Group Plc, Trustpilot A/S, Trustpilot S.r.l.Trustpilot: 4 million EUR fine for inadequate verification of the authenticity of reviews ItalyFake reviews €4m

According to the AGCM, the review platform did not adequately check whether reviews – including those labelled as "verified" – were genuine, and allowed companies to invite specifically selected customers to leave reviews via paid services, which undermined the representativeness of the star ratings. In addition, information on how the platform works and on paid services was lacking; the authority also saw dark pattern elements in this.

What organisations can take from it

Anyone who advertises with verified reviews must actually carry out the verification and disclose the selective collection of reviews.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Artt. 20, 21, 22 e 23, comma 1, lett. bb-ter Codice del Consumo
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
23 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Mar 2026 Balt SAS / Balt USA LLCMedical technology: DOJ declination for Balt SAS after bribery of a hospital physician USABribery of public officials €1.05m

Through sham consultancy agreements, fictitious invoices and purported bonus payments, around 602,000 USD in bribes flowed from 2017 to 2023 via a Belgian consultant to a physician in a senior position at a French public hospital, so that the hospital would purchase embolisation coils from Balt. The DOJ declined to prosecute on account of voluntary self-disclosure, cooperation and remediation (declination of 17 March 2026); Balt is disgorging 1,214,797 USD in profits.

What organisations can take from it

Physicians at public hospitals are public officials – consultancy agreements with them require documented services and approval by the compliance function.

Relevance to training and awareness

Benefits to physicians in the public healthcare sector, sham consultancy agreements

Authority / court
U.S. Department of Justice (Criminal Division, Fraud Section)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA; Corporate Enforcement and Voluntary Self-Disclosure Policy (Declination)
Action
Disgorgement of profits
Status of proceedings
final
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure (including to the French national financial prosecutor's office, PNF), full cooperation, timely remediation, disciplinary measures, parallel resolution in France.
Liability of senior managers
A former manager of the US subsidiary (David Ferrera) and a consultant (Marc Tilman) were charged with FCPA violations and money laundering.
Published
19 Mar 2026

Original amount 1,214,797 USD, converted at the ECB reference rate of 17 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Mar 2026 TradeStation Securities, Inc.OFAC: USD 1.11 million settlement with TradeStation over securities trading for customers in Iran, Syria and Crimea USABreaches of sanctions and embargoes €963,196

Online broker TradeStation Securities, Inc. of Florida is paying USD 1,110,661 under a settlement with OFAC for 481 apparent violations of multiple sanctions programmes. According to OFAC's findings, following several failures in compliance controls, customers in Iran, Syria and Crimea were able to execute 481 securities trades worth a total of USD 4,442,645 via the mobile app between June 2021 and June 2022. OFAC treated the apparent violations as non-egregious and voluntarily self-disclosed and credited significant remedial measures; the base penalty was USD 2,221,322. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "TradeStation Securities, Inc. Settles with OFAC for $1,110,661 Related to Apparent Violations of Multiple Sanctions Regulations", 17 March 2026, https://ofac.treasury.gov/media/935351/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204; Syrian Sanctions Regulations, 31 C.F.R. § 542.207; Ukraine-/Russia-Related Sanctions Regulations, 31 C.F.R. § 589.207 (481 mutmaßliche Verstöße); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Mar 2026

Original amount 1,110,661 USD, converted at the ECB reference rate of 17 Mar 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule PortugalCartels and collusion €4.52m

From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).

What organisations can take from it

An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.

Relevance to training and awareness

No-poach agreements in association rules

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
12 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Direktmarketing-Unternehmen, UK (anonymisiert)ICO: £130,000 fine for a direct marketing firm over calls to TPS numbers United KingdomMarketing and consent €150,737

In March 2026 the ICO fined a small UK direct marketing company £130,000 and also served an enforcement notice. According to the ICO, over almost eleven months in 2024 the company had staff make more than 230,000 marketing calls to lines that had been on the UK's opt-out register for sales calls (Telephone Preference Service, TPS) for over 28 days, prompting 12 complaints. The ICO treated this as a breach of regulation 21 of PECR.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 21 und 24 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 130,000 GBP, converted at the ECB reference rate of 12 Mar 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements LuxembourgMarketing and consent overturned

In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.

What organisations can take from it

Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.

Authority / court
Cour administrative (Luxemburg); Verfahren der CNPD
Area of law
Data protection · Marketing and consent
Legal basis
Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
Action
Order
Status of proceedings
overturned
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Amazon had implemented the compliance order before the hearing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Mar 2026 National Grid Electricity Transmission plcNational Grid (NGET): 20 million GBP after neglected Harker substation United KingdomOther €23.2m

Between 2016 and 2021, the transmission system operator did not adequately monitor, maintain and repair the civil structures of the 132 kV Harker substation near Carlisle – a hub for electricity exchange between Scotland and England – and thereby also delayed grid connections. NGET accepted the breaches and paid 20 million GBP into the Energy Industry Voluntary Redress Scheme.

What organisations can take from it

Operators of critical networks must systematically inspect even the inconspicuous civil structures of their installations – a maintenance backlog becomes a threat to supply.

Authority / court
Office of Gas and Electricity Markets (Ofgem)
Area of law
Other
Legal basis
Electricity Act 1989, s. 9(2); Standard Licence Condition B7 (Transmission Licence)
Action
Other
Status of proceedings
final
Sector
Energy and utilities

Original amount 20,000,000 GBP, converted at the ECB reference rate of 11 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Mar 2026 Birks Group Inc.FINTRAC: jeweller Birks sanctioned over missing risk assessment and compliance review CanadaInternal controls €32,755

The nationwide jewellery chain (a dealer in precious metals and stones) received a penalty of 51,562.50 CAD from the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) because written compliance policies were lacking or not applied, the money laundering risk was not assessed and documented, and the prescribed two-yearly effectiveness review was not carried out. Birks has appealed to the Federal Court.

What organisations can take from it

Jewellers, too, must maintain a documented compliance programme with a risk assessment and regular effectiveness reviews.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce
Published
5 May 2026

Original amount 51,562.5 CAD, converted at the ECB reference rate of 11 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2026 Canaccord Genuity LLCFinCEN: 80 million USD against Canaccord Genuity over AML and correspondent banking deficiencies USACustomer due diligence €69.2m

The US Financial Crimes Enforcement Network (FinCEN) imposed 80 million USD on the broker-dealer, which admitted wilful BSA infringements: no effective AML programme, no due diligence on correspondent accounts of foreign financial institutions and failure to file suspicious activity reports in connection with securities fraud. Remedial measures that had been promised were not implemented for years.

What organisations can take from it

Implement remedial measures promised in writing to the supervisory authority genuinely and swiftly – years of delay aggravate the later sanction.

Authority / court
Financial Crimes Enforcement Network (FinCEN)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Bank Secrecy Act (BSA)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Published
6 Mar 2026

Original amount 80,000,000 USD, converted at the ECB reference rate of 6 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2026 Fleurette Properties LtdCommodities holding Fleurette: 25.8 million EUR strafbeschikking over bribery in Congo NetherlandsBribery of public officials €25.8m

According to the Dutch Public Prosecution Service (OM), the top holding company of a mining, oil and gold group, which was based in the Netherlands from 2010 to 2017, participated together with others in bribing public officials of the DR Congo in order to obtain licences for cobalt and copper mines. On 6 March 2026, the OM issued a strafbeschikking (prosecutorial penalty order) imposing a fine of 25.8 million EUR, which Fleurette accepted.

What organisations can take from it

In the commodities sector, licences and concessions are the main target for bribery – holding companies share liability for payments made by their subsidiaries.

Relevance to training and awareness

Award of licences in the commodities sector, payments to public officials

Authority / court
Openbaar Ministerie (OM); Ermittlungen FIOD Anti-Corruptie Centrum
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Buitenlandse ambtelijke omkoping (Wetboek van Strafrecht); OM-strafbeschikking
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Culpability
intentional
Published
10 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2026 ΚΟΜΠΑ Μονοπρόσωπη Ε.Π.Ε. und HAPPY DOG Α.Ε. ΖωοτροφώνGreece: around 482,500 EUR against pet food importers for resale price maintenance GreeceCartels and collusion €482,498

Two importers of dog and cat food monitored their retailers’ consumer prices on price comparison portals and asked them to adjust them to their price lists; the retailers complied. In a settlement procedure (Decision 901/2026), the Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) imposed 387,498 EUR on KOMPA and 95,000 EUR on Happy Dog; the case began with a tip-off via the authority’s anonymous whistleblowing platform.

What organisations can take from it

Recommended prices must not be enforced through monitoring and calls to retailers – and authorities’ whistleblowing channels make such practices visible.

Relevance to training and awareness

Prohibition of resale price maintenance in sales

Authority / court
Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 1 Gesetz 3959/2011; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Settlement procedure with reduced fines
Published
6 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 Allin IP DX LLCAllin IP DX: 980,000 USD after self-disclosure over paid referral marketers USACommercial bribery €843,519

Between January and June 2023, the Sarasota laboratory paid independent marketers to steer laboratory samples from Medicare beneficiaries to it. It self-disclosed the conduct, cooperated extensively and paid 980,000 USD.

What organisations can take from it

Early self-disclosure limits the damage – but this requires the compliance function to actually get to see problematic sales contracts.

Relevance to training and awareness

Success-based remuneration of sales partners

Authority / court
U.S. Attorney's Office, Middle District of Florida
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
Voluntary self-disclosure, detailed disclosure and cooperation.

Original amount 980,000 USD, converted at the ECB reference rate of 5 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 SIA "SS"Classifieds portal ss.lv blocked users of competitor – fine of 186,781 EUR LatviaAbuse of market power €186,781

From March 2020 to May 2021, the operator of ss.lv/ss.com (market share over 60%) deleted advertisements and blocked accounts of users – mainly car dealers and estate agents – who also advertised on the competing platform pp.lv; anyone wishing to register with an inbox.lv address additionally had to provide a different e-mail address. The Konkurences padome (Latvian Competition Council) considered this an abuse of a dominant position (Art. 102 TFEU), imposed 186,780.65 EUR and required objective criteria for dealing with customers.

What organisations can take from it

Market-leading platforms must not punish users for multi-homing – internal moderation rules need objective criteria.

Relevance to training and awareness

Competition law limits in dealing with competitors’ customers

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
18 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 Loblaw Companies LimitedOPC: Loblaw must change retention of PC Optimum data after account deletion CanadaData subject rights and transparency Other

During a wave of boycotts in 2024, Loblaw did not process deletion requests in time and retained purchase and usage data from the loyalty programme (more than 17 million members) even after accounts were closed, without demonstrating effective anonymisation. Loblaw undertook to the Office of the Privacy Commissioner of Canada (OPC) to have the anonymisation independently reviewed and to carry out annual deletions.

What organisations can take from it

Companies that continue to use data as anonymous after account deletion must be able to demonstrate the re-identification risk – IP addresses are often enough to link data to a person.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
PIPEDA
Action
Other
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
5 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Mar 2026 Schaeffler AGSchaeffler: deviation of quarterly figures from market expectations disclosed too late GermanyDisclosure and reporting obligations €180,000

The automotive supplier's business figures for the first quarter of 2024 deviated significantly from market expectations; this inside information was not disclosed without delay by means of an ad hoc announcement. BaFin imposed a fine.

What organisations can take from it

Make a comparison of internal figures with the analyst consensus a fixed part of the quarterly process, so that significant deviations are immediately assessed for ad hoc disclosure obligations.

Relevance to training and awareness

Recognising inside information in deviations from market expectations (controlling/IR)

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR
Action
Fine
Status of proceedings
final
Sector
Automotive
Published
26 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Mar 2026 John Wood Group PLCJohn Wood Group: incorrect financial results published – almost 13 million GBP United KingdomDisclosure and reporting obligations €14.9m

The energy services company published incorrect results for the 2022 and 2023 financial years and for the first half of 2024; accounting judgements were influenced by the desire to maintain previously reported figures, and systems and controls were inadequate. The UK Financial Conduct Authority (FCA) imposed a fine of 12,993,700 GBP (18,562,500 GBP without the 30 % discount).

What organisations can take from it

Accounting judgements must not be geared to figures already communicated – this is a control failure, not a calculation error.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Listing Rule 1.3.3R; Listing Principle 1
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Employees
10,000 or more
Mitigating circumstances
30 % discount for early settlement and acceptance of the findings
Published
4 Mar 2026

Original amount 12,993,700 GBP, converted at the ECB reference rate of 3 Mar 2026.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register MaltaMoney laundering and terrorist financing €69,000

Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.

What organisations can take from it

Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The bank continuously attempted to upload reports
Published
6 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Northern Isga FoundationFINTRAC: CAD 91,162.50 penalty on Northern Isga Foundation for 4 violations of anti-money laundering obligations CanadaInternal controls €57,009

According to FINTRAC, Northern Isga Foundation is a non-profit charitable organisation based in Glenevis, Alberta, that receives a portion of a casino's revenues and is therefore a reporting entity. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 91,162.50 on the foundation on 2 March 2026. According to FINTRAC's findings, made during a compliance examination, the foundation committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme and the prescribed review of the compliance programme. According to FINTRAC, the foundation has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Northern Isga Foundation", published 26 March 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-03-26-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
26 Mar 2026

Original amount 91,162.5 CAD, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order DenmarkData subject rights and transparency €8,031

Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.

What organisations can take from it

Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.

Relevance to training and awareness

Handling access requests (Art. 15 GDPR)

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
Action
Fine
Status of proceedings
final
Sector
Other

Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy FinlandData subject rights and transparency €5,000

Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.

What organisations can take from it

Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.

Relevance to training and awareness

Right of access to call recordings

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15 Abs. 1 und 3
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Feb 2026 MBaer Merchant Bank AGFINMA withdraws MBaer Merchant Bank's licence over serious anti-money laundering deficiencies SwitzerlandInternal controls Order

Following enforcement proceedings, the Swiss Financial Market Supervisory Authority (FINMA) found serious, systematic deficiencies in anti-money laundering due diligence, organisation and risk management; the bank enabled clients to circumvent official asset freezes and executed transactions for sanctioned persons. FINMA had withdrawn the bank's licence and ordered its liquidation; with the withdrawal of the appeal before the Federal Administrative Court, the orders took effect on 27 February 2026. The day before, FinCEN had proposed designating the bank as an institution of primary money laundering concern.

What organisations can take from it

Systematic anti-money laundering and sanctions deficiencies can cost a bank its licence – not just money.

Authority / court
Eidgenössische Finanzmarktaufsicht (FINMA)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Schweizer Geldwäschereirecht und Bankenaufsichtsrecht (laut FINMA)
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Employees
50 to 249
Published
27 Feb 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Feb 2026 Teledyne FLIR LLCTeledyne FLIR: thermal imaging cameras incorrectly assessed and supplied to Entity List address USAExport control and dual-use goods €846,453

The manufacturer of militarily relevant thermal imaging technology admitted 19 violations to the US Commerce Department's Bureau of Industry and Security (BIS): incorrect de minimis calculations for cameras that went to China via Sweden, pricing arranged with a Chinese drone manufacturer to circumvent the licence requirement, missing records and eight deliveries in 2024 to a Hong Kong address on the Entity List that the screening software did not detect.

What organisations can take from it

Actively incorporate new forms of listing, such as address-only entries, into screening; do not rely solely on the software provider.

Relevance to training and awareness

De minimis calculation, address-based Entity List entries in screening

Authority / court
U.S. Department of Commerce, Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations, §§ 734.4 (De minimis), 744.16, 764.2(a), (b), (h), (i)
Action
Fine
Status of proceedings
final
Sector
Defence and security
Mitigating circumstances
Voluntary self-disclosures for some of the violations
Published
26 Feb 2026

Original amount 1,000,000 USD, converted at the ECB reference rate of 26 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Feb 2026 All FAB Precision Sheetmetal, Inc.Sheet metal fabricator: second amputation on the same press brake – Cal/OSHA $212,850 USA, CAWorkplace safety and accidents €180,168

In June 2025, an employee in San Jose lost a finger on a press brake without guarding – identical to an accident in June 2024 for which the business had already been fined $43,500. The California Division of Occupational Safety and Health (Cal/OSHA) imposed $212,850 (including a wilful repeat violation); the employer appealed.

What organisations can take from it

After an accident, retrofitting the machine is mandatory – an identical second accident will be treated as wilful.

Authority / court
California Division of Occupational Safety and Health (Cal/OSHA)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
California Code of Regulations, Title 8 (Maschinenschutz)
Action
Fine
Status of proceedings
under appeal
Sector
Steel and metals
Culpability
intentional
Repeat case
yes
Published
26 Feb 2026

Original amount 212,850 USD, converted at the ECB reference rate of 26 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Feb 2026 Reddit, Inc.ICO: £14.47 million fine for Reddit over processing children's data without age checks United KingdomData protection €16.6m

The ICO fined Reddit, Inc. £14,472,500. The regulator found that the platform did not use any robust age assurance and therefore had no lawful basis for processing the personal data of children under 13. The ICO also found that Reddit had not carried out a data protection impact assessment on the risks to children before January 2025. The ICO found infringements of Articles 5(1)(a), 6, 8 and 35 UK GDPR.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection
Legal basis
Art. 5(1)(a), 6, 8 und 35 UK GDPR; section 155 DPA 2018
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms

Original amount 14,472,500 GBP, converted at the ECB reference rate of 23 Feb 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Feb 2026 Yorkshire Water Services LimitedYorkshire Water: 733,333 GBP fine for repeated sewage discharges into park brook United KingdomEmissions and permits €839,630

Between October 2018 and August 2019, untreated sewage entered a brook in Pools Brook Country Park on three occasions – due to a burst rising main, a blockage caused by wet wipes and a failing pipe coupling; during the first incident, fish died in the park lake. Yorkshire Water had already pleaded guilty in January 2024 and had not attended any of the interviews; the court imposed a fine of 733,333 GBP plus costs.

What organisations can take from it

After a first incident, the cause at the site must be remedied permanently; repeated discharges from the same pipe lead to high fines.

Authority / court
Derby Crown Court (Anklage: Environment Agency)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Regulations 12(1)(b) und 38(1)(a) Environmental Permitting (England and Wales) Regulations 2016
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Culpability
negligent
Repeat case
yes
Published
23 Feb 2026

Original amount 733,333 GBP, converted at the ECB reference rate of 23 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Feb 2026 VersaBankFINTRAC: CAD 42,075 penalty on VersaBank for 2 violations of anti-money laundering obligations CanadaCustomer due diligence €26,082

According to FINTRAC, VersaBank is a bank based in London, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 42,075 on the company on 23 February 2026. According to FINTRAC's findings, the company committed 2 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures and enhanced measures for high-risk situations. Specifically, according to FINTRAC, the bank failed in at least seven instances to correctly identify elevated or high-risk clients and apply enhanced due diligence. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on VersaBank", published 5 May 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-05-05-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
PCMLTFA s. 9.6(1), 9.6(3); PCMLTF Regulations 156(1)(b), 157; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
5 May 2026

Original amount 42,075 CAD, converted at the ECB reference rate of 23 Feb 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 BVwG reduces FMA penalty against private bank over unclarified beneficial owners AustriaCustomer due diligence €356,000

From 2017 to 2020, an Austrian bank specialising in private and investment banking had not adequately examined the ownership and control structure of an offshore holding client despite the lack of evidence on shareholders, trust arrangements and beneficial owners. The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the infringement but reduced the additional penalty imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 17 December 2024 from 476,000 to 356,000 EUR (total penalty 436,000 EUR less FMA penalties already paid), because the FMA had taken the seriousness of the offence into account twice and the bank had cooperated, admitted its errors and terminated the client relationship; an appeal on points of law has been permitted.

What organisations can take from it

For offshore holdings with trustees, prove the beneficial owner with supporting documents – a self-declaration is not enough.

Relevance to training and awareness

Identifying beneficial owners in holding and trust structures

Authority / court
Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 17.12.2024
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 9 Abs. 1 erster Satz i. V. m. § 6 Abs. 1 Z 2 FM-GwG; § 35 Abs. 1 und 3 i. V. m. § 34 Abs. 1 Z 2 und Abs. 2 FM-GwG; § 22 Abs. 9 FMABG (Zusatzstrafe)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Reduction by the court because the wrongfulness of the offence had been counted twice, cooperation, admission of the facts and of guilt, and termination of the client relationship

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR RomaniaData protection €1,999

The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.

What organisations can take from it

Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.

Relevance to training and awareness

Taking patient data when leaving; cooperation with the supervisory authority

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
20 Feb 2026

Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 The Commissioner of Police for the City of London (City of London Police)ICO: reprimand for City of London Police over late subject access responses United KingdomData subject rights and transparency Reprimand or warning

The ICO issued a reprimand to the City of London Police. The ICO found that between 1 April 2023 and 31 July 2025 the police force had failed to answer subject access requests within the statutory deadline. The ICO found this breached Article 12(3) UK GDPR and section 45(3) of the Data Protection Act 2018.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12(3) UK GDPR; section 45(3) DPA 2018; Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files CroatiaData subject rights and transparency €100,000

An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.

Relevance to training and awareness

Data minimisation for ID copies, retention periods

Missing or inadequate training played a role in the decision.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
negligent
Mitigating circumstances
No damage to data subjects was found.
Published
19 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Somers Forge LimitedSomers Forge: 750,000 GBP after fatal accident on a 20-metre lathe United KingdomWorkplace safety and accidents €859,697

In December 2023, a machinist was caught by a lathe and fatally injured while finishing a rotating workpiece with emery cloth. The forge had not prohibited manual work with emery cloth, had not prevented access to moving parts and had not carried out a risk assessment; the Health and Safety Executive (HSE) prosecution resulted in a fine of 750,000 GBP plus 38,314 GBP in costs.

What organisations can take from it

Expressly prohibit dangerous habitual practices on machine tools and safeguard against them with guarding and instruction.

Relevance to training and awareness

Safe working on rotating machinery

Authority / court
Health and Safety Executive (Walsall Magistrates' Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Health and Safety at Work etc. Act 1974, s. 2(1)
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Published
18 Feb 2026

Original amount 750,000 GBP, converted at the ECB reference rate of 18 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Périphériques et Matériels de Contrôle SAS (Groupe Carrus)Betting terminal manufacturer PMC: CJIP over payments to the head of state-owned PMU Mali FranceBribery of public officials €499,150

From 2008 to 2011, the Paris-based supplier of betting and gaming terminals made unjustified payments of 78,972 EUR to the head of the majority state-owned Pari Mutuel Urbain Mali, with which it had a supply contract awarded without a tender. The case was triggered by a report from TRACFIN (the French financial intelligence unit). Public interest fine of 499,150 EUR (including 335,000 EUR already seized) and a three-year AFA compliance programme.

What organisations can take from it

Managers of state-controlled companies are also public officials – even small private payments to them create a risk of criminal liability for medium-sized companies.

Relevance to training and awareness

Payments to heads of state-owned companies abroad

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger und Geldwäsche
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
50 to 249
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Canada, BCData breaches and data security Other

Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.

What organisations can take from it

Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.

Relevance to training and awareness

Unauthorised viewing of patient records (snooping)

Authority / court
Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
Area of law
Data protection · Data breaches and data security
Legal basis
Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
Action
Other
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR EU levelOrganisational requirements €1.37m

The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.

What organisations can take from it

Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2026 BVwG upholds 588,000 EUR FMA penalty against major bank over incorrect risk classification AustriaCustomer due diligence €588,000

The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) dismissed the appeal of a listed major Austrian bank and upheld the fine of 588,000 EUR (plus 58,800 EUR in procedural costs) imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 19 November 2024. From 2017 to 2020, the bank had not adequately risk-classified three business relationships and had disregarded sector risks such as gambling and precious metals trading as well as cash intensity; an appeal on points of law has been permitted.

What organisations can take from it

Customers from gambling or precious metals trading with a high share of cash belong in a higher risk class – otherwise the enhanced obligations are missing.

Relevance to training and awareness

Risk classification of cash-intensive high-risk sectors

Authority / court
Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 19.11.2024
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 6 Abs. 5 i. V. m. § 34 Abs. 1 Z 2 und § 35 Abs. 1–3 FM-GwG
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Feb 2026 Carillion plc (in liquidation)FCA: Public censure for Carillion plc over misleading market information United KingdomMarket abuse and insider dealing Reprimand or warning

The FCA publicly censured the former construction and services group Carillion plc. The regulator found that between July 2016 and July 2017 the company published misleading information, breaching the prohibition of market manipulation and listing requirements; in July 2017 Carillion had to announce a provision of £845 million. Because the company has been in liquidation since January 2018, no fine was imposed; the FCA stated it would otherwise have been £37.91 million.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Art. 15 MAR; Listing Rule 1.3.3R; Listing Principle 1; Premium Listing Principle 2; sections 91 und 123 FSMA 2000
Action
Reprimand or warning
Status of proceedings
final
Sector
Construction and real estate

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 ELKOND HHK, VUKI, Prysmian, NKT, KABEX u. a. (Kabelkartell, 9 Unternehmen und ein Verband)Cable cartel: PMÚ imposes record fines of 97.4 million EUR SlovakiaCartels and collusion €97.4m

Manufacturers and suppliers of copper and aluminium cables coordinated a common calculation of the metal surcharge, which makes up a significant part of the final price; an industry association acted as facilitator. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a total of 97,434,800 EUR, the highest amount in a single proceeding; two leniency applicants were not fined (not final). Addressees: ELKOND HHK, a.s.; VUKI a.s.; Prysmian Kablo s.r.o.; Prysmian Kabely, s.r.o.; Kablo Vrchlabí s.r.o.; NKT s.r.o.; PRECON s.r.o.; Tele–Fonika Kabely CZ s.r.o.; KABELOVNA KABEX a. s.; Asociace výrobců kabelů a vodičů ČR a SR (leniency applicants without a fine: ICS Industrial Cables Slovakia, PRAKAB).

What organisations can take from it

A coordinated calculation formula for price components is also price fixing – association work needs competition law support.

Relevance to training and awareness

Price coordination via associations and surcharge formulas

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
Action
Fine
Status of proceedings
unknown
Sector
Manufacturing and mechanical engineering
Culpability
intentional
Published
11 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 DPG Media nv; Mediahuis nv; PPP Belgium bv; bpost nv (Kronzeuge)Press concession: 11.9 million EUR for collusion in newspaper delivery tender BelgiumCartels and collusion €11.9m

So that bpost would obtain the state concession for newspaper delivery for 2023–2027, its competitor PPP refrained from submitting a bid and in return received additional delivery volumes from DPG Media and Mediahuis (bid rigging). In a settlement procedure, the Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (Belgian Competition Authority, BMA) imposed 3,786,574 EUR (DPG Media), 7,788,423 EUR (Mediahuis) and 323,486 EUR (PPP); bpost, as leniency applicant, received full immunity, and two bpost employees involved were fined a total of 6,300 EUR.

What organisations can take from it

Agreements on who participates in a tender are hardcore cartels – individuals are also liable, and leniency applicants benefit.

Relevance to training and awareness

Collusion in public tenders

Authority / court
Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (BMA)
Area of law
Competition law · Cartels and collusion
Legal basis
Code de droit économique Art. IV.1; AEUV Art. 101
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Leniency programme (immunity for bpost; reductions of 50% and 40% for DPG Media and Mediahuis respectively) and 10% settlement reduction.
Liability of senior managers
First-ever fines against two natural persons (employed by bpost), totalling 6,300 EUR.
Published
13 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 IMG Academy, LLCOFAC: USD 1.72 million settlement with IMG Academy over school contracts with two sanctioned individuals USABreaches of sanctions and embargoes €1.45m

School and sports academy IMG Academy, LLC of Bradenton, Florida, is paying USD 1,720,000 under a settlement with OFAC for apparent violations of the counternarcotics sanctions. According to OFAC's findings, between 2019 and 2025 IMG Academy entered into tuition agreements for the children of two individuals on the SDN List because of their ties to a sanctioned Mexican drug cartel and processed the related payments; 89 dealings were involved in total. OFAC treated the apparent violations as non-egregious and not voluntarily self-disclosed because an investigation was already under way when the academy reported them; the settlement amount equals the base penalty. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "IMG Academy, LLC Settles with OFAC for $1.7 Million Related to Apparent Violations of Counternarcotics Sanctions", 12 February 2026, https://ofac.treasury.gov/media/935006/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Foreign Narcotics Kingpin Sanctions Regulations, 31 C.F.R. § 598.202 (89 mutmaßliche Verstöße); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Other
Published
12 Feb 2026

Original amount 1,720,000 USD, converted at the ECB reference rate of 12 Feb 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 UAB „Manado“, MB „Parts ready“Manado and Parts ready: cartel in Vilnius public transport spare parts tender LithuaniaCartels and collusion €41,080

In two tenders by ‘Vilniaus viešasis transportas’ for vehicle spare parts (May–October 2025), the dealers coordinated bids and prices, wrote the bids for each other and sent them from the same computer. The contracting entity reported the suspicion. Following acknowledgement (minus 15%), fines of 17,950 EUR (Manado) and 23,130 EUR (Parts ready). Source: archived copy of the press release.

What organisations can take from it

Even jointly prepared bids by small dealers are a cartel – and contracting entities increasingly recognise such patterns.

Relevance to training and awareness

Competition law in tenders

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Cartels and collusion
Legal basis
Konkurencijos įstatymas (verbotene Vereinbarungen)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Acknowledgement of the infringement (15% reduction)
Published
12 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 Peter the Chef Fine Food LimitedPeter the Chef Fine Food: four CFIA penalties totalling 41,600 CAD (food safety) Canada, ONOther €25,794

On a single day, the Canadian Food Inspection Agency (CFIA) imposed four administrative monetary penalties on the food manufacturer in Ontario under the Safe Food for Canadians Act (s. 17(1)) and the Safe Food for Canadians Regulations (ss. 49, 88, 90(1)): 13,000, 11,000, 11,000 and 6,600 CAD, totalling 41,600 CAD.

What organisations can take from it

Preventive controls and documentation under food safety law are sanctioned individually – several gaps quickly add up.

Authority / court
Canadian Food Inspection Agency (CFIA)
Area of law
Other
Legal basis
Safe Food for Canadians Act, s. 17(1); Safe Food for Canadians Regulations, ss. 49, 88, 90(1)
Action
Fine
Status of proceedings
final
Sector
Food and agriculture

Original amount 41,600 CAD, converted at the ECB reference rate of 12 Feb 2026.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Feb 2026 Applied Materials, Inc. und Applied Materials Korea, Ltd.Applied Materials pays 252 million USD for chip equipment exports to China USAExport control and dual-use goods €212.2m

In 2021 and 2022, Applied Materials and its Korean subsidiary exported ion implanters for semiconductor manufacturing worth around 126 million USD via Korea without a licence to a Chinese company placed on the Entity List in 2020. The penalty imposed by the US Commerce Department's Bureau of Industry and Security (BIS) corresponds to twice the transaction value and thus the statutory maximum; the compliance staff and executives responsible are no longer with the company.

What organisations can take from it

Routing through foreign subsidiaries does not remove the licence requirement; export control needs audits and clear accountability of management.

Relevance to training and awareness

Entity List screening for deliveries via subsidiaries

Authority / court
U.S. Department of Commerce, Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations (Entity List)
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Employees
10,000 or more
Liability of senior managers
According to BIS, the responsible compliance staff and senior executives from sales and production are no longer employed.
Published
12 Feb 2026

Original amount 252,500,300 USD, converted at the ECB reference rate of 11 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Feb 2026 Disney DTC, LLC und ABC Enterprises, Inc. (The Walt Disney Company)California: $2.75 million against Disney over incomplete opt-outs for streaming USA, CACookies and tracking €2.31m

Disney implemented objections to the sale and sharing of data only for individual services or devices rather than across the whole account, continued to disclose data via embedded ad-tech providers and offered no opt-out in connected TV apps. It was the largest CCPA settlement at the time of the agreement with the Attorney General of California.

What organisations can take from it

An opt-out must take effect across all services, devices and integrated third-party providers of an account.

Authority / court
Attorney General of California (California Department of Justice)
Area of law
Data protection · Cookies and tracking
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more
Published
11 Feb 2026

Original amount 2,750,000 USD, converted at the ECB reference rate of 11 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Feb 2026 Strukton Civiel Projecten B.V. und Strukton International B.V. (Strukton-Gruppe)Construction group Strukton pays 10 million EUR out-of-court settlement over bribery on the Riyadh Metro NetherlandsBribery of public officials €10m

To secure a share in the Riyadh Metro project, around 31 million USD was paid between 2013 and 2021 to an agent representing a high-ranking member of the Saudi royal family; the agent payments were understated to the export credit insurer Atradius. Strukton accepted a transaction (out-of-court settlement) of 10 million EUR.

What organisations can take from it

Commissions to agents with ties to ruling families carry the highest risk – and false statements to export credit insurers constitute a second offence.

Relevance to training and awareness

Agent commissions and false statements to export credit insurers

Authority / court
Openbaar Ministerie (OM)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Buitenlandse ambtelijke omkoping und valsheid in geschrift (Wetboek van Strafrecht); Transactie nach Art. 74 Sr
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Culpability
intentional
Mitigating circumstances
Cooperation from mid-2023; compliance programme in place since 2017; the employees involved are no longer with the company.
Liability of senior managers
The Dutch Public Prosecution Service (OM) is considering prosecuting several natural persons involved (not named).
Published
30 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Feb 2026 Paxful Holdings Inc.Crypto platform Paxful: 4 million USD penalty after guilty plea to BSA infringements USAInternal controls €3.36m

Following a guilty plea to charges including conspiracy to operate an unlicensed money transmitting business and to violate the AML obligations of the Bank Secrecy Act, the peer-to-peer crypto platform was sentenced to a penalty of 4 million USD. 112.5 million USD would have been appropriate, but the US Department of Justice (DOJ) found an inability to pay; in December 2025, FinCEN had additionally imposed a civil penalty of 3.5 million USD.

What organisations can take from it

Crypto platforms without registration and KYC face criminal liability – up to the limit of their ability to pay.

Authority / court
U.S. Department of Justice
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Travel Act; Verschwörung zum Betrieb eines nicht lizenzierten Geldtransfergeschäfts und zur Verletzung der AML-Pflichten des Bank Secrecy Act
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Mitigating circumstances
Penalty limited from 112.5 million to 4 million USD because of proven inability to pay
Published
11 Feb 2026

Original amount 4,000,000 USD, converted at the ECB reference rate of 10 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Feb 2026 Alco Harvesting LLC dba Bonipak Produce Inc. und verbundene UnternehmenBonipak: $6.175 million for farmworkers over undisclosed paid sick leave USA, CAMinimum wage and undeclared work €5.22m

Following the COVID death of a farmworker in employer-provided housing, the California Labor Commissioner's Office sued the agricultural business in Santa Maria in 2021: more than 10,000 farmworkers, including H-2A seasonal workers, had not been informed of their entitlement to paid sick leave; in addition, there was unpaid travel time as well as overtime and minimum wage violations. The settlement of $6,175,000 (of which $4.2 million goes directly to workers) includes posting and reporting obligations.

What organisations can take from it

Information obligations towards seasonal workers are not a formality – companies that leave workers in the dark about paid sick leave are liable for the consequences.

Authority / court
California Labor Commissioner's Office (Division of Labor Standards Enforcement)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
California Labor Code (Paid Sick Leave, COVID-19 Supplemental Paid Sick Leave, Mindestlohn, Überstunden)
Action
Other
Status of proceedings
final
Sector
Food and agriculture
Published
4 Feb 2026

Original amount 6,175,000 USD, converted at the ECB reference rate of 4 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Feb 2026 MediaLab.AI, Inc.ICO: £247,590 fine for Imgur operator MediaLab over children's data without age checks United KingdomData protection €287,361

The ICO fined MediaLab.AI, Inc., which operated the Imgur platform in the UK until 30 September 2025, £247,590. The ICO found that Imgur admitted children under 13, stated to be under parental supervision, and relied on consent as its lawful basis, but it had no way of establishing users' ages and therefore of obtaining the required parental consent. The ICO therefore found there was no valid lawful basis and also found that no data protection impact assessment had been carried out (Articles 5(1)(a), 6, 8 and 35 UK GDPR).

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection
Legal basis
Art. 5(1)(a), 6, 8 und 35 UK GDPR; section 155(1)(a) DPA 2018
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms

Original amount 247,590 GBP, converted at the ECB reference rate of 4 Feb 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Feb 2026 RE/MAX Twin City Realty Inc.FINTRAC: CAD 24,750 penalty on RE/MAX Twin City Realty Inc. for one violation of anti-money laundering obligations CanadaInternal controls €15,336

According to FINTRAC, RE/MAX Twin City Realty Inc. is a real estate brokerage based in Kitchener, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 24,750 on the company on 4 February 2026. According to FINTRAC's findings, made during a compliance examination, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned assessing and documenting money laundering and terrorist financing risks. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on RE/MAX Twin City Realty Inc.", published 5 May 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-05-05-1-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(c); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Published
5 May 2026

Original amount 24,750 CAD, converted at the ECB reference rate of 4 Feb 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Feb 2026 TMAC LtdICO: £100,000 fine for TMAC over marketing calls to TPS numbers United KingdomMarketing and consent €115,969

The ICO fined TMAC Ltd £100,000 and issued an enforcement notice. The ICO found that between 8 February and 24 September 2024 the company made 260,332 unsolicited marketing calls to numbers registered with the Telephone Preference Service (TPS). Recipients were also not given the caller details required by regulation 24 of PECR. The legal basis is regulations 21 and 24 of PECR.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 21(1)(b) und 24 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 100,000 GBP, converted at the ECB reference rate of 3 Feb 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 RASEMA s.r.o.; M – D – J, spol. s.r.o.; SIMA plus Krompachy, s.r.o.; BarCom spol. s.r.o.Photovoltaic tender: 1.1 million EUR – the contracting entity was also a cartel member SlovakiaCartels and collusion €1.1m

In a tender for industrial photovoltaic installations that was to be financed from EU Structural Funds, three bidders coordinated their bids so that a pre-selected bidder would win; the contracting entity BarCom acted as facilitator. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a total of 1,098,200 EUR and three-year procurement bans on all four; the EU funding was refused because of the indications of competition infringements, and the collusion was proven by e-mails secured during the inspection.

What organisations can take from it

A contracting entity that determines the winner of a funded tender in advance is itself liable under competition law and additionally risks losing the funding.

Relevance to training and awareness

Collusion in funded procurement

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Culpability
intentional
Published
11 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list PortugalCartels and collusion €8,200

Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).

What organisations can take from it

Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.

Relevance to training and awareness

No price recommendations by professional associations

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 Finca Monte GrandeCBP stops coffee from Mexican Finca Monte Grande over forced labour USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: coffee from Finca Monte Grande (Mexico) is being detained at all US ports of entry because there are indications of forced labour (ILO indicators including debt bondage, withholding of wages, retention of identity documents and excessive overtime).

What organisations can take from it

Importers of agricultural commodities should be able to check working conditions down to plantation level; otherwise they face detention at the border.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Published
29 Jan 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jan 2026 Syngenta LtdSyngenta: 400,000 GBP after uncontrolled release of high-pressure steam during maintenance United KingdomWorkplace safety and accidents €460,564

While flange bolts were being removed from a steam trap in November 2023, a corroded isolation valve failed and high-pressure steam escaped; the contractor's fitter narrowly escaped serious injury. The agrochemicals group had not maintained work equipment and had not assessed the risk despite known corrosion (only single instead of double isolation). The Health and Safety Executive (HSE) prosecution resulted in a fine of 400,000 GBP plus 8,288 GBP in costs.

What organisations can take from it

Known corrosion requires safer isolation procedures – routine tasks must not mask risks.

Relevance to training and awareness

Isolation and shut-off during maintenance

Authority / court
Health and Safety Executive (Leeds Magistrates' Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Provision and Use of Work Equipment Regulations 1998, reg. 5(1); Management of Health and Safety at Work Regulations 1999, reg. 3(1)
Action
Fine
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more
Published
28 Jan 2026

Original amount 400,000 GBP, converted at the ECB reference rate of 28 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jan 2026 CCV Group B.V.Netherlands: payment institution CCV without integrity risk analysis – 406,125 EUR fine NetherlandsInternal controls €406,125

Until March 2018, the payment institution had no systematic integrity risk analysis (SIRA) and therefore no systematic identification and analysis of integrity risks for its gatekeeper function. The Dutch central bank (De Nederlandsche Bank, DNB) imposed the fine in 2020; following objection and appeal proceedings, it was fixed at the reduced amount of 406,125 EUR by the decision of 28 January 2026 and was published in July 2026.

What organisations can take from it

Without a documented integrity risk analysis, any money laundering prevention lacks its foundation – and that alone is subject to fines.

Authority / court
De Nederlandsche Bank (DNB)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 3:10 Wet op het financieel toezicht (Wft); Art. 10 Besluit prudentiële regels Wft (Bpr)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Mitigating circumstances
Fine reduced in the objection and appeal proceedings
Published
21 Jul 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Jan 2026 Archer-Daniels-Midland Company (ADM)ADM: embellished segment results in Nutrition – 40 million USD penalty USADisclosure and reporting obligations €34.5m

ADM and former executives had artificially inflated the results of the Nutrition segment through retroactive intra-group rebates and price adjustments in order to show growth targets of 15–20 %. ADM is paying a civil penalty of 40 million USD; two former managers are paying a combined 979,953 USD in disgorgement including interest and 200,000 USD in penalties, while litigation continues against a third.

What organisations can take from it

Intra-group transfer prices and retroactive segment adjustments require independent control when segments are publicly promoted as growth drivers.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Antifraud-, Reporting-, Buchführungs- und interne Kontrollvorschriften der US-Bundeswertpapiergesetze (Settled Order der SEC)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
ADM's cooperation and remedial measures were taken into account
Liability of senior managers
Vince Macciocchi: 404,343 USD disgorgement/interest, 125,000 USD penalty, 3-year officer-and-director bar; Ray Young: 575,610 USD disgorgement/interest, 75,000 USD penalty; action against Vikram Luthar pending

Original amount 41,179,953 USD, converted at the ECB reference rate of 27 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data SwedenData breaches and data security €564,626

The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).

What organisations can take from it

Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
Published
26 Jan 2026

Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack FranceData breaches and data security €5m

In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.

What organisations can take from it

Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.

Relevance to training and awareness

Social engineering and account takeover

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jan 2026 Logistics business: fines for minimum wage, reporting and foreign employment violations GermanyMinimum wage and undeclared work €13,731

Between June and December 2023, a logistics and transport business withheld a total of around 2,000 EUR in minimum wages from several employees, breached reporting and immediate notification obligations, and in July/August 2023 employed a foreign national without a residence permit. The fines: 5,231 EUR (minimum wage), 750 EUR each (reporting obligations) and 7,000 EUR (unauthorised employment of foreign nationals), totalling 13,731 EUR (date = publication).

What organisations can take from it

Even small wage arrears are penalised individually alongside reporting and residence violations – HR processes for new hires need a fixed checklist.

Relevance to training and awareness

Immediate notification and checking of work permits when hiring

Authority / court
Hauptzollamt Karlsruhe (Finanzkontrolle Schwarzarbeit)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
§ 21 Abs. 1 Nr. 11 MiLoG; § 111 Abs. 1 Nr. 2 SGB IV; § 404 Abs. 2 Nr. 3 SGB III
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
22 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jan 2026 CineplexCineplex: Court of Appeal upholds 38.9 million CAD penalty for online booking fee CanadaMisleading advertising and pricing €24m

The cinema company added a mandatory booking fee of 1.50 CAD to advertised ticket prices for online purchases. In September 2024, the Competition Tribunal classified this as drip pricing and imposed a penalty of 38.9 million CAD (the amount Cineplex had earned from it between June 2022 and December 2023) plus a ten-year prohibition; the Federal Court of Appeal dismissed the appeal in January 2026.

What organisations can take from it

An advertised price must be attainable – only government charges may be added separately.

Authority / court
Federal Court of Appeal / Competition Tribunal (auf Antrag des Competition Bureau)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Competition Act, Deceptive Marketing Practices (Drip Pricing, seit 24.06.2022 ausdrücklich geregelt)
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
23 Jan 2026

Original amount 38,900,000 CAD, converted at the ECB reference rate of 21 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2026 PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs)Pharmaceutical cartel uncovered thanks to whistleblower: 7.8 million EUR against PHOENIX and TRANSMEDIC SlovakiaCartels and collusion €7.8m

The two companies colluded in tenders of the General Health Insurance Company for the supply of medicines (2017–2020). For the first time, a cartel was uncovered on the basis of information from a whistleblower; the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 7,595,200 EUR and a one-year procurement ban on PHOENIX and 201,800 EUR and a three-year procurement ban on TRANSMEDIC (first instance).

What organisations can take from it

Whistleblowers receive a reward in Slovakia – internal reporting channels should be faster than the route to the authority.

Relevance to training and awareness

Bid rigging in public tenders; whistleblowing channels

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
PHOENIX: settlement with a 30% fine reduction and a shortened procurement ban.
Published
24 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2026 Cardif Lux Vie S.A.Cardif Lux Vie: 615,000 EUR over deficiencies in money laundering questionnaires and customer files LuxembourgCustomer due diligence €615,000

An on-site inspection in 2023 revealed that the life insurer in some cases did not handle the mandatory money laundering risk assessment questionnaires in compliance with the rules, that the employees responsible lacked sufficiently precise instructions and that customer files contained many incorrect answers. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 615,000 EUR.

What organisations can take from it

Risk questionnaires are only as good as the guidance given to those who complete them – clear work instructions and training are part of this.

Relevance to training and awareness

Money laundering risk assessment by employees

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 8-4, 8-5; Règlement CAA 20/03
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Close cooperation with the CAA during and after the inspection; remediation plan for all deficiencies submitted promptly.
Published
1 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 Derbyshire ConstabularyDerbyshire Constabulary: 60,000 GBP after burn injuries during Molotov cocktail training United KingdomWorkplace safety and accidents €69,196

During a public order training exercise in February 2021, police officers wearing flame-retardant protective clothing had petrol bombs thrown at them; four officers suffered burns with permanent scarring. There was no information on the service life and testing of the PPE, no risk assessment for the manufacture and use of the petrol bombs, and no safe systems of work. The Health and Safety Executive (HSE) prosecution resulted in a fine of 60,000 GBP plus 9,470 GBP in costs.

What organisations can take from it

Realistic operational training also needs a risk assessment and tested protective equipment.

Relevance to training and awareness

Safety in high-risk exercises and PPE testing

Authority / court
Health and Safety Executive (Sheffield Magistrates' Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Health and Safety at Work etc. Act 1974, s. 2(1)
Action
Fine
Status of proceedings
final
Sector
Public sector
Published
20 Jan 2026

Original amount 60,000 GBP, converted at the ECB reference rate of 19 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants AustriaData subject rights and transparency €25,500

The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).

What organisations can take from it

Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.

Relevance to training and awareness

Recording of telephone calls and applicant data

Authority / court
Datenschutzbehörde
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
Action
Fine
Status of proceedings
under appeal
Sector
Other
Employees
Under 50
Mitigating circumstances
No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR RomaniaEmployee data €14,997

An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.

Relevance to training and awareness

Handling employees’ health data, e-mail distribution lists

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
19 Jan 2026

Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jan 2026 Allay Claims LtdICO: £120,000 fine for Allay Claims over marketing texts about PPI tax refunds United KingdomMarketing and consent €138,344

The ICO fined Allay Claims Ltd £120,000 and issued an enforcement notice. The ICO found that the company had sent a large volume of unsolicited text messages promoting services to reclaim tax on PPI refunds; the enforcement notice gives the period as 1 February 2023 to 13 February 2024. The ICO found a serious breach of regulation 22 of PECR (electronic marketing without consent).

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulation 22 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Original amount 120,000 GBP, converted at the ECB reference rate of 15 Jan 2026.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2026 Zalando SEZalando: around 31 million PLN for missing 30-day lowest prices on discounts PolandMisleading advertising and pricing €7.34m

Zalando did not display the lowest price of the previous 30 days for discounts, manipulated reference prices to make reductions appear larger and did not present the mandatory information consistently at all stages of the purchasing process. Poland's Office of Competition and Consumer Protection (UOKiK) imposed a fine of 30,945,000 PLN; the decision is not final.

What organisations can take from it

Discount information must be identical and correct on all pages of a shop – listing, product page, shopping basket.

Relevance to training and awareness

Presentation of discounts in online shops

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
14 Jan 2026

Original amount 30,945,000 PLN, converted at the ECB reference rate of 14 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2026 Whaleco Technology Limited (Temu)Temu: almost 6 million PLN over changing reference prices and discount labelling PolandMisleading advertising and pricing €1.4m

The operator of the Temu interface omitted the 30-day lowest price or stated it incorrectly, labelled promotions inconsistently and changed reference prices from day to day without the actual price changing. UOKiK imposed a fine of 5,910,900 PLN; the decision is not final.

What organisations can take from it

Reference prices that shift daily without any real price change are a misleading staging of discounts.

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
14 Jan 2026

Original amount 5,910,900 PLN, converted at the ECB reference rate of 14 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Jan 2026 Maplebear Inc. (Instacart)Instacart pays 60 million USD in FTC settlement over "free delivery" with mandatory fees USAMisleading advertising and pricing €51.5m

According to the FTC, Instacart advertised free delivery but charged mandatory service fees of up to 15 %, promised a "100 % satisfaction guarantee" without providing full refunds and did not sufficiently point out the subsequent charges for trial subscriptions. Under the settlement, the company is paying 60 million USD for refunds and must discontinue the practices complained of.

What organisations can take from it

Anyone advertising something as "free" must not add a mandatory fee elsewhere.

Relevance to training and awareness

Price advertising and disclosure of fees in marketing

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Section 5 FTC Act; Restore Online Shoppers' Confidence Act (ROSCA)
Action
Disgorgement of profits
Status of proceedings
final
Sector
Retail and e-commerce
Published
18 Dec 2025

Original amount 60,000,000 USD, converted at the ECB reference rate of 13 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Jan 2026 Estee Lauder Cosmetics Ltd.Estee Lauder Cosmetics: 750,000 CAD fine for unreported PFAS in eyeliners Canada, ONWaste and hazardous substances €463,765

A routine inspection in 2023 found that the company was selling eyeliners containing the PFAS substance perfluorononyl dimethicone without submitting the required notification of a ‘significant new activity’; a subsequent compliance order was not complied with. The court imposed 750,000 CAD; the company must inform its shareholders and is listed in the Environmental Offenders Registry.

What organisations can take from it

Product development and regulatory affairs must check new substances for notification requirements before market launch; regulatory orders must be implemented within the deadline.

Relevance to training and awareness

Chemical notification and approval obligations for product launches

Authority / court
Ontario Court of Justice (Ermittlungen: Environment and Climate Change Canada)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Canadian Environmental Protection Act, 1999 (Significant New Activity, Compliance Order)
Action
Fine
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Published
2 Feb 2026

Original amount 750,000 CAD, converted at the ECB reference rate of 13 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jan 2026 Bulgarian construction subcontractor: 232,500 EUR for paying below the minimum wage GermanyMinimum wage and undeclared work €232,500

A Bulgarian construction company that worked as a subcontractor for a German firm on a major construction site in the district of Tuttlingen between January and May 2023 paid below the minimum wage, recorded only the duration of working time rather than its start and end, and did not register the posting. The decisions issued in September 2025, final since the end of 2025, amount to 232,500 EUR – of which 215,000 EUR is disgorgement of the economic benefit and 17,500 EUR is imposed on the managing director (date = publication; exact date of the decision not specified).

What organisations can take from it

General contractors should actively check the minimum wage, working time records and posting notifications of their foreign subcontractors – the economic benefit is disgorged in full.

Authority / court
Hauptzollamt Singen (Finanzkontrolle Schwarzarbeit)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Mindestlohngesetz; Arbeitnehmer-Entsendegesetz (Aufzeichnungs- und Meldepflichten)
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Liability of senior managers
Separate fine of 17,500 EUR against the managing director.
Published
9 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts FranceData breaches and data security €42m

Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.

What organisations can take from it

Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
Published
14 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Glasgow City CouncilGlasgow City Council: 80,000 GBP after collapse of a rusted-through lamp post United KingdomWorkplace safety and accidents €92,092

In June 2023, a lamp post dating from the 1950s/60s, whose steel at the base was at least 60 % rusted through, fell over and seriously injured a pedestrian. The post had been rated as poor in 2022 but was not scheduled for replacement until 2024; the council's visual inspections did not identify the acute risk of collapse. The Health and Safety Executive (HSE) prosecution resulted in a fine of 80,000 GBP.

What organisations can take from it

Inspection regimes for ageing infrastructure must prioritise findings and trigger immediate action where there is acute danger.

Authority / court
Health and Safety Executive (Glasgow Sheriff Court)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Health and Safety at Work etc. Act 1974, s. 3(1)
Action
Fine
Status of proceedings
final
Sector
Public sector
Published
12 Jan 2026

Original amount 80,000 GBP, converted at the ECB reference rate of 8 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log GreeceEmployee data €10,000

In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.

What organisations can take from it

Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.

Relevance to training and awareness

Confidential handling of employees’ health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jan 2026 Superior General Partner Inc.Superior General Partner: 1.35 million CAD fine for sodium chlorite in river and late reporting Canada, QCWaste and hazardous substances €845,987

In 2019, as a result of an equipment defect, sodium chlorite entered the Rivière du Lièvre twelve times from the ERCO Mondial chemical plant in Gatineau; in the last incident, the authorities were only informed after five days. The company was fined 1.35 million CAD, and the then technical and environmental director 15,000 CAD.

What organisations can take from it

Reporting obligations for releases of substances apply immediately; those who wait for days incur additional liability – including personally as the person responsible.

Relevance to training and awareness

Immediate reporting of environmental incidents to the authorities

Authority / court
Court of Québec (Ermittlungen: Environment and Climate Change Canada)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Fisheries Act (Einbringen schädlicher Stoffe; unterlassene sofortige Meldung)
Action
Fine
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Liability of senior managers
Jean-François Roux, the plant's then technical and environmental director, was personally fined 15,000 CAD.
Published
8 Jan 2026

Original amount 1,365,000 CAD, converted at the ECB reference rate of 7 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jan 2026 Portugal: 16,000 EUR against filling station operator for forwarding complaints late PortugalConsumer protection and online retail €16,000

A filling station operator (medium-sized company, name not published) did not send the originals of eight sheets from the statutory complaints book to the authority on time. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) imposed 16,000 EUR for eight negligent administrative offences; the Competition, Regulation and Supervision Court upheld the fine in full on 14 July 2026.

What organisations can take from it

Even formal obligations such as forwarding complaints book sheets are sanctioned per case – branch staff must know the procedure.

Relevance to training and awareness

Timely forwarding of customer complaints from the complaints book

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Consumer protection and online retail
Legal basis
Decreto-Lei n.º 156/2005 (Livro de Reclamações); Regime Jurídico das Contraordenações Económicas, Art. 18, 19
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Employees
50 to 249
Culpability
negligent
Mitigating circumstances
No previous record, no economic advantage

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent PolandData protection €232,208

The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.

What organisations can take from it

Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Repeat case
yes
Mitigating circumstances
During the proceedings the function was made independent and placed directly under the management board.
Published
26 Jan 2026

Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 C2MAC Group, Fonderie De Riccardis, Zanardi Fonderie u. a. (Gießereikartell, 12 Unternehmen und Assofond)Italy: 70 million EUR against 16 foundries and the association Assofond over price index cartel ItalyCartels and collusion €70m

From 2004 to June 2024, foundries coordinated their pricing strategies via the association Assofond: they exchanged sensitive information and developed joint indexation mechanisms ("Assofond indicators") in order to push through price increases including margins. The AGCM imposed fines of 70 million EUR (maximum around 600 million EUR), taking the crisis in the sector into account as a mitigating factor. Addressees: C2MAC Group, Fonderia Corrà, Fonderie De Riccardis, Fonderie Guido Glisenti/Lead Time, Pilenga Baldassarre/E.F. Group, Fonderie Mora Gavardo/Camozzi Group, Zanardi Fonderie, VDP Fonderia, Fonderie Ariotti, Ironcastings, Fonderia Zardo, ZML Industries/Cividale, Assofond.

What organisations can take from it

Joint price indices within an association are only permissible if they do not enable coordination of margins or prices – metalworking companies should have their association activities accompanied by competition law advice.

Relevance to training and awareness

Association indices and price adjustment clauses as a coordination tool

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Steel and metals
Mitigating circumstances
The severe crisis in the foundry sector was taken into account in setting the fines
Published
31 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier GreeceMarketing and consent €80,000

Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).

What organisations can take from it

Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.

Relevance to training and awareness

Checking consent before telemarketing

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5, 6, 7, 29, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Dec 2025 Rickenbacher Data LLC (Datamasters)CPPA: $45,000 against data broker Datamasters over failure to register USA, CAMarketing and consent €38,275

Without registering as a data broker, the Texas reseller traded in the names and contact details of millions of people, sorted by illnesses such as Alzheimer's or addiction, by age, presumed ethnicity and political views. In addition to the fine, the California Privacy Protection Agency (CPPA) requires it to stop selling data on all Californians.

What organisations can take from it

Companies that buy or sell address lists for advertising must check registration obligations – health-related lists are particularly risky.

Authority / court
California Privacy Protection Agency (CPPA)
Area of law
Data protection · Marketing and consent
Legal basis
California Delete Act (Registrierungspflicht für Datenhändler)
Action
Fine
Status of proceedings
final
Sector
Other
Published
8 Jan 2026

Original amount 45,000 USD, converted at the ECB reference rate of 30 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2025 Ryanair DAC, Ryanair Holdings plcItaly: 255.8 million EUR against Ryanair for obstructing travel agencies ItalyAbuse of market power €255.8m

From April 2023 until at least April 2025, Ryanair obstructed travel agencies from buying Ryanair flights in combination with other services, for example through facial recognition procedures, account deletions, blocking of means of payment and restrictive partner agreements. The AGCM considered this to be an abuse of a dominant position and imposed fines of 255,761,692 EUR on a joint and several basis.

What organisations can take from it

Dominant providers must not use technical barriers to force sales partners and resellers out of the market.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Published
23 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR FranceEmployee data €15m

In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.

What organisations can take from it

Store employee performance metrics only for as long and in as much detail as their specific purpose requires.

Authority / court
Conseil d'État
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Transport, logistics and shipping
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 New York-Presbyterian Hudson Valley HospitalNYP Hudson Valley Hospital: 6.8 million USD for payments to referring practice USACommercial bribery €5.79m

The hospital (until 2015 Hudson Valley Hospital Center) allegedly paid an oncology practice in Westchester millions of dollars to induce it to refer patients to the hospital; the hospital billed the services to Medicare and Medicaid. The U.S. Attorney’s Office filed a complaint and at the same time concluded a settlement of 6.8 million USD.

What organisations can take from it

Cooperation agreements between hospitals and office-based practices must properly document services and remuneration – otherwise payments are treated as referral bonuses.

Relevance to training and awareness

Payments to referrers in hospitals

Authority / court
U.S. Attorney's Office, Southern District of New York
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Healthcare

Original amount 6,800,000 USD, converted at the ECB reference rate of 22 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws FranceData processors €1.7m

As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.

What organisations can take from it

Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat SpainData processors €500,000

An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.

What organisations can take from it

Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.

Relevance to training and awareness

Diligence in customer service / misdirected messages

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data processors
Legal basis
Art. 25 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Snowball.xyz-Gruppe (Snowball.xyz, Šviesa, Tavo mokykla, Ateities pamoka) und AL holdingas-Gruppe (AL holdingas, Ugdymo sprendimai, UNT nuoma)E-register providers shared the market – 3.6 million EUR in cartel fines LithuaniaCartels and collusion €3.63m

In August 2020, the operators of the electronic class registers ‘Tamo’ and ‘Eduka’ agreed to stop competing: one group kept the class register business, the other took over the digital learning content. Following acknowledgement of the infringement, the fines were reduced by 15%: 2,714,940 EUR jointly and severally for the Snowball.xyz group and 913,340 EUR for the AL holdingas group (Art. 101 TFEU). The decision can be appealed. Source: archived copy of the press release.

What organisations can take from it

Agreements between competitors on ‘who does what’ are cartels – even when dressed up as portfolio streamlining.

Relevance to training and awareness

Market sharing among competitors

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Cartels and collusion
Legal basis
Konkurencijos įstatymas; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Acknowledgement of the infringement (15% reduction)
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style ItalyEmployee data €120,000

At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.

What organisations can take from it

Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.

Relevance to training and awareness

Employee monitoring through telematics

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Small number of data subjects (five employees), immediate suspension of the processing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Bravogroup Holding Vagyonkezelő Kft.Bravogroup: 32.6 million HUF for unnotified stake in Xiaomi distributor HungaryMerger control €84,042

In February 2023, the IT holding company acquired a 50% stake with negative sole control in the Xiaomi distributor Mystical Hungary Zrt., but only approached the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) after 582 days and notified the concentration thereafter. Following voluntary disclosure, acknowledgement and waiver of legal remedies, the authority imposed a significantly reduced 32.6 million HUF.

What organisations can take from it

Blocking rights (negative control) can also trigger a notification requirement – review stakes under merger control law before signing.

Relevance to training and awareness

Merger control for minority stakes with veto rights

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Merger control
Legal basis
Ungarisches Wettbewerbsgesetz, Vollzugsverbot (VJ/20/2025)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Voluntary disclosure, acknowledgement and waiver of legal remedies.
Published
18 Dec 2025

Original amount 32,600,000 HUF, converted at the ECB reference rate of 18 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Linglong International Europe D.O.O. ZrenjaninCBP import stop for tyres from Linglong's plant in Serbia USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: car tyres from Linglong International Europe D.O.O. Zrenjanin (Serbia) are being detained at all US ports of entry because there are indications of forced labour (ILO indicators including deception, debt bondage, isolation, retention of identity documents and withholding of wages (nine indicators in total)).

What organisations can take from it

Automotive suppliers should specifically audit recruitment, accommodation and the safekeeping of identity documents at plants with recruited migrant workers.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Automotive
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2025 Beausite Métal inc.Beausite Métal: 40,000 CAD because PCB equipment was not disposed of despite an order Canada, QCWaste and hazardous substances €24,745

The metal recycler in Val-des-Sources had received an environmental protection compliance order to dispose of and destroy PCB-contaminated equipment. At a follow-up inspection in May 2024, the equipment was still on the site; the company pleaded guilty under the Canadian Environmental Protection Act, 1999 (CEPA 1999) and was fined 40,000 CAD.

What organisations can take from it

Regulatory orders need an owner and a date in the calendar – non-compliance is a separate offence.

Authority / court
Court of Québec (Anklage: Environment and Climate Change Canada)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Canadian Environmental Protection Act, 1999
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Published
18 Dec 2025

Original amount 40,000 CAD, converted at the ECB reference rate of 17 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2025 Asparagus farm without reliable working time records: Raad van State upholds 11,250 EUR NetherlandsWorking time €11,250

In May/June 2022, the working time records of an asparagus business (anonymised in the judgment) deviated structurally from the hours actually worked; among other things, Sunday work went unrecorded, so compliance with working and rest times could not be checked. The Administrative Jurisdiction Division of the Dutch Council of State (Raad van State, Afdeling bestuursrechtspraak) upheld the fine of 11,250 EUR, imposed in 2023 without prior warning, including the increase factor of 1.5.

What organisations can take from it

Working time records that do not reflect actual hours are treated as missing – businesses are then sanctioned without prior warning.

Relevance to training and awareness

Correct recording of working and rest times

Authority / court
Raad van State, Afdeling bestuursrechtspraak (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid)
Area of law
Health and safety and employment law · Working time
Legal basis
Art. 4:3 Abs. 1 Arbeidstijdenwet
Action
Fine
Status of proceedings
final
Sector
Food and agriculture

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2025 Greencore Group plcGreencore/Bakkavor: takeover only with sale of sauce plant in Bristol United KingdomMerger control Order

In the planned acquisition of the food manufacturer Bakkavor, the Competition and Markets Authority (CMA) found a substantial lessening of competition in chilled own-label sauces for UK supermarkets. It cleared the merger only because Greencore undertook to sell its entire chilled soups and sauces plant in Bristol, including its employees, to a pre-determined purchaser.

What organisations can take from it

Even overlaps in small product segments can hold up an entire acquisition – prepare remedies early.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Competition law · Merger control
Legal basis
Enterprise Act 2002, s. 73(2) (Undertakings in lieu of reference)
Action
Order
Status of proceedings
final
Sector
Food and agriculture
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Dec 2025 Hardeck Möbel GmbH & Co. KGFurniture retailer Hardeck: 379,503 EUR fine for breach of AML due diligence obligations GermanyCustomer due diligence €379,504

The Arnsberg regional government (Bezirksregierung Arnsberg), as anti-money laundering supervisor for the non-financial sector, imposed a fine of 379,503.50 EUR, final since 16 December 2025, on the furniture retailer as a dealer in goods for breach of due diligence obligations under the German Money Laundering Act (Geldwäschegesetz, GwG). Karl-Ernst Hardeck is named as the person responsible for the company.

What organisations can take from it

Furniture retailers, as dealers in goods, are also obliged entities under the GwG – breaches of due diligence obligations can trigger six-figure fines.

Relevance to training and awareness

Identification for cash payments in the trade in goods

Authority / court
Bezirksregierung Arnsberg (Geldwäscheaufsicht Nichtfinanzsektor)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Geldwäschegesetz (Sorgfaltspflichten); Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Liability of senior managers
The announcement names Karl-Ernst Hardeck as the person responsible for the infringement

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Exide, FET (inkl. Elettra), Rombat, EUROBAT (Clarios Kronzeuge)EU: 72 million EUR against starter battery manufacturers and the association EUROBAT EU levelCartels and collusion €72m

From 2005 to 2017, the manufacturers of automotive starter batteries agreed, with the help of the association EUROBAT, to publish jointly calculated lead surcharges (EUROBAT premiums) and to use them in price negotiations with carmakers. Fines: Exide 30 million EUR, Rombat 20.218 million EUR, Elettra 15.594 million EUR, FET 6.11 million EUR, EUROBAT 125,000 EUR; Clarios escaped a fine as leniency applicant.

What organisations can take from it

Suppliers may pass on raw material surcharges individually, but must never fix them in an industry-wide coordinated manner via association indices.

Relevance to training and awareness

Joint raw material surcharges among competitors via association indices

Authority / court
Europäische Kommission
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV, Art. 53 EWR-Abkommen
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Leniency programme (Clarios 100 %, FET 50 %, Rombat 30 %); reduction for inability to pay for one company; payment in instalments

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack NetherlandsData breaches and data security €175,000

In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.

What organisations can take from it

Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Mitigating circumstances
Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Dec 2025 Police Service of ScotlandICO: £66,000 fine and reprimand for Police Scotland over handling of sensitive data United KingdomData breaches and data security €75,282

The ICO fined the Police Service of Scotland £66,000 and also issued a reprimand. The ICO found that, during a criminal investigation, the police carried out a bulk download of data from the mobile phone of an employee who had made a complaint, without ensuring that this was lawful, fair and limited to what was necessary; it found infringements for the period 18 January to 5 April 2021. For this the ICO issued the reprimand under sections 35 and 37 DPA 2018 (Part 3). The ICO also found that the Professional Standards Department later disclosed this data without authorisation to the person accused, in an internal misconduct investigation. Appropriate technical and organisational measures for compiling such misconduct packs were missing, and the breach was only reported to the ICO on 30 June 2022, although the police had known of it since 17 June 2022. For these infringements the ICO imposed the fine. The combined notice relies, among other provisions, on Articles 5(1)(f) and 32(1) UK GDPR (security of processing), Articles 5(1)(c) and 25 UK GDPR (data minimisation, data protection by design) and Article 33(1) UK GDPR (breach notification).

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5(1)(c), 5(1)(f), 25(1)-(2), 32(1) und 33(1) UK GDPR; section 155 DPA 2018 (Geldbuße); sections 35 und 37 DPA 2018 (Part 3), Verwarnung nach Schedule 13 para 2(c) DPA 2018
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Original amount 66,000 GBP, converted at the ECB reference rate of 12 Dec 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Dec 2025 Nationwide Building SocietyFCA: £44 million against Nationwide over financial crime controls United KingdomCustomer due diligence €50.4m

The UK Financial Conduct Authority (FCA) imposed £44,078,500 (after a 30% discount) because, from October 2016 to July 2021, the building society had no effective systems to keep due diligence and risk assessments for personal customers up to date, and did not identify personal accounts used for business purposes. As a result, one customer received 24 fraudulent Covid furlough payments totalling £27.3 million.

What organisations can take from it

Keep customer profiles continuously up to date – anyone who postpones known weaknesses for years ends up paying for the abuse.

Relevance to training and awareness

Identifying personal accounts used for business purposes

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
FCA Principle 3; SYSC 6.1.1R und 6.3.1R
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
30% settlement discount
Published
12 Dec 2025

Original amount 44,078,500 GBP, converted at the ECB reference rate of 11 Dec 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Dec 2025 ZMLUK LimitedICO: £105,000 fine for ZMLUK over unsolicited marketing emails United KingdomMarketing and consent €119,986

The ICO fined ZMLUK Limited £105,000. The ICO found that the company had sent unsolicited marketing emails for energy-saving products; the notice gives the period as 1 January to 21 July 2023. The ICO found a serious breach of regulation 22 of PECR (electronic marketing without consent). Under the notice, timely payment reduces the amount by 20% to £84,000.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulation 22 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 105,000 GBP, converted at the ECB reference rate of 11 Dec 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Dec 2025 „ЗП Либра“ ООДZP Libra: 44,205 leva for poaching customers using competitor’s trade secrets BulgariaCompetition law €22,602

With the help of an employee of its competitor I&G Insurance Brokers who later moved to ZP Libra, the broker unfairly concluded a brokerage agreement to the detriment of the competitor and used the competitor’s trade secrets to poach customers. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) imposed 29,470 leva (1% of 2024 turnover, Art. 36(1) ZZK – Bulgarian Protection of Competition Act) and 14,735 leva (0.5%, Art. 37(1) ZZK); fines totalling 1,000 leva were also imposed on the employee.

What organisations can take from it

When hiring employees from competitors, make sure they do not bring customer lists or secrets with them – otherwise both the company and the individual are liable.

Relevance to training and awareness

Taking customer data and trade secrets when changing employer

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 36 Abs. 1, Art. 37 Abs. 1 ZZK
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Fines on the employee involved (1,000 leva in total)
Published
16 Dec 2025

Original amount 44,205 BGN, converted at the ECB reference rate of 11 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Dec 2025 Century 21 Heritage Group Ltd.FINTRAC: CAD 148,912.50 penalty on Century 21 Heritage Group Ltd. for one violation of anti-money laundering obligations CanadaSuspicious activity reports €92,446

According to FINTRAC, Century 21 Heritage Group Ltd. is a real estate brokerage. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 148,912.50 on the company on 10 December 2025. According to FINTRAC's findings, made during a compliance examination, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned suspicious transaction reporting. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Century 21 Heritage Group Ltd.", published 10 February 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-02-10-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Construction and real estate
Published
10 Feb 2026

Original amount 148,912.5 CAD, converted at the ECB reference rate of 10 Dec 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Dec 2025 Invest in OÜLender Invest in OÜ pays 16,000 EUR for failing to submit annual accounts EstoniaDisclosure and reporting obligations €16,000

The lender did not submit its 2024 annual report, together with the audit report, the resolution on the appropriation of profits and the minutes of the shareholders’ meeting, to the financial supervisory authority on time. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed a fine of 16,000 EUR; the maximum is 1 million EUR or 10% of annual turnover. Date = publication.

What organisations can take from it

Even small supervised lenders need a reliable deadline calendar for mandatory supervisory reports.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 56 Abs. 3, § 96 Abs. 2 KAVS (Gesetz über Kreditgeber und -vermittler)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
10 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository EU levelPlatform obligations €120m

First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.

What organisations can take from it

Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
5 Dec 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 Volvo Hungária Kereskedelmi és Szolgáltató Kft.; Seres Gépipari Kereskedelmi Kft.; GIF Modul Kft.; Interteher Kft.; Eurotrade Kft.; He Hans Eibinger Kft. (MUT Kft. ohne Buße nach Entschädigung)Refuse vehicle cartel: over 1.5 billion HUF, of which 270 million for obstructing the inspection HungaryCartels and collusion €4.06m

In 2014–2015, chassis and body manufacturers allocated contracts and submitted cover bids in tenders for refuse collection and sewer cleaning vehicles. The Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed cartel fines of 1,278.4 million HUF (of which 972.9 million on Volvo Hungária) and, in addition, a record procedural fine of 270 million HUF on Volvo Hungária for obstructing access to data secured during the inspection.

What organisations can take from it

Regular meetings on ‘capacity planning’ with competitors are cartel evidence – and obstructing an inspection costs extra.

Relevance to training and awareness

Bid rigging and conduct during inspections

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Cartels and collusion
Legal basis
Ungarisches Wettbewerbsgesetz, Art. 101 AEUV (Submissionsabsprachen, Verfahrensbuße; VJ/30/2018)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Culpability
intentional
Mitigating circumstances
Admissions and leniency applications by most participants; MUT paid 116 million HUF in compensation to contracting authorities.
Published
5 Dec 2025

Original amount 1,548,400,000 HUF, converted at the ECB reference rate of 5 Dec 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 FMP West Midlands LimitedMetal polishing firm: fine after crush injury on unguarded tube polishing machine United KingdomWorkplace safety and accidents €27,501

While feeding a tube polishing machine that had no guarding and defective rollers, an employee's hand was drawn into the machine; one finger was partially severed and two others were crushed. The business had not prevented access to dangerous machine parts. Fine of £24,000 plus costs.

What organisations can take from it

In-running nips on rollers must be protected by fixed guards; defective machines must be taken out of service, not kept running.

Authority / court
Birmingham Magistrates' Court (Anklage: Health and Safety Executive)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Regulation 11(1) Provision and Use of Work Equipment Regulations 1998
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Published
8 Dec 2025

Original amount 24,000 GBP, converted at the ECB reference rate of 5 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository EU levelPlatform obligations Order

Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.

What organisations can take from it

Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Dec 2025 Jeronimo Martins Polska (Biedronka)Biedronka: almost 105 million PLN over undisclosed conditions for "100 % back" PolandMisleading advertising and pricing €24.7m

The supermarket chain advertised promotions such as "Special Wednesday" with "100 % money back as a voucher", but did not state restrictions concerning product categories, minimum spend and use of the vouchers in radio, app and in-store advertising, only on the receipt, the website or in-store notices. UOKiK imposed a fine of 104,722,016 PLN; the decision is not final.

What organisations can take from it

State the essential restrictions of a promotion in the advertising itself, not just on the receipt.

Relevance to training and awareness

Complete promotion terms in advertising

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Verletzung kollektiver Verbraucherinteressen (irreführende Werbung durch Unterlassen)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Culpability
intentional
Published
4 Dec 2025

Original amount 104,722,016 PLN, converted at the ECB reference rate of 4 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Dec 2025 Gracetown, Inc.OFAC: USD 7.14 million penalty on Gracetown over payments for a blocked company and failure to file a blocking report USABreaches of sanctions and embargoes €6.12m

OFAC has imposed a penalty of USD 7,139,305 on New York property management company Gracetown, Inc. by way of a Penalty Notice. According to OFAC's findings, between April 2018 and May 2020 Gracetown received 24 payments on behalf of an affiliated company owned by a sanctioned Russian oligarch, although OFAC had previously given it explicit notice of the prohibition. Gracetown also failed to report the blocked property to OFAC for more than 45 months. OFAC regarded the violations as wilful or at least reckless, egregious and not voluntarily self-disclosed; the base penalty equalled the statutory maximum of USD 8,906,358. OFAC's publication does not state whether Gracetown has paid the penalty or challenged it in court. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "OFAC Imposes $7,139,305 Penalty on Gracetown, Inc. for Violating Ukraine-/Russia-Related Sanctions and Reporting Obligations", 4 December 2025, https://ofac.treasury.gov/media/934796/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Ukraine-/Russia-Related Sanctions Regulations, 31 C.F.R. § 589.201; Reporting, Procedures and Penalties Regulations, 31 C.F.R. § 501.603 (Sperrmeldung); Penalty Notice nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Published
4 Dec 2025

Original amount 7,139,305 USD, converted at the ECB reference rate of 4 Dec 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Dec 2025 Southern Health Solutions, Inc. (Next Medical / NextMed)NextMed: FTC settlement over allegations of hidden costs and review manipulation USAFake reviews €128,557

According to the FTC, the telemedicine company advertised GLP-1 weight-loss programmes with monthly prices that did not include medication, laboratory costs and medical consultations, concealed the minimum term and cancellation fees, published fake testimonials from employees and relatives, and induced customers to delete negative reviews by offering vouchers or refunds. Under the final settlement order, the company and its management are paying 150,000 USD, which is earmarked for refunds.

What organisations can take from it

"Buying off" negative reviews with vouchers is just as misleading as inventing positive ones.

Relevance to training and awareness

Review manipulation and price disclosures

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Section 5 FTC Act; Restore Online Shoppers' Confidence Act (ROSCA)
Action
Disgorgement of profits
Status of proceedings
final
Sector
Healthcare
Liability of senior managers
Founder Robert Epstein and CEO Frank Leonardo III are named in the press release as parties involved.
Published
3 Dec 2025

Original amount 150,000 USD, converted at the ECB reference rate of 3 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Dec 2025 The Boeing Company und Spirit AeroSystems Holdings, Inc.Boeing/Spirit AeroSystems: takeover only with divestiture of Airbus supplier plants USAMerger control Order

For the 8.3 billion USD takeover of the fuselage and wing supplier Spirit AeroSystems, the Federal Trade Commission (FTC) required Boeing to divest Spirit’s Airbus businesses to Airbus and the plant in Subang, Malaysia, to CTRM, to provide transitional services and to continue supplying defence competitors. A monitor oversees implementation.

What organisations can take from it

Vertical acquisitions of a supplier on which competitors also depend often only go through with divestitures and supply commitments.

Authority / court
Federal Trade Commission (FTC)
Area of law
Competition law · Merger control
Legal basis
Section 7 Clayton Act; Section 5 FTC Act (Consent Order)
Action
Order
Status of proceedings
unknown
Sector
Defence and security
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 IPI Partners, LLCPrivate equity firm IPI held oligarch's funds for four years after designation USABreaches of sanctions and embargoes €9.89m

In 2017/2018, the Chicago fund manager specialising in data centres took in capital from the Russian oligarch Suleiman Kerimov via nested structures and continued to manage this investment for four years after his designation in April 2018. The US Treasury's Office of Foreign Assets Control (OFAC) assessed the case as non-egregious and not voluntarily self-disclosed.

What organisations can take from it

Screen investors through to the beneficial owner and re-check them when new designations occur – nested structures do not protect against liability.

Relevance to training and awareness

Checking beneficial owners of investors and fund structures

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Ukraine-/Russia-Related Sanctions Regulations (31 C.F.R. part 589); IEEPA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
No prior violations in five years; cooperation improved significantly only after initially insufficient engagement (including waiver of attorney-client privilege), hence only limited credit
Published
2 Dec 2025

Original amount 11,485,352 USD, converted at the ECB reference rate of 2 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 Post Office LimitedICO: reprimand for Post Office over publication of unredacted settlement deed United KingdomData breaches and data security Reprimand or warning

On 2 December 2025 the ICO issued a reprimand to Post Office Limited. The ICO found that on 25 April 2024 the company put the unredacted version of a settlement deed on its corporate website instead of the intended redacted one, exposing personal data of 502 postmasters who had taken part in the 2017 group litigation linked to the Horizon IT scandal. The ICO concluded that appropriate technical and organisational measures were lacking, in breach of Articles 5(1)(f), 32(1) and 32(2) UK GDPR. No fine was imposed.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5(1)(f), 32(1) und 32(2) UK GDPR; Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Transport, logistics and shipping

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts EU levelData subject rights and transparency —

On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.

What organisations can take from it

Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.

Authority / court
Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
Status of proceedings
unknown
Sector
Media and online platforms
Published
2 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Dec 2025 British exporter pays 620,515 GBP for unlicensed exports of military goods United KingdomExport control and dual-use goods €706,898

In September 2025, an unnamed British exporter paid a compound settlement of 620,515.04 GBP to HM Revenue & Customs (HMRC) for unlicensed exports of military goods. HMRC offers such settlements only for unintentional breaches or weaknesses in internal controls and following voluntary disclosure (date = publication).

What organisations can take from it

Weaknesses in internal export control become expensive even without intent – disclosing breaches early can avoid prosecution.

Relevance to training and awareness

Classification of goods and licensing requirements for military goods

Authority / court
HM Revenue & Customs (HMRC) / Export Control Joint Unit
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Control Order 2008
Action
Fine
Status of proceedings
final
Sector
Defence and security
Culpability
negligent
Mitigating circumstances
Voluntary disclosure (prerequisite for the compound settlement)
Published
1 Dec 2025

Original amount 620,515.04 GBP, converted at the ECB reference rate of 1 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Dec 2025 VIP Realty Inc.FINTRAC: CAD 33,000 penalty on VIP Realty Inc. for one violation of anti-money laundering obligations CanadaInternal controls €20,296

According to FINTRAC, VIP Realty Inc. is a real estate brokerage based in Ottawa, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 33,000 on the company on 1 December 2025. According to FINTRAC's findings, made during a compliance examination, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned the prescribed review of the compliance programme. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on VIP Realty Inc.", published 9 July 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-07-09-2-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Published
9 Jul 2026

Original amount 33,000 CAD, converted at the ECB reference rate of 1 Dec 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Dec 2025 SUROVINA d.o.o.; SALOMON d.o.o.; RECIKEL d.o.o.; DINOS d.o.o.Packaging waste: AVK finds market sharing by four waste management companies SloveniaCartels and collusion Order

In the reopened proceedings, the Javna agencija Republike Slovenije za varstvo konkurence (Slovenian Competition Protection Agency, AVK) found that the companies had shared the market for take-back schemes for packaging waste and agreed to stop providing their services to a competitor (now Interzero). The authority ordered immediate termination; the decision is not final, and an earlier decision from 2019 in the same matter is partly final.

What organisations can take from it

An agreement to stop supplying a common competitor is a cartel – even in regulated waste management markets.

Relevance to training and awareness

Boycott and market-sharing agreements

Authority / court
Javna agencija Republike Slovenije za varstvo konkurence (AVK)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 6 ZPOmK-1, Art. 101 AEUV (3062-5/2017)
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Published
16 Apr 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Nov 2025 Institute of Certified BookkeepersFCA: Public censure for Institute of Certified Bookkeepers over deficient AML supervision United KingdomMoney laundering and terrorist financing Reprimand or warning

The FCA, through its supervisor OPBAS, publicly censured the Institute of Certified Bookkeepers. The professional body is responsible for anti-money laundering supervision of more than 3,000 bookkeepers in the UK. The FCA found that between January 2022 and July 2023 it did not supervise its members effectively or on a risk basis; among other things it suspended inspections for more than nine months and did not keep adequate records of its supervision.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing
Legal basis
Regulation 16 Oversight of Professional Body AML and CTF Supervision Regulations 2017; Regulations 17 und 46 MLRs 2017
Action
Reprimand or warning
Status of proceedings
final
Sector
Other

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ FranceCookies and tracking €1.5m

When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.

What organisations can take from it

Cookie settings must apply across all domains of a service – including when users move to affiliated sites.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Corrections during the proceedings, cooperation.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 Manor Windsor Realty Ltd.FINTRAC: estate agent Manor Windsor Realty without AML training programme – 107,250 CAD CanadaInternal controls €65,907

The estate agency in Windsor (Ontario) received a penalty of 107,250 CAD from the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for four violations: no up-to-date, approved compliance policies, no assessment of the money laundering risk, no written ongoing training programme and no effectiveness review of the compliance programme. The company has appealed to the Federal Court.

What organisations can take from it

For estate agents, a missing written training programme is a separate violation subject to penalties.

Relevance to training and awareness

AML training programme for estate agents

Missing or inadequate training played a role in the decision.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
under appeal
Sector
Construction and real estate
Published
12 Feb 2026

Original amount 107,250 CAD, converted at the ECB reference rate of 27 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis BelgiumMarketing and consent €5,000

The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.

What organisations can take from it

Data brokers must be able to prove for every record on which legal basis it was collected and resold.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Nov 2025 SIA "EUROPARK LATVIA"Europark Latvia pays 25,000 EUR for payment reminders sent to outdated addresses LatviaData protection €25,000

Following several complaints, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined how the parking operator collects contractual penalties: invoices were sent to previous rather than current registered addresses, claims were handed over to debt collection services and entered in the database of Kredītinformācijas Birojs. The authority found breaches of the principles of lawfulness, data minimisation and confidentiality and of the accountability obligation and imposed 25,000 EUR (previous year’s turnover according to the decision: 8,323,178 EUR).

What organisations can take from it

Anyone collecting debts or reporting them to credit agencies must first ensure that address data are up to date.

Relevance to training and awareness

Data quality in receivables management

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection
Legal basis
Art. 5 Abs. 1 lit. a, c, f und Abs. 2, Art. 83 Abs. 5 lit. a DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Culpability
intentional
Mitigating circumstances
Practice changed after the proceedings began; contracts concluded with the population and vehicle registers (PMLP, CSDD)

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 Caesars Entertainment, Inc. / Desert Palace, LLC (Caesars Palace)Nevada: 7.8 million USD against Caesars over gambling by an illegal bookmaker USA, NVCustomer due diligence €6.77m

On 13 November 2025, the Nevada Gaming Control Board (NGCB) filed a disciplinary complaint for unsuitable methods of operation in connection with the illegal bookmaker Mathew Bowyer and at the same time concluded a settlement of 7.8 million USD with conditions attached to the gaming licences. The conditions relate primarily to improving the AML programme and to additional training and awareness-raising for employees; the Nevada Gaming Commission (NGC) adopted the settlement as its order on 20 November 2025 (Case No. 25-03).

What organisations can take from it

Casino staff must recognise high-risk players and unexplained sources of funds – revenue interests must not override AML obligations.

Relevance to training and awareness

Checking the source of gambling funds, recognising high-risk customers

Missing or inadequate training played a role in the decision.

Authority / court
Nevada Gaming Commission (NGC) auf Beschwerde des Nevada Gaming Control Board (NGCB)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Glücksspielrecht Nevada (unsuitable methods of operation)
Action
Fine
Status of proceedings
final
Sector
Other
Employees
10,000 or more
Mitigating circumstances
Numerous remedial measures already implemented
Published
13 Nov 2025

Original amount 7,800,000 USD, converted at the ECB reference rate of 20 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 LastPass UK LtdICO: £1.2 million against LastPass UK after breach of backup database United KingdomData breaches and data security €1.39m

In 2022, an attacker first compromised an employee's company laptop and then the personal laptop of a senior employee, whose master password he captured using a keylogger. Because the personal and business password vaults were linked via the same master password, he obtained the access and decryption keys stored there and stole data on up to 1.6 million UK users from the backup database.

What organisations can take from it

Never keep critical keys on employees' personal devices or in their personal accounts – access must be technically separated and restricted.

Relevance to training and awareness

Separation of personal and work devices and credentials

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 lit. f
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
11 Dec 2025

Original amount 1,228,283 GBP, converted at the ECB reference rate of 20 Nov 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent FranceCookies and tracking €750,000

On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.

What organisations can take from it

A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Published
27 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 MP Technology Services Ltd.FINTRAC: CAD 536,853.35 penalty on MP Technology Services Ltd. for 4 violations of anti-money laundering obligations CanadaSuspicious activity reports €331,514

According to FINTRAC, MP Technology Services Ltd. is an entity determined to be a foreign money services business operating in Canada. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 536,853.35 on the company on 20 November 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned international electronic funds transfer reporting, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks and suspicious transaction reporting. Specifically, FINTRAC found four unreported incoming international transfers and four unreported suspicious attempted transactions; policies and risk assessment were not tailored to Canadian requirements. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on MP Technology Services Ltd.", published 18 December 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-12-18-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9(1), 9.6(1), 9.6(2); PCMLTF Regulations 30(1)(c), 156(1)(b), 156(1)(c); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
18 Dec 2025

Original amount 536,853.35 CAD, converted at the ECB reference rate of 20 Nov 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Nov 2025 1135233 B.C. Ltd.FINTRAC: CAD 149,886 penalty on 1135233 B.C. Ltd. for 6 violations of anti-money laundering obligations CanadaSuspicious activity reports €92,557

According to FINTRAC, 1135233 B.C. Ltd. (operating as LeHomes Realty Premier) is a real estate brokerage based in Vancouver, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 149,886 on the company. Published by FINTRAC on 20 November 2025; decision date not published. According to FINTRAC's findings, the company committed 6 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, appointing a compliance officer, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme and client identification record keeping. According to FINTRAC, the company will pay the penalty in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on 1135233 B.C. Ltd.", published 20 November 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-11-20-3-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7; PCMLTF Regulations 39(1)(b), 71(1)(a), 71(1)(b), 71(1)(c), 71(1)(d); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Published
20 Nov 2025

Original amount 149,886 CAD, converted at the ECB reference rate of 20 Nov 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Nov 2025 Exodus Movement, Inc.OFAC: USD 3.1 million settlement with Exodus over customer support for users in Iran USABreaches of sanctions and embargoes €2.68m

US fintech Exodus Movement, Inc. is paying USD 3,103,360 under a settlement with OFAC for 254 apparent violations of the Iran sanctions. According to OFAC's findings, Exodus provided customer support to users in Iran and in some cases helped them access third-party crypto exchanges through its own wallet software. According to OFAC, on twelve occasions staff, despite being aware of the sanctions, advised users to hide their location via VPN in order to circumvent those exchanges' controls; OFAC treated these instances as egregious. The apparent violations were not voluntarily disclosed; the base penalty was USD 4,774,400. Extensive remediation and cooperation were taken into account. Exodus satisfies USD 630,000 of the settlement amount by investing in additional sanctions controls; USD 2,473,360 is payable to the Treasury. OFAC signed the settlement agreement on 19 November 2025 and published it on 16 December 2025. According to the settlement agreement, the settlement does not constitute an admission by Exodus of the apparent violations. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "Exodus Movement, Inc. Settles with OFAC for $3,103,360 for Apparent Violations of Iran-related Sanctions Regulations", 16 December 2025, https://ofac.treasury.gov/media/934831/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204 (254 mutmaßliche Verstöße), in 12 Fällen zusätzlich § 560.203 (Umgehung); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
16 Dec 2025

Original amount 3,103,360 USD, converted at the ECB reference rate of 19 Nov 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Nov 2025 Betreibergesellschaft des Onlineshops About You (Sitz Hamburg; in der Mitteilung nicht namentlich genannt)About You: 505 million HUF fine and compensation for countdown pressure and discount claims HungaryMisleading advertising and pricing €1.32m

The fashion mail-order company presented discounts in a misleading manner and exerted psychological pressure with countdowns running down by the second and scarcity notices. In addition to a fine of 505 million HUF imposed by the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH), the Hamburg-based operating company committed to paying compensation of 1,750 HUF each to all Hungarian customers who made purchases between 31 December 2022 and 31 December 2024 (estimated at over 500 million HUF) and to a consumer protection compliance programme.

What organisations can take from it

Countdown timers and scarcity banners must be true – otherwise they are prohibited purchasing pressure.

Relevance to training and awareness

Dark patterns and price information in online shops

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Verbot unlauterer Geschäftspraktiken gegenüber Verbrauchern
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Acknowledgement, cooperation, customer compensation and compliance programme almost halved the fine.
Published
19 Nov 2025

Original amount 505,000,000 HUF, converted at the ECB reference rate of 19 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Nov 2025 Firemount Group Ltd.CBP stops clothing from Firemount Group in Mauritius USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: clothing and textiles from Firemount Group Ltd. (Mauritius) are being detained at all US ports of entry because there are indications of forced labour (ILO indicators including abuse of vulnerability, debt bondage, deception, and intimidation and threats).

What organisations can take from it

Suppliers outside traditional high-risk countries must also be checked for their recruitment practices for foreign workers.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Other
Published
18 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Nov 2025 TotalEnergies Marketing France, Rubis Énergie, Rubis Terminal, EG RetailFrance: 187.5 million EUR against fuel suppliers over depot agreement in Corsica FranceCartels and collusion €187.5m

Between 2016 and 2023, the shareholders of the Corsican fuel storage company DPLC made the use of the depots conditional on a shareholding by means of a contractual clause; non-shareholders had to buy their fuel from their competitors, which could push up pump prices in Corsica (decision 25-D-07). Fines: TotalEnergies Marketing France 115.82 million EUR, Rubis 64.67 million EUR, EG Retail 7 million EUR.

What organisations can take from it

Shared infrastructure of competitors must be open to third parties on fair terms – shareholder agreements should be reviewed under competition law.

Relevance to training and awareness

Joint ventures of competitors and access conditions for third parties

Authority / court
Autorité de la concurrence
Area of law
Competition law · Cartels and collusion
Legal basis
Art. L.420-1 Code de commerce, Art. 101 AEUV
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities
Employees
10,000 or more
Published
17 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses CroatiaInternational data transfers €4.5m

The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.

What organisations can take from it

Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Valvoline Inc. und Greenbriar Equity Fund V, L.P.Valvoline/Greenbriar: FTC requires sale of 45 quick oil change shops USAMerger control Order

Valvoline wanted to acquire around 200 Oil Changers shops from Greenbriar for 625 million USD. Because the two competed directly in 25 local markets, under the proposed consent order the acquisition may only be completed if 45 shops are sold to Main Street Auto.

What organisations can take from it

For branch networks too, the competition authority examines each local market individually – map overlaps before the deal.

Authority / court
Federal Trade Commission (FTC)
Area of law
Competition law · Merger control
Legal basis
Section 7 Clayton Act; Section 5 FTC Act (Consent Order)
Action
Order
Status of proceedings
unknown
Sector
Automotive

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Nov 2025 BSG: company car does not replace the minimum wage – additional contribution claims upheld GermanyMinimum wage and undeclared work Order

Two employers remunerated part-time workers solely by providing a company car. Germany's Federal Social Court (Bundessozialgericht, BSG) upheld the German pension insurance's claims for additional contributions: the benefit in kind does not satisfy the minimum wage entitlement, and contributions must be paid on the minimum wage owed (B 12 BA 8/24 R, B 12 BA 6/23 R).

What organisations can take from it

Remuneration models involving benefits in kind should be checked for minimum wage compliance before they are introduced – otherwise additional contribution claims going back years may follow.

Relevance to training and awareness

Minimum wage in money only – benefits in kind in payroll

Authority / court
Bundessozialgericht, 12. Senat (Betriebsprüfung: Deutsche Rentenversicherung Bund)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
§ 1 MiLoG; § 28p SGB IV (Betriebsprüfung)
Action
Order
Status of proceedings
final
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2025 Comunicaciones Celulares S.A. (TIGO Guatemala)TIGO Guatemala pays more than 118 million USD for bribing members of Congress USABribery of public officials €102.1m

From 2012 to 2018, the Guatemalan mobile network operator made monthly cash payments to members of Congress or their security staff in order to obtain legislative support; part of the funds came from laundered drug money. Two-year Deferred Prosecution Agreement with a criminal penalty of 60 million USD and administrative forfeiture of 58,198,343 USD.

What organisations can take from it

In joint ventures with local partners, the parent company needs genuine control over cash flows and contacts with public officials – an early voluntary self-disclosure is no substitute for a full investigation.

Relevance to training and awareness

Bribery of public officials, cash payments, integrity of co-shareholders

Authority / court
U.S. Department of Justice (Criminal Division, Fraud Section; USAO Southern District of Florida)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA, 15 U.S.C. § 78dd-3 (Verschwörung, 18 U.S.C. § 371); Deferred Prosecution Agreement
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure by the parent company Millicom in 2015; subsequently extensive cooperation and remediation (including dismissals of staff and an 800 % increase in compliance personnel).
Liability of senior managers
According to the DOJ, the scheme was directed by the then Guatemalan shareholder and other senior individuals; four individuals had already been charged (not named).
Published
12 Dec 2025

Original amount 118,198,343 USD, converted at the ECB reference rate of 12 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Nov 2025 Avida Finans ABAvida Finans: 20 million SEK for loans to consumers unable to repay SwedenConsumer protection and online retail €1.82m

The Swedish financial supervisory authority Finansinspektionen (FI) examined consumer loans granted by the lender over four weeks in summer 2024 and found at least around 30 cases in which consumers without the ability to repay received loans. FI issued a remark and imposed 20 million SEK.

What organisations can take from it

Carry out credit checks consistently even under sales pressure and verify them internally through sample checks.

Relevance to training and awareness

Creditworthiness assessment in sales

Authority / court
Finansinspektionen (FI)
Area of law
Consumer protection and online retail
Legal basis
Konsumentkreditlagen (2010:1846), Kreditprüfung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Nov 2025

Original amount 20,000,000 SEK, converted at the ECB reference rate of 11 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Nov 2025 Devro (Scotland) LimitedDevro (Scotland): 48,000 GBP fine for discharging industrial wastewater into burn United KingdomEmissions and permits €58,610

In July 2021, a blockage in the foul sewer at the Moodiesburn plant (collagen casings for sausages) caused untreated industrial wastewater to back up into the surface water system, polluting the Bothlin Burn with ammonia and organic load. The company pleaded guilty on 11 November 2025; on 24 March 2026, the Scottish Environment Protection Agency (SEPA) reported a fine of 48,000 GBP plus a 3,600 GBP victim surcharge.

What organisations can take from it

On-site drainage needs monitoring and maintenance so that faults in the foul sewer do not reach watercourses via surface water pipes.

Authority / court
Airdrie Sheriff Court (Ermittlungen: SEPA, Anklage: Crown Office and Procurator Fiscal Service)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Regulations 4 und 44(1)(a) Water Environment (Controlled Activities) (Scotland) Regulations 2011; Section 20(3)(a) Water Environment and Water Services (Scotland) Act 2003
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Published
24 Mar 2026

Original amount 51,600 GBP, converted at the ECB reference rate of 11 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Nov 2025 Bank of Scotland PLCOFSI: GBP 160,000 penalty for Bank of Scotland over payments through a designated person's account United KingdomBreaches of sanctions and embargoes €182,274

On 10 November 2025 OFSI imposed a monetary penalty of GBP 160,000 on Bank of Scotland PLC; without the 50 per cent discount for voluntary disclosure it would have been GBP 320,000, according to OFSI. According to OFSI's findings, between 8 and 24 February 2023 the bank processed 24 payments totalling GBP 77,383.39 through the account of a person designated under Russia sanctions, including credits of GBP 76,000. According to OFSI, screening failed to pick up a variant of the name, and a human error occurred during a PEP review on 20 February 2023. The notice of intent of 28 August 2025 had proposed GBP 175,000. The bank did not request a ministerial review. Source: Office of Financial Sanctions Implementation (OFSI), HM Treasury, "Imposition of monetary penalty: Bank of Scotland PLC", 26 January 2026, https://www.gov.uk/government/publications/imposition-of-monetary-penalty-bank-of-scotland-plc. Contains public sector information licensed under the Open Government Licence v3.0 (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/).

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, reg. 11, 12; Geldbuße nach s. 146 Policing and Crime Act 2017
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
26 Jan 2026

Original amount 160,000 GBP, converted at the ECB reference rate of 10 Nov 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Nov 2025 DoctolibFrance: 4.665 million EUR against Doctolib for abuse in doctor appointment booking FranceAbuse of market power €4.67m

Doctolib tied doctors with exclusivity clauses, bundled telemedicine with the appointment booking subscription and in 2018 acquired its main competitor MonDocteur in order to eliminate it (decision 25-D-06). Fines: 4.615 million EUR for exclusivity and tying, 50,000 EUR for the acquisition.

What organisations can take from it

Platforms with high market shares should have exclusivity clauses, bundled offers and acquisitions of rivals reviewed under competition law.

Authority / court
Autorité de la concurrence
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV, Art. L.420-2 Code de commerce
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Culpability
intentional
Published
6 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Nov 2025 UAB „Emsi“Emsi took over four filling stations without merger clearance – 1.02 million EUR LithuaniaMerger control €1.02m

In 2024, Emsi acquired control of four filling stations in Kaunas, Vilnius and Maišiagala through leases (via an affiliated company) and purchases without obtaining the required clearances, ignoring previous notices from the Konkurencijos taryba (Lithuanian Competition Council). For two concentrations, fines of 545,160 EUR and 477,010 EUR were imposed, a total of 1,022,170 EUR, together with an obligation to remedy the situation within three months. Source: archived copy of the press release.

What organisations can take from it

Even the long-term lease of individual sites may require notification – if in doubt, ask the authority beforehand.

Relevance to training and awareness

Merger control also for leases of individual sites

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Merger control
Legal basis
Konkurencijos įstatymas (Anmelde- und Genehmigungspflicht für Zusammenschlüsse)
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
6 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Nov 2025 Lead Pronto LtdICO: £30,000 fine for Lead Pronto over marketing texts about boiler grants United KingdomMarketing and consent €34,064

The ICO fined Lead Pronto Ltd £30,000 and issued an enforcement notice. The ICO found that the company had sent unsolicited text messages promoting government-funded boiler grants. The ICO found a serious breach of regulation 22 of PECR (electronic marketing without consent).

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulation 22 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 30,000 GBP, converted at the ECB reference rate of 6 Nov 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Nov 2025 Coinbase Europe LimitedIreland: 21.5 million EUR against Coinbase Europe – 30 million transactions unchecked IrelandInternal controls €21.5m

In a settlement of 5 November 2025, the Central Bank of Ireland imposed a reprimand and 21,464,734 EUR (after a 30% discount on 30,663,906 EUR) for breaches of transaction monitoring obligations between April 2021 and March 2025: because of configuration errors in the monitoring system, more than 30 million transactions worth over 176 billion EUR – around 31% of all transactions – were not properly monitored over a period of twelve months. The subsequent review took almost three years and led to 2,708 suspicious transaction reports; the High Court confirmed the sanction on 12 January 2026, and it is the Central Bank's first enforcement action in the crypto sector.

What organisations can take from it

Test monitoring rules regularly for complete coverage – a silent configuration error can go undetected for years.

Authority / court
Central Bank of Ireland
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Published
6 Nov 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Nov 2025 Groupe ParfaitFrance: 7.6 million EUR against Groupe Parfait for failing to meet merger remedies (Martinique) FranceMerger control €7.6m

In 2022, clearance of an acquisition in food retail in Martinique was made conditional on the divestiture of a Géant Casino hypermarket by September 2023; Parfait only sold it in September 2025, allowed the value of the assets to deteriorate and obstructed the trustee (decision 25-D-05). Fines: 4.5 million EUR (divestiture), 2.5 million EUR (preservation of value), 600,000 EUR (cooperation).

What organisations can take from it

Merger control commitments are binding – missed deadlines and a lack of cooperation with the trustee are sanctioned separately.

Relevance to training and awareness

Compliance with merger remedies and cooperation with trustees

Authority / court
Autorité de la concurrence
Area of law
Competition law · Merger control
Legal basis
Verstoß gegen Zusagen aus Freigabeentscheidung 22-DCC-254 (Fusionskontrolle, Code de commerce)
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce
Published
3 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Oct 2025 Google LLCTexas: Google pays $1.375 billion over location, incognito and biometric data USA, TXCookies and tracking €1.19bn

Texas, represented by the Office of the Attorney General, had sued Google for unlawfully collecting location data, activity in incognito mode and biometric identifiers. Google signed a settlement of $1.375 billion, concluding two sets of proceedings.

What organisations can take from it

Settings such as location history or incognito mode must deliver what they promise users – otherwise billion-dollar risks loom, even at the level of individual US states.

Authority / court
Office of the Attorney General of Texas
Area of law
Data protection · Cookies and tracking
Action
Other
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
31 Oct 2025

Original amount 1,375,000,000 USD, converted at the ECB reference rate of 31 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Oct 2025 "MAXIMA Latvija" SIAMaxima Latvija pays 1.87 million EUR for price pressure on food suppliers LatviaAbuse of market power €1.87m

From November 2021 to August 2024, the retailer (market share 28%) put pressure on economically dependent suppliers: price increases remained unapproved for months, lower prices were demanded in the form of ultimatums and delisting was threatened. The Konkurences padome (Latvian Competition Council) found an unfair trading practice, imposed 1,872,805 EUR and set clear deadlines for negotiations.

What organisations can take from it

Purchasing departments of retailers with strong market power need clear rules for price negotiations – threats of delisting are off limits.

Relevance to training and awareness

Fair purchasing negotiations with suppliers

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law · Abuse of market power
Legal basis
Negodīgas tirdzniecības prakses aizlieguma likums (NTPAL)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
5 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Oct 2025 MM Grupp OÜCinema chain MM Grupp (Apollo) took over Forum Cinemas without clearance – 7.5 million EUR LithuaniaMerger control €7.51m

In 2021, the Estonian parent company of Apollo cinemas acquired control of Forum Cinemas Lithuania before the notified merger had been cleared and integrated the cinemas in Vilnius and Kaunas into its network, even though the Konkurencijos taryba (Lithuanian Competition Council) had provisionally expressed competition concerns. Fine of 7,507,930 EUR (0.8% of consolidated worldwide turnover) and obligation to end the infringement within six months. Source: archived copy of the press release.

What organisations can take from it

No implementation before clearance: restructurings and leases can also constitute prohibited early implementation.

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Merger control
Legal basis
Konkurencijos įstatymas (Vollzugsverbot bei Zusammenschlüssen)
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
30 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Oct 2025 ExxonMobil Chemical LimitedExxonMobil Chemical: 176,000 GBP fine for six days of continuous flaring in Fife United KingdomEmissions and permits €200,913

Following a loss of steam in April 2019, the ethylene plant in Fife flared for almost a week; the smoke significantly exceeded permit limits, and the Scottish Environment Protection Agency (SEPA) received over 900 complaints. Existing procedures and emergency plans should have prevented the incident but were not adequately followed. The company pleaded guilty and was fined 176,000 GBP.

What organisations can take from it

Emergency plans only protect if staff apply them consistently in an emergency – regular drills are part of permit compliance.

Relevance to training and awareness

Compliance with operating and emergency procedures in industrial plants

Authority / court
Kirkcaldy Sheriff Court (Ermittlungen: Scottish Environment Protection Agency, SEPA)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Regulation 67(1)(b) Pollution Prevention and Control (Scotland) Regulations 2012; Section 2 Pollution Prevention and Control Act 1999
Action
Fine
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more
Culpability
negligent
Published
28 Oct 2025

Original amount 176,000 GBP, converted at the ECB reference rate of 28 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Oct 2025 Landesbank Hessen-Thüringen Girozentrale (Helaba)BaFin: fine against Helaba over inadequate monitoring systems for money laundering prevention GermanyInternal controls €20,000

By decision of 28 October 2025 (final since 7 November 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 20,000 EUR because, from October 2022 to September 2023, the Landesbank operated data processing systems for money laundering prevention that were only partially adequate. Under the German Banking Act (KWG), the criteria by which monitoring identifies suspicious transactions must be documented, and the systems must be checked regularly by an independent auditor.

What organisations can take from it

Transaction monitoring needs documented indicators and a regular independent quality review – the mere existence of software is not enough.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
§ 56 Abs. 2 Nr. 11b KWG (Betrieb angemessener Datenverarbeitungssysteme zur Geldwäscheprävention)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
10 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Oct 2025 SINOP ALFA, s.r.o.SINOP ALFA: 70,000 EUR for refusing to hand over business mobile phone during inspection SlovakiaCompetition law €70,000

During an unannounced inspection in the air-conditioning, refrigeration and heat pump services sector, the company repeatedly refused to produce a mobile phone used for business purposes. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) regarded this as obstruction of the inspection and imposed 70,000 EUR, around 1% of the previous year’s turnover (not final).

What organisations can take from it

Business smartphones are part of the documents that may be inspected – a dawn raid guide for employees prevents costly wrong reactions.

Relevance to training and awareness

Conduct during inspections (dawn raids), handing over mobile devices

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Mitwirkungspflicht bei Nachprüfungen)
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
intentional
Published
28 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 TFG Holding, Inc.JustFab, ShoeDazzle, FabKids: 4.8 million USD settlement with 33 attorneys general over VIP membership USA, PAInformation duties in online retail €4.14m

According to the allegations of the attorneys general, the online fashion retailer enrolled buyers in a paid VIP membership programme without their express consent, presented prices in a misleading way and made cancellation difficult. Under the settlement with 32 states and D.C., TFG is providing around 3.8 million USD in automatic refunds and paying 1 million USD to the states; the settlement does not constitute an admission of guilt.

What organisations can take from it

A purchase must not silently trigger a membership with monthly charges.

Relevance to training and awareness

Subscription models and express consent at checkout

Authority / court
Attorney General of Pennsylvania (verhandelt mit Maryland, Texas und D.C.; Vergleich mit 33 Attorneys General)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Verbraucherschutzgesetze der beteiligten Bundesstaaten
Action
Disgorgement of profits
Status of proceedings
final
Sector
Retail and e-commerce
Published
23 Oct 2025

Original amount 4,800,000 USD, converted at the ECB reference rate of 23 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login FinlandData breaches and data security €865,000

Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.

What organisations can take from it

Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
28 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees ItalyVideo surveillance €15,000

The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).

What organisations can take from it

Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.

Relevance to training and awareness

Purpose limitation in video surveillance and employee data

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 5, 6, 12, 13, 35, 88
Action
Fine
Status of proceedings
final
Sector
Public sector
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified PolandIncident reporting obligations €4,938

In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.

What organisations can take from it

Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.

Relevance to training and awareness

Checking postal mailings; notifying data breaches involving identification numbers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 TotalEnergies; TotalEnergies Electricité et Gaz de FranceParis Judicial Court: TotalEnergies advertising on climate neutrality misleading FranceMisleading environmental and sustainability claims Order

In an action brought by Greenpeace France, Les Amis de la Terre and Notre Affaire à Tous, the Paris Judicial Court (Tribunal judiciaire de Paris, 34th chamber) found that TotalEnergies had advertised on totalenergies.fr with the goal of ‘carbon neutrality by 2050’ and its role as a player in the energy transition without disclosing that oil and gas production continues to be expanded – a misleading commercial practice. The court ordered the communication to cease, damages to be paid to the associations and the operative part of the judgment to be published on the website (RG 22/02955); claims relating to gas and agrofuels were dismissed.

What organisations can take from it

Net-zero targets may only be advertised to consumers with reference to the actual business strategy.

Relevance to training and awareness

Climate targets in consumer communication

Authority / court
Tribunal judiciaire de Paris (34. Kammer)
Area of law
Environment and sustainability · Misleading environmental and sustainability claims
Legal basis
Art. L121-1 ff. Code de la consommation (Umsetzung der Richtlinie 2005/29/EG)
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Employees
10,000 or more
Published
23 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Oct 2025 Gate GourmetTribunal: Gate Gourmet files no response – £20,000 to whistleblower United KingdomRetaliation against whistleblowers €23,018

Because Gate Gourmet failed to file a response to the claim despite repeated requests, the Manchester Employment Tribunal found that there had been detriment on grounds of a protected disclosure and in January 2026 awarded £15,000 for loss of earnings and £5,000 for injury to feelings. An application for reconsideration, based on an email inbox that was no longer monitored, was refused.

What organisations can take from it

Correspondence from authorities and courts must go to monitored addresses – missed deadlines turn a defensible claim into a default judgment.

Relevance to training and awareness

Managing deadlines and incoming mail in litigation

Authority / court
Employment Tribunal
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Employment Rights Act 1996, s. 47B (Benachteiligung wegen geschützter Offenlegung); Employment Tribunal Procedure Rules 2024, Rule 22
Action
Other
Status of proceedings
unknown
Sector
Food and agriculture
Published
7 Jan 2026

Original amount 20,000 GBP, converted at the ECB reference rate of 22 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Oct 2025 Winsor Maintenance Inc., Main Source Group, Inc. u. a. sowie OptumCare Management LLC (Auftraggeberin)Cleaning companies/OptumCare: 438,204 USD – overtime and missed breaks USA, CAWorking time €377,534

More than 90 cleaners in industrial, laboratory and healthcare facilities often worked beyond scheduled hours without overtime pay, received no compensation for split shifts and travel time and were unable to take breaks because of excessive workloads. A web of companies owned by the Hong family concealed the employer; the Notice of Final Findings of 21 October 2025 established 438,204 USD, with OptumCare jointly liable as the client.

What organisations can take from it

Clients of cleaning and service providers should check working hours and breaks at the provider – otherwise they are jointly liable.

Authority / court
California Labor Commissioner's Office (Division of Labor Standards Enforcement)
Area of law
Health and safety and employment law · Working time
Legal basis
California Labor Code § 2810.3; Overtime, Split Shift, Meal and Rest Periods, Mindestlohn
Action
Other
Status of proceedings
unknown
Sector
Other
Liability of senior managers
Members of the owning family and an acquaintance cited personally.
Published
24 Nov 2025

Original amount 438,204 USD, converted at the ECB reference rate of 21 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Oct 2025 Taxshelter.be SATaxshelter.be: 75,000 EUR for missing prospectus supplement on guarantee risks BelgiumDisclosure and reporting obligations €75,000

After the tax authority had refused the tax shelter certificates for a financed show and the insurer left cover open, the provider failed to inform investors of this material risk in good time by means of a prospectus supplement. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 75,000 EUR with publication by name.

What organisations can take from it

New material risks for investors trigger an immediate obligation to publish a supplement – not only in the next annual prospectus.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Verordnung (EU) 2017/1129 Art. 23; Loi du 11 juillet 2018 (Loi Prospectus)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
21 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Oct 2025 Griffin Jewellery Designs Inc.FINTRAC: CAD 77,137.50 penalty on Griffin Jewellery Designs Inc. for 3 violations of anti-money laundering obligations CanadaInternal controls €47,055

According to FINTRAC, Griffin Jewellery Designs Inc. is a dealer in precious metals and stones. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 77,137.50 on the company on 17 October 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks and the prescribed review of the compliance programme. According to FINTRAC, the company is paying the penalty in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Griffin Jewellery Designs Inc.", published 4 December 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-12-04-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1), 9.6(2); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Published
4 Dec 2025

Original amount 77,137.5 CAD, converted at the ECB reference rate of 17 Oct 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Oct 2025 WhatsApp Ireland Limited (Dienst „Channels“) und PinterestWhatsApp (Channels) and Pinterest: designated as ‘exposed to terrorist content’ IrelandPlatform obligations Order

After both hosting services had received at least two final removal orders from EU authorities within twelve months, Coimisiún na Meán (Ireland’s media and online safety regulator) designated them as exposed to terrorist content under the TCO Regulation. They must take specific protective measures and report on them within three months; the regulator assesses their effectiveness.

What organisations can take from it

Repeated removal orders trigger additional, monitored prevention obligations for platforms – content moderation must be prepared for this.

Authority / court
Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Oct 2025 Xeltox Enterprises Ltd. (Cryptomus)FINTRAC: record penalty of 177 million CAD against crypto payment service Cryptomus CanadaSuspicious activity reports €108.1m

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 176,960,190 CAD on the crypto payment service registered in British Columbia. In July 2024 alone, 1,068 suspicious transaction reports were not filed – including on transactions linked to child sexual abuse material, fraud, ransomware and sanctions evasion – as well as 1,518 reports of large virtual currency transactions; in addition, there were violations of a ministerial directive and a lack of policies and risk assessment. The company has appealed to the Federal Court.

What organisations can take from it

Crypto services without a functioning reporting system are sanctioned per report not filed – the total can threaten their existence.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
22 Oct 2025

Original amount 176,960,190 CAD, converted at the ECB reference rate of 16 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Oct 2025 Capita plc und Capita Pension Solutions LimitedICO: £14 million against Capita after ransomware attack affecting 6.6 million people United KingdomData breaches and data security €16.1m

In March 2023, an employee unintentionally downloaded malicious files; although an alert was triggered after ten minutes, the device was only isolated after 58 hours. Attackers stole around one terabyte of data on 6.6 million people (including pension data and criminal record information). Fines imposed by the UK Information Commissioner's Office (ICO): £8 million against Capita plc and £6 million against Capita Pension Solutions.

What organisations can take from it

Security alerts need binding response times and an adequately staffed SOC – known vulnerabilities must be remedied across the group.

Relevance to training and awareness

Handling malicious downloads and security alerts

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32
Action
Fine
Status of proceedings
final
Sector
Other
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
£45 million had provisionally been proposed; reduced, among other things, for security improvements, credit monitoring for those affected and cooperation with authorities and the NCSC.
Published
15 Oct 2025

Original amount 14,000,000 GBP, converted at the ECB reference rate of 15 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Oct 2025 Zimpler ABZimpler: 3 million SEK over anti-money laundering deficiencies at gambling-related payment service SwedenCustomer due diligence €272,245

Between July 2023 and April 2024, the payment service provider, a substantial part of whose business is linked to the gambling sector, had gaps in its general risk assessment (including a missing assessment of its currency exchange service), in its customer risk assessment and in customer due diligence. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 3 million SEK.

What organisations can take from it

Include every new product – even an ancillary service such as currency exchange – in the money laundering risk assessment before launch.

Relevance to training and awareness

Money laundering risks in the gambling environment

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
15 Oct 2025

Original amount 3,000,000 SEK, converted at the ECB reference rate of 15 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools USA, NYSecurity measures and risk management €2.4m

Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.

What organisations can take from it

Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent
Published
14 Oct 2025

Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late USA, NYIncident reporting obligations €1.95m

Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.

What organisations can take from it

Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
23 NYCRR § 500.17(a), § 500.12(a) u. a.
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Oct 2025 AS Inbank FinanceOrder against Inbank Finance over deficiencies in creditworthiness assessment EstoniaConsumer protection and online retail Order

During an inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) found that Inbank Finance’s internal rules on assessing the creditworthiness of consumers did not fully comply with the law and that the assessment itself showed deficiencies. It issued an order requiring the company to remedy the deficiencies by mid-December. Date = publication.

What organisations can take from it

Creditworthiness assessments must be documented, rule-based and actually applied in day-to-day business.

Relevance to training and awareness

Responsible lending in sales

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail
Legal basis
Gesetz über Kreditgeber und -vermittler (KAVS), verantwortungsvolle Kreditvergabe
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance
Published
14 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 J.P. Morgan SEBaFin: 45 million EUR against J.P. Morgan SE over late suspicious activity reports GermanySuspicious activity reports €45m

By decision of 13 October 2025 (final since 30 October 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 45 million EUR on J.P. Morgan SE because the institution had culpably breached its duty of supervision in the internal processes for filing money laundering suspicious activity reports; from 4 October 2021 to 30 September 2022, suspicious activity reports were systematically not filed on time. BaFin points out that, in the case of systematic infringements, the amount of the fine can be based on the institution's total turnover.

What organisations can take from it

File suspicious activity reports without delay – systematic backlogs in the reporting process are themselves an infringement, and the fine can then be calculated on the basis of the institution's total turnover.

Relevance to training and awareness

Filing money laundering suspicious activity reports without delay

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
§ 130 Abs. 1 OWiG (Aufsichtspflichtverletzung) i. V. m. Pflichten nach dem GwG (Verdachtsmeldungen); Bekanntmachung nach § 57 Abs. 1 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Published
6 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Wonderinterest Trading LtdCyprus: 100,000 EUR against Wonderinterest Trading over misleading client information CyprusOrganisational requirements €100,000

For 2022 to 2024, the Cyprus Securities and Exchange Commission (CySEC) found that the investment firm had no adequate compliance procedures, did not define target markets for its financial instruments, did not act in the best interests of clients and did not inform clients in a fair, clear and not misleading manner. It imposed fines of 50,000, 30,000 and 20,000 EUR; a judicial review of the decision has been recorded.

What organisations can take from it

Advertising statements by financial service providers must present risks in a balanced way – marketing belongs in the compliance approval process.

Relevance to training and awareness

Fair and not misleading marketing communications

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Sec. 17(2), 17(3)(c), 22(1), 25(1), 25(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 22, 44 Delegierte VO (EU) 2017/565
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers SpainData subject rights and transparency €17,600

The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.

What organisations can take from it

New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Mitigating circumstances
Partial immediate payment (20% reduction under Art. 85 LPACAP).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients EstoniaData subject rights and transparency Order

Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.

What organisations can take from it

Access requests concerning health data require a fixed procedure with deadlines – in small practices too.

Relevance to training and awareness

Handling access requests from patients

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 BlueCrest Capital Management (UK) LLPFCA: Public censure for BlueCrest over conflicts between internal and external funds United KingdomOrganisational requirements Reprimand or warning

The FCA publicly censured BlueCrest Capital Management (UK) LLP. Between October 2011 and December 2015 BlueCrest managed external funds for investors as well as an internal fund open only to partners and staff. The FCA found that portfolio managers were moved from the external to the internal fund without the resulting conflict of interest being managed adequately, leaving external investors with an inferior service. Instead of a fine, the FCA took into account BlueCrest's agreement to pay USD 101 million in redress to non-US investors.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
FCA Principle 8 (Interessenkonflikte); section 205 FSMA 2000; section 55L(5) FSMA 2000 (Entschädigungsauflage)
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Finamore S.A.Finamore: licence of insurance broker withdrawn over serious deficiencies LuxembourgOrganisational requirements Other

The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broking firm’s licence (effective from 1 December 2025), among other things for using unregistered intermediaries, lacking internal expertise, insufficiently protected confidential data, economically unexplained payment flows with affiliated companies, incomplete or false information provided to the supervisory authority and deficient customer information.

What organisations can take from it

False information to the supervisory authority and unregistered distribution partners can cost the business its existence – not just a fine.

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 303 Abs. 3 lit. c
Action
Other
Status of proceedings
unknown
Sector
Financial services and insurance
Published
29 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Oct 2025 BGH: price reduction only permissible with a clearly legible 30-day lowest price GermanyMisleading advertising and pricing Order

A food discounter advertised a coffee with a price reduction without stating the lowest total price of the previous 30 days unambiguously, clearly recognisably and legibly. In an action brought by the Wettbewerbszentrale (Centre for Protection against Unfair Competition), the BGH upheld the injunction issued by the lower courts (Regional Court of Amberg, Higher Regional Court of Nuremberg).

What organisations can take from it

In all discount advertising, state the 30-day lowest price as clearly as the discount itself.

Relevance to training and awareness

Price information in discount advertising (30-day lowest price)

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 183/24
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 11 Abs. 1 PAngV; § 5a Abs. 1, § 5b Abs. 4 UWG
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Published
9 Oct 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Oct 2025 South Wales PoliceICO: enforcement notice against South Wales Police over subject access backlog United KingdomData subject rights and transparency Order

The ICO issued an enforcement notice to South Wales Police over serious delays in handling subject access requests. The ICO found that from April 2023 to March 2024 the force answered only 29% of requests on time; in August 2025, 352 requests were overdue, one of them by almost two years. The ICO ordered the force to clear the backlog by June 2026. The legal basis is Articles 12(3), 15(1) and 15(3) UK GDPR and section 45 of the Data Protection Act 2018. According to the notice, the force employs almost 3,000 police officers and over 2,200 other staff.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12(3), 15(1) und 15(3) UK GDPR; section 45 DPA 2018; section 149 DPA 2018
Action
Order
Status of proceedings
unknown
Sector
Public sector
Employees
1,000 to 9,999

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Oct 2025 Manor Farm Dairy LtdManor Farm Dairy: fine after slurry overflow into stream near Dorchester United KingdomEmissions and permits €18,635

In March 2024, cattle slurry ran from the dairy farm's lagoons into a stream, seriously damaging it over more than 2 km, with effects up to 4.5 km downstream. The court imposed a fine of 6,000 GBP (reduced from 9,000 GBP because of an early guilty plea) and 10,158.50 GBP in costs; the Environment Agency described the incident as avoidable.

What organisations can take from it

Farms must maintain sufficient slurry storage capacity and monitor lagoons.

Authority / court
Taunton Magistrates' Court (Anklage: Environment Agency)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Regulations 12(1)(b) und 38(1)(a) Environmental Permitting (England and Wales) Regulations 2016
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Culpability
negligent
Mitigating circumstances
Early guilty plea (fine reduced from 9,000 to 6,000 GBP).
Published
13 Oct 2025

Original amount 16,158.5 GBP, converted at the ECB reference rate of 8 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script EstoniaData protection Order

The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.

What organisations can take from it

Publicly accessible register data remain personal data – automated scraping requires its own legal basis.

Relevance to training and awareness

Public registers are no licence for data collection

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests GermanyData subject rights and transparency €195,000

A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).

What organisations can take from it

Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.

Relevance to training and awareness

Timely handling of access requests

Authority / court
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Betroffenenrechte)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
30 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2025 Tractor Supply CompanyCPPA: $1.35 million against Tractor Supply over missing opt-out mechanisms USA, CAData subject rights and transparency €1.16m

The rural retail giant inadequately informed consumers and job applicants about their rights, offered no effective means of opting out of the sale and sharing of data (including no Global Privacy Control) and passed data on to third parties without the required contracts. An officer must certify compliance annually for four years, as required by the California Privacy Protection Agency (CPPA).

What organisations can take from it

Privacy notices must also cover job applicants, and browser opt-out signals such as GPC must be implemented technically.

Authority / court
California Privacy Protection Agency (CPPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more
Published
30 Sep 2025

Original amount 1,350,000 USD, converted at the ECB reference rate of 26 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Sep 2025 Synergy Credit UnionFINTRAC: CAD 214,500 penalty on Synergy Credit Union for 4 violations of anti-money laundering obligations CanadaSuspicious activity reports €131,757

According to FINTRAC, Synergy Credit Union is a provincially regulated credit union based in Lloydminster, Saskatchewan. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 214,500 on the company on 26 September 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, assessing and documenting money laundering and terrorist financing risks, enhanced measures for high risk and written compliance policies and procedures. Specifically, according to FINTRAC, the credit union failed to report suspicious transactions in two instances; contrary to its own policies, 46 of 102 high-risk clients were not reviewed annually. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Synergy Credit Union", published 27 November 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-11-27-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1), 9.6(3); PCMLTF Regulations 156(1)(b), 156(1)(c), 157; PCMLTF Suspicious Transaction Reporting Regulations s. 9(1); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
27 Nov 2025

Original amount 214,500 CAD, converted at the ECB reference rate of 26 Sep 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Sep 2025 Amazon.com, Inc.Amazon pays 2.5 billion USD in FTC settlement over Prime sign-up and cancellation hurdles USAInformation duties in online retail €2.13bn

According to the U.S. Federal Trade Commission (FTC), Amazon used confusing order screens to push millions of customers into Prime subscriptions without their consent and deliberately made cancellation difficult. The settlement comprises a civil penalty of 1 billion USD and 1.5 billion USD in refunds, as well as a clear decline button and simple cancellation.

What organisations can take from it

Subscription sign-ups require an equally prominent option to decline and a cancellation process that is as simple as signing up.

Relevance to training and awareness

Dark patterns and subscription design in product design

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Restore Online Shoppers' Confidence Act (ROSCA); Section 5 FTC Act
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more
Liability of senior managers
The press release names Senior Vice President Neil Lindsay and Vice President Jamil Ghani.
Published
25 Sep 2025

Original amount 2,500,000,000 USD, converted at the ECB reference rate of 25 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Sep 2025 „Смарт Софт“ ЕООДBidder Smart Soft denigrates competitor in letters to schools – 37,410 leva BulgariaCompetition law €19,128

During ongoing tenders for school equipment, Smart Soft sent dozens of identical letters to schools in the Plovdiv/Pazardzhik/Panagyurishte region containing untrue or distorted statements about its competitor Evroklas-konsult. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act) over around two months and imposed 3% of 2024 turnover, i.e. 37,410 leva. An appeal has been lodged against the decision.

What organisations can take from it

Have sales letters about competitors – especially to public contracting authorities – legally reviewed before they are sent.

Relevance to training and awareness

Communication about competitors in sales

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software

Original amount 37,410 BGN, converted at the ECB reference rate of 25 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Sep 2025 TicketmasterTicketmaster commits to price transparency following Oasis presale United KingdomMisleading advertising and pricing Order

The CMA objected that, during the Oasis presale, fans in the queue were not told that standing tickets were being sold at two price levels, and that "Platinum" tickets cost almost 2.5 times as much without it being adequately explained that they offered no added value compared with some standard tickets. Without admitting liability, Ticketmaster gave undertakings: advance notice of tiered pricing, price ranges in the queue, no misleading ticket descriptions and a two-year reporting obligation.

What organisations can take from it

Disclose dynamic or tiered prices before purchase; product descriptions must not suggest added value that does not exist.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Britisches Verbraucherschutzrecht (Verfahren nach den vor April 2025 geltenden Befugnissen; Verpflichtungszusagen)
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
Undertakings without admission of liability.
Published
25 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Sep 2025 Giant Manufacturing Co. Ltd.CBP detains bicycles from Giant Manufacturing over forced labour USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: bicycles, bicycle parts and accessories from Giant Manufacturing Co. Ltd. (Taiwan) are being detained at all US ports of entry because there are indications of forced labour (ILO indicators including debt bondage, withholding of wages, excessive overtime and abusive working and living conditions). Detained shipments can be destroyed, re-exported or released upon proof of admissibility.

What organisations can take from it

Recruitment fees for migrant workers are a core risk – suppliers should demonstrably bear them themselves.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Manufacturing and mechanical engineering
Published
24 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Sep 2025 TikTok Pte. Ltd.Canadian regulators: TikTok inadequately protected children's data CanadaMarketing and consent Other

The joint investigation by the Office of the Privacy Commissioner of Canada and the supervisory authorities of Québec, British Columbia and Alberta found that every year hundreds of thousands of children used the platform despite the minimum age of 13, and that TikTok processed data without valid consent, including for profiling and advertising. TikTok undertook to improve age verification and make privacy notices easier to understand, and already during the investigation largely stopped targeted advertising to under-18s (except by broad categories such as language and approximate location).

What organisations can take from it

Age limits in the terms of use are not enough – platforms need effective age verification and child-appropriate transparency.

Authority / court
Office of the Privacy Commissioner of Canada gemeinsam mit den Aufsichten von Québec, British Columbia und Alberta
Area of law
Data protection · Marketing and consent
Legal basis
PIPEDA und Datenschutzgesetze für den Privatsektor von Québec, British Columbia und Alberta
Action
Other
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
23 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2025 ShapeShift AGOFAC: USD 750,000 settlement with ShapeShift over crypto exchanges with users in sanctioned countries USABreaches of sanctions and embargoes €636,618

Crypto exchange ShapeShift AG, incorporated in Switzerland and operated from Denver, Colorado, is paying USD 750,000 under a settlement with OFAC for apparent violations of multiple sanctions programmes. According to OFAC's findings, between December 2016 and October 2018 ShapeShift exchanged digital assets worth USD 12,570,956 with users in Cuba, Iran, Sudan and Syria in 17,183 instances, although IP addresses revealed their location. The company introduced a sanctions compliance programme only after receiving an OFAC subpoena. OFAC treated the apparent violations as non-egregious and not voluntarily self-disclosed; the base penalty was USD 39,515,000. The low settlement amount reflects the fact that ShapeShift has ceased operations and has limited assets. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "ShapeShift AG Settles with OFAC for $750,000 Related to Apparent Violations of Multiple Sanctions Programs", 22 September 2025, https://ofac.treasury.gov/media/934641/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Cuban Assets Control Regulations, 31 C.F.R. § 515.201(b) (39); Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204 (16.839); Sudanese Sanctions Regulations, 31 C.F.R. § 538.205 (33); Syrian Sanctions Regulations, 31 C.F.R. § 542.207 (272); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
22 Sep 2025

Original amount 750,000 USD, converted at the ECB reference rate of 22 Sep 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2025 First Nations Bank of CanadaFINTRAC: CAD 601,139.80 penalty on First Nations Bank of Canada for 5 violations of anti-money laundering obligations CanadaSuspicious activity reports €369,432

According to FINTRAC, First Nations Bank of Canada is a bank based in Saskatoon, Saskatchewan. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 601,139.80 on the company on 22 September 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 5 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, enhanced measures for high-risk situations and ongoing monitoring of business relationships. Specifically, according to FINTRAC, suspicious transaction reports were missing in 5 of 16 case files reviewed; in six instances reviewed, high-risk clients were not subject to special measures. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on First Nations Bank of Canada", published 16 October 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-10-16-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1), 9.6(3); PCMLTF Regulations 123.1, 156(1)(b), 156(1)(c), 157; PCMLTF Suspicious Transaction Reporting Regulations s. 9(1); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
16 Oct 2025

Original amount 601,139.8 CAD, converted at the ECB reference rate of 22 Sep 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers SloveniaSecurity measures and risk management Reprimand or warning

After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).

What organisations can take from it

Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.

Relevance to training and awareness

Security testing for software releases of interfaces

Authority / court
Banka Slovenije
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
Action
Reprimand or warning
Status of proceedings
final
Sector
Financial services and insurance
Liability of senior managers
Reprimand also issued to the responsible Director of IT Development (Dejan Pust).

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Sep 2025 Chegg Inc.Chegg pays 7.5 million USD in FTC settlement over allegations of obstructed subscription cancellation USAInformation duties in online retail €6.35m

According to the FTC complaint, the education provider hid the cancellation option for its automatically renewing subscriptions on its website and, since October 2020, continued to charge almost 200,000 customers even after they had cancelled. Under the settlement, Chegg is paying 7.5 million USD for refunds and must offer simple cancellation.

What organisations can take from it

Cancellations received must be reliably implemented in the systems – continuing to charge customers is a separate violation.

Relevance to training and awareness

Cancellation processes and customer service for subscriptions

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Restore Online Shoppers' Confidence Act (ROSCA); Section 5 FTC Act
Action
Disgorgement of profits
Status of proceedings
final
Sector
Telecoms, IT and software
Repeat case
yes
Published
15 Sep 2025

Original amount 7,500,000 USD, converted at the ECB reference rate of 18 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2025 Go West Invest SAGo West Invest: 10,000 EUR for outdated information note in tax shelter offering BelgiumDisclosure and reporting obligations €10,000

From June 2021 to October 2024, the company, which raises tax shelter funds through public offerings, kept a public offering on its website with an information note from 2020 without publishing an updated note and filing it with the Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA); several dozen investors with an investment volume of under 5 million EUR were affected. The FSMA accepted a settlement of 10,000 EUR.

What organisations can take from it

Investor information has an expiry date – a deadline calendar for mandatory documents prevents infringements.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Loi du 11 juillet 2018 (Loi Prospectus), Art. 10, 11
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
16 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN PolandData protection €2,669

For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.

What organisations can take from it

This also applies in small practices and companies: management cannot be its own data protection officer.

Relevance to training and awareness

Role and independence of the data protection officer; release of patient records

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
An independent external data protection officer was appointed in July 2024.
Published
29 Sep 2025

Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Sep 2025 Colorcon LimitedPharmaceutical supplier Colorcon paid Moscow salaries via sanctioned banks United KingdomBreaches of sanctions and embargoes €176,590

In 2022, the Moscow office of the British subsidiary made payments – mainly salaries – to accounts at Alfa-Bank, Promsvyazbank, Sberbank and VTB; after deduction of payments covered by a general licence, around 128,300 GBP remained in breach. The approval process in the UK checked only the amount and the recipient, not the bank; because of a four-month delay in reporting, HM Treasury's Office of Financial Sanctions Implementation (OFSI) granted only a 35% instead of a 50% reduction.

What organisations can take from it

Anyone approving payments must also screen the recipient's bank against sanctions lists – and report breaches discovered without delay.

Relevance to training and awareness

Payment approval with screening of the recipient bank, prompt reporting

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, reg. 12
Action
Fine
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Mitigating circumstances
Disclosure and full cooperation, but delayed
Published
30 Sep 2025

Original amount 152,750 GBP, converted at the ECB reference rate of 10 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service FinlandData breaches and data security €1.8m

After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.

What organisations can take from it

Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
Published
10 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor LatviaData breaches and data security €300,000

Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.

What organisations can take from it

Processors are also independently liable for the security of the systems they operate.

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Sep 2025 Vanquis Bank LimitedOFSI: breach by Vanquis Bank published instead of a penalty after a delayed account freeze United KingdomBreaches of sanctions and embargoes Other

On 8 September 2025 OFSI published a report on sanctions breaches by Vanquis Bank Limited but did not impose a monetary penalty. According to OFSI's findings, the account of a person designated under counter-terrorism sanctions remained fully usable for eight days after the designation; during that time GBP 200 was withdrawn in cash and a purchase of GBP 8.99 was made. OFSI had given the bank advance notice the day before the designation. According to OFSI, the staff responsible had been redeployed to remediation work, so the internal one-day deadline for the freeze was missed. The bank reported the breach itself, but only 13 days after the designation. Type of measure: Breach published by OFSI instead of a monetary penalty (disclosure under s. 149(3) PACA 2017). The publication does not mention any pending review. Source: Office of Financial Sanctions Implementation (OFSI), HM Treasury, "Disclosure notice: 08 September 2025", 8 September 2025, https://www.gov.uk/government/publications/disclosure-notice-08-september-2025. Contains public sector information licensed under the Open Government Licence v3.0 (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/).

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
regulations 11 and 12 of the Counter-Terrorism (Sanctions) (EU Exit) Regulations 2019; Veröffentlichung nach section 149(3) Policing and Crime Act 2017
Action
Other
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 Sep 2025

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Sep 2025 „Paysera LT“, UABPaysera took over e-money institution Contis without approval – 400,000 EUR LithuaniaOrganisational requirements €400,000

Paysera acquired 100% of the shares in UAB ‘Finansinės paslaugos „Contis“’ before the assessment period had expired and without a non-objection from the supervisory authority; in April 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) objected to the acquisition owing to a lack of documents on reputation, financial soundness and money laundering risks. In addition, the annual financial statements and other reports were not approved and submitted on time. Fine of 400,000 EUR and obligation to remedy by 30 September 2025. Source: archived copy of the press release.

What organisations can take from it

Complete acquisitions of holdings in supervised institutions only after approval – otherwise voting rights are suspended and fines loom.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Elektroninių pinigų ir elektroninių pinigų įstaigų įstatymas (Inhaberkontrolle, Berichtspflichten)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 Midri, Inc. (Restaurant J BBQ, Los Angeles)Restaurant J BBQ: 680,238 USD – breaks denied, split shifts without premium USA, CAWorking time €584,046

The Koreatown restaurant regularly denied 48 employees meal and rest breaks, required them to remain available for guests even during the lunch break, did not pay split-shift premiums and did not pay all wages. The California Labor Commissioner’s Office imposed 680,238 USD, of which 538,638 USD for the benefit of the employees.

What organisations can take from it

In the restaurant trade, breaks must be actively scheduled and documented – being on call for guests during the break turns it into working time.

Relevance to training and awareness

Break arrangements in the restaurant trade

Authority / court
California Labor Commissioner's Office (Division of Labor Standards Enforcement)
Area of law
Health and safety and employment law · Working time
Legal basis
California Labor Code (Meal and Rest Periods, Split Shift Premium, Lohnabrechnung)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Liability of senior managers
Owner Byung Kwan Lee named in the announcement.

Original amount 680,238 USD, converted at the ECB reference rate of 4 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam AustriaIncident reporting obligations €870

Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.

What organisations can take from it

External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.

Relevance to training and awareness

Recognising and escalating alerts about security gaps

Missing or inadequate training played a role in the decision.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB EU levelData subject rights and transparency —

The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.

What organisations can take from it

Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.

Authority / court
Gerichtshof der Europäischen Union, Rs. C-413/23 P
Area of law
Data protection · Data subject rights and transparency
Legal basis
Verordnung (EU) 2018/1725 (Informationspflicht)
Status of proceedings
under appeal
Sector
Public sector
Published
4 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2025 SURYS SAS (Gruppe Imprimerie Nationale)Hologram manufacturer SURYS: CJIP of 18.4 million EUR in the Ukrainian passport case FranceBribery of public officials €18.4m

From 2013, SURYS supplied security holograms for Ukrainian passports to the state-owned company Polygraph via an interposed Estonian company; the investigation (following a request for mutual legal assistance from Ukraine's National Anti-Corruption Bureau, NABU) concerned misappropriation of public funds, bribery of foreign public officials and money laundering. Public interest fine of 18,363,007 EUR, plus 3,770,000 EUR in damages to the Ukrainian state and a three-year AFA compliance programme.

What organisations can take from it

If a state customer insists on an interposed trader without any discernible added value, treat this as a red flag for misappropriation and bribery.

Relevance to training and awareness

Interposed trading companies and sales agents

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger, Geldwäsche
Action
Fine
Status of proceedings
final
Sector
Other
Employees
250 to 999
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
3 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2025 Fracht FWO Inc.Freight forwarder Fracht FWO chartered blocked Venezuelan airline with Mahan Air jet USABreaches of sanctions and embargoes €1.38m

In May 2022, bypassing internal compliance procedures, the Houston freight forwarder engaged a blocked Venezuelan state-owned airline for a shipment from Mexico to Argentina; the aircraft used, which was also blocked, was operated by Iran's Mahan Air. The US Treasury's Office of Foreign Assets Control (OFAC) classified the case as egregious and not voluntarily self-disclosed, partly because two vice presidents bypassed the screening under time pressure.

What organisations can take from it

Urgent customer orders never justify skipping sanctions screening of carriers and of the aircraft or vessels used.

Relevance to training and awareness

Business partner screening under time pressure, circumvention of internal approvals

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Venezuela-, Iran-, Proliferations- und Terrorismus-Sanktionsprogramme (OFAC); IEEPA
Action
Fine
Status of proceedings
final
Sector
Transport, logistics and shipping
Culpability
negligent
Repeat case
no
Mitigating circumstances
No prior violations in five years, immediate remediation, substantial cooperation
Liability of senior managers
According to OFAC, the violation was driven primarily by two vice presidents who bypassed internal screening processes.
Published
3 Sep 2025

Original amount 1,610,775 USD, converted at the ECB reference rate of 3 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Sep 2025 IDdesign A/SIDdesign: High Court raises GDPR fine to 1.5 million DKK – group turnover counts DenmarkData protection €200,986

The furniture retailer had stored data of around 385,000 customers in a legacy system without retention periods. The district court had imposed 100,000 DKK; following a referral to the CJEU on whether the fine is to be calculated on the basis of the turnover of the entire group, the High Court increased the fine to 1.5 million DKK.

What organisations can take from it

Retention periods also apply to legacy systems in individual branches – and the group turnover counts when setting the fine.

Authority / court
Vestre Landsret (auf Anzeige der Datatilsynet)
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 83
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Original amount 1,500,000 DKK, converted at the ECB reference rate of 2 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Sep 2025 Commerciale I.C. - Pacific Inc.FINTRAC: CAD 224,235 penalty on Commerciale I.C. - Pacific Inc. for 5 violations of anti-money laundering obligations CanadaInternal controls €139,658

According to FINTRAC, Commerciale I.C. - Pacific Inc. is a money services business based in Montréal, Quebec. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 224,235 on the company on 2 September 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 5 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned international electronic funds transfer reporting, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the prescribed review of the compliance programme and compliance with a ministerial directive. Specifically, according to FINTRAC, 8 of 22 electronic funds transfer reports reviewed were not filed on time; the company also did not comply with a ministerial directive. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Commerciale I.C. - Pacific Inc.", published 5 February 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-02-05-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 11.43; PCMLTF Regulations 132(1), 156(1)(b), 156(1)(c), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
5 Feb 2026

Original amount 224,235 CAD, converted at the ECB reference rate of 2 Sep 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Google LLC und Google Ireland LimitedGoogle: 325 million EUR – advertising cookies at account creation and ads in the Gmail inbox FranceCookies and tracking €325m

When creating a Google account, users were not sufficiently informed that advertising cookies were necessarily placed in the process; in addition, Google displayed advertisements between e-mails in Gmail without prior consent. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 200 million EUR on Google LLC and 125 million EUR on Google Ireland and ordered remedial action within six months, subject to a penalty payment of 100,000 EUR per day.

What organisations can take from it

Do not tacitly tie advertising cookies to account creation – and advertising in the inbox counts as direct marketing requiring consent.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés; Art. L. 34-5 Code des postes et des communications électroniques
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Infinite Styles Services Co. Limited (Shein)Shein: 150 million EUR – cookies without consent and despite rejection FranceCookies and tracking €150m

On shein.com, advertising cookies were placed without consent as soon as the site was accessed; in addition to an incomplete cookie banner, there was an advertising pop-up without an option to reject. After clicking ‘Reject all’ or withdrawing consent, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 150 million EUR.

What organisations can take from it

A cookie banner must work technically: rejecting and withdrawing consent must actually stop cookies from being placed and read.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Umsetzung von Art. 5 Abs. 3 ePrivacy-Richtlinie)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 SIA "SILTUMTEHSERVISS", SIA "Apkure IM", SIA "ADAPTERIS", SIA "Alpex", SIA "Infrakom"Bid-rigging cartel in pipeline construction contracts – five construction firms pay 513,508 EUR LatviaCartels and collusion €513,508

From 2021 to 2024, two groups of construction companies coordinated in more than 30 public tenders for the construction and repair of utility pipelines: they exchanged sensitive information, determined winners and submitted sham bids. Prompted by information from the contracting entity Rīgas namu pārvaldnieks, the Konkurences padome (Latvian Competition Council) imposed a total of 513,508.08 EUR.

What organisations can take from it

Jointly preparing bids with competitors – even where the work is later carried out jointly – is a cartel; tender teams must know this.

Relevance to training and awareness

Competition law in tenders

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 11 Abs. 1 Konkurences likums
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Mitigating circumstances
All companies except Infrakom concluded a settlement with the Competition Council, acknowledged the facts and waived an appeal; in return, a 10% fine reduction.
Published
10 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Blacktower Financial Management (Cyprus) LtdCyprus: Blacktower Financial Management pays 70,000 EUR over conflicts of interest CyprusOrganisational requirements €70,000

For the period November 2020 to May 2025, the Cyprus Securities and Exchange Commission (CySEC) investigated the investment firm’s handling of conflicts of interest and its general conduct of business and information obligations towards clients. The proceedings ended with a settlement of 70,000 EUR, which the company has paid.

What organisations can take from it

Conflicts of interest must be identified, documented and managed vis-à-vis clients – adviser training is the basis for this.

Relevance to training and awareness

Recognising conflicts of interest in investment advice

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 24(1), 25(1) Gesetz über Wertpapierdienstleistungen 2017; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Aug 2025 Juba Express Inc.FINTRAC: CAD 67,150 penalty on Juba Express Inc. for 5 violations of anti-money laundering obligations CanadaInternal controls €41,888

According to FINTRAC, Juba Express Inc. is a money services business based in Toronto, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 67,150 on the company on 29 August 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 5 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, international electronic funds transfer reporting, large cash transaction reporting and money services business registration requirements. Specifically, according to FINTRAC, nine electronic funds transfer reports and three large cash transaction reports were incomplete; one branch was not disclosed in the registration. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Juba Express Inc.", published 11 December 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-12-11-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9(1); PCMLTF Regulations 30(1)(a), 30(1)(b), 156(1)(b), 156(1)(c), 156(2); PCMLTF Registration Regulations s. 4(b), 5; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
11 Dec 2025

Original amount 67,150 CAD, converted at the ECB reference rate of 29 Aug 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Aug 2025 Saskatchewan Indian Gaming AuthorityFINTRAC: CAD 1,175,000 penalty on Saskatchewan Indian Gaming Authority for 3 violations of anti-money laundering obligations CanadaSuspicious activity reports €731,540

According to FINTRAC, Saskatchewan Indian Gaming Authority is a reporting entity in the casino sector. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 1,175,000 on the company on 28 August 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting and written compliance policies and procedures. Specifically, according to FINTRAC, four suspicious transaction reports were missing, three reports filed contained no indicators of suspicion, and the regulator found shortcomings in patron risk rating in 41 of 100 instances reviewed. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Saskatchewan Indian Gaming Authority", published 12 September 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-09-12-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9(1), 9.6(1); PCMLTF Regulations 156(1)(b); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
12 Sep 2025

Original amount 1,175,000 CAD, converted at the ECB reference rate of 28 Aug 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Aug 2025 Home Improvement Marketing LtdICO: £300,000 fine for Home Improvement Marketing over 2.4 million automated calls United KingdomMarketing and consent €347,343

The ICO fined Home Improvement Marketing Ltd £300,000 and issued an enforcement notice. After executing a search warrant in March 2024, it found that between 31 May and 31 August 2023 the company had instigated 2,449,380 automated marketing calls without prior consent; 274 complaints were received. According to the ICO, the software responded to recipients' answers and offered no way to opt out of further calls. The legal basis is regulations 19 and 24 of PECR.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 19 und 24 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate

Original amount 300,000 GBP, converted at the ECB reference rate of 28 Aug 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Aug 2025 Green Spark Energy LtdICO: £250,000 fine for Green Spark Energy over 9.6 million automated marketing calls United KingdomMarketing and consent €289,452

The ICO fined Green Spark Energy Ltd £250,000 and issued an enforcement notice. After executing a search warrant in March 2024, the regulator found that from May 2023 to May 2024 the company had instigated 9,587,050 automated calls carrying recorded marketing messages; 497 complaints were received. According to the ICO, the recordings contained misleading statements designed to pressure homeowners, for example about supposed risks of their existing loft insulation. The legal basis is regulations 19 and 24 of PECR.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulations 19 und 24 PECR; section 55A DPA 1998
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate

Original amount 250,000 GBP, converted at the ECB reference rate of 28 Aug 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2025 V.Ships Norway A.S.V.Ships Norway: 2 million USD fine for oil pollution and falsified oil record books USAWaste and hazardous substances €1.73m

On board the tanker M/T Swift Winchester, a hose connected the incinerator's waste oil tank to the sewage tank from February to August 2022, so that oily waste bypassed the pollution prevention equipment and went into the sea; in August 2022, an oily water separator filter was also hosed down with degreaser on deck and the oily mixture ran overboard. The vessel called at Baton Rouge and Port Arthur with a knowingly falsified oil record book. The ship management company pleaded guilty and is paying a fine of 2 million USD.

What organisations can take from it

When a crew member reports misconduct to management, the company must intervene immediately; otherwise it is liable for the continued pollution.

Relevance to training and awareness

Handling oil residues on board and honest documentation

Authority / court
U.S. District Court for the Eastern District of Texas (Anklage: DOJ Environment and Natural Resources Division)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Act to Prevent Pollution from Ships (APPS)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Culpability
intentional
Published
27 Aug 2025

Original amount 2,000,000 USD, converted at the ECB reference rate of 27 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2025 Bristol City CouncilICO: enforcement notice against Bristol City Council over unanswered subject access requests United KingdomData subject rights and transparency Order

The ICO issued an enforcement notice to Bristol City Council because it found that the council had not responded to subject access requests as required by law. The notice relies on Articles 12(3), 15(1) and 15(3) UK GDPR and examines, among other things, the period from 1 April 2023 to 31 March 2024.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12(3), 15(1) und 15(3) UK GDPR; section 149 DPA 2018
Action
Order
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2025 Acqua Minerale San Benedetto S.p.A.AGCM: San Benedetto removes ‘CO2 neutral’ claim on Ecogreen bottles ItalyMisleading environmental and sustainability claims Other

Labels, the website and commercials for the Ecogreen line claimed that bottle production caused no greenhouse gas emissions and even had a positive effect on the environment. Following an intervention by Italy's competition and consumer protection authority (Autorità Garante della Concorrenza e del Mercato, AGCM) (moral suasion, case PS12596), the mineral water producer removed the claim ‘impatto zero CO2’ in mid-July 2025, revised nature motifs and added a QR code linking to sustainability information.

What organisations can take from it

‘Zero emissions’ promises on packaging can hardly be substantiated; it is better to present specific reduction steps transparently.

Relevance to training and awareness

Climate claims on packaging

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Environment and sustainability · Misleading environmental and sustainability claims
Legal basis
Codice del Consumo (unlautere Geschäftspraktiken), Verfahren PS12596
Action
Other
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Voluntary amendment of all labels and advertising materials following the authority's intervention.
Published
26 Aug 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2025 GXO Logistics, Inc. und Wincanton LimitedGXO/Wincanton: supermarket warehouse logistics must be sold after takeover United KingdomMerger control Order

GXO had already acquired Wincanton in April 2024; the Competition and Markets Authority (CMA) imposed a hold-separate order, appointed a monitoring trustee and, in Phase 2, found a lessening of competition in dedicated warehousing services for grocery retail. Under the final undertakings, GXO committed to divest Wincanton’s business serving supermarket customers.

What organisations can take from it

Anyone completing a deal before the merger review has concluded bears the risk of having to give up parts of the acquired business again.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Competition law · Merger control
Legal basis
Enterprise Act 2002, ss. 41, 82, 90 (Final Undertakings)
Action
Order
Status of proceedings
final
Sector
Transport, logistics and shipping

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2025 PAUPE HOLDING SA, Bitusag S.A., Bitusag Neuchâtel SA, Wyss Fils SA, Prodo SA, Duckert SAWEKO fines road maintenance firms in Jura/Neuchâtel over bid rigging SwitzerlandCartels and collusion Fine

Regional suppliers of surface treatments and chip sealing in road maintenance colluded on bids and allocated territories. Switzerland's Competition Commission (Wettbewerbskommission, WEKO) imposed sanctions on Bitusag/Paupe (jointly and severally, CHF 640,000–990,000, exact amount redacted), Wyss Fils (CHF 44,000–74,000), Prodo (CHF 760) and Duckert (CHF 0) and approved amicable settlements; the investigation against Colas Suisse was discontinued.

What organisations can take from it

Small regional road builders are also sanctioned – cover bids and territorial protection must disappear from corporate culture.

Relevance to training and awareness

Cover bids and territorial agreements in regional road construction

Authority / court
Wettbewerbskommission (WEKO)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 5 Abs. 3 i.V.m. Abs. 1 KG, Art. 49a Abs. 1 KG
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Mitigating circumstances
Amicable settlements; leniency programme (Duckert free of sanctions)

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Aug 2025 Varengold Bank AGBaFin: 3.3 million EUR fine and penalty payment against Varengold Bank GermanySuspicious activity reports €3.8m

By decision of 22 August 2025, Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 3.3 million EUR because the bank systematically filed suspicious activity reports late from June 2023 to March 2025; in February 2025, a penalty payment of 500,000 EUR had already been imposed for failure to comply with a 2023 order concerning Iran-related transactions (total 3.8 million EUR). In addition, in July 2025 BaFin ordered comprehensive remediation of the deficiencies in money laundering prevention, with an action plan and reporting obligations.

What organisations can take from it

Failing to implement a supervisory order risks penalty payments and a comprehensive package of measures in addition to the fine.

Relevance to training and awareness

Suspicious activity reports and handling of high-risk transactions

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Bußgeld: § 56 Abs. 1 S. 1 Nr. 69, Abs. 3 GwG; Anordnung: § 51 Abs. 2 GwG, § 44 Abs. 1 KWG; Zwangsgeld: § 14 VwVG i. V. m. § 17 FinDAG; Bekanntmachung nach § 57 Abs. 1 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Published
16 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Aug 2025 Bank J. Safra Sarasin AGBank J. Safra Sarasin: 3.5 million CHF fine for money laundering in the Petrobras complex SwitzerlandInternal controls €3.73m

Between 2011 and 2014, the bank did not take all the necessary organisational precautions, with the result that bribes flowed to Petrobras executives through several account relationships (around 71 million USD in attempted or completed aggravated money laundering). Fine of 3.5 million CHF; because of a settlement of 16 million CHF with Petrobras, the Office of the Attorney General of Switzerland (Bundesanwaltschaft, OAG) waived a compensation claim. A former asset manager was separately given a suspended prison sentence.

What organisations can take from it

Unusual payment flows involving clients close to PEPs must be escalated and, if necessary, rejected – responsibility lies with the bank as an organisation.

Relevance to training and awareness

Anti-money laundering and PEP clients

Authority / court
Bundesanwaltschaft
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 102 Abs. 2 StGB i. V. m. Art. 305bis Abs. 1 und 2 StGB
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Time elapsed since the offence, organisational corrective measures after the affair became known; no compensation claim because of the payment of 16 million CHF to Petrobras.
Liability of senior managers
A former asset manager was separately given a suspended prison sentence of six months for aggravated money laundering (offences committed at another Swiss bank).
Published
22 Aug 2025

Original amount 3,500,000 CHF, converted at the ECB reference rate of 22 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Aug 2025 J.P. Morgan (Suisse) SAJ.P. Morgan (Suisse): 3 million CHF fine in the 1MDB complex for deficient anti-money laundering controls SwitzerlandCustomer due diligence €3.2m

Between October 2014 and July 2015, around 174 million CHF from predicate offences in the 1MDB complex passed through the bank in 43 transfers, even though negative information about the Petrosaudi managers involved was publicly available. The Office of the Attorney General of Switzerland (Bundesanwaltschaft) convicted the bank by summary penalty order and imposed 3 million CHF; a compensation claim was waived because the 1MDB fund is being compensated as a private claimant.

What organisations can take from it

Publicly available negative information about clients must feed into the risk assessment and be capable of stopping transactions.

Relevance to training and awareness

Customer due diligence and adverse media screening

Authority / court
Bundesanwaltschaft
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 102 Abs. 2 StGB i. V. m. Art. 305bis Abs. 1 und 2 StGB
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Time elapsed since the offence, very good cooperation in the proceedings, compensation of the private claimant (1MDB).
Published
22 Aug 2025

Original amount 3,000,000 CHF, converted at the ECB reference rate of 22 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months USA, NYIncident reporting obligations €1.71m

An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.

What organisations can take from it

Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.

Relevance to training and awareness

Recognising phishing; reporting channels for security incidents

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2025 Portugal: 30,000 EUR for exclusive tying of banana growers on Madeira PortugalAbuse of market power €30,000

A dominant company for the collection, distribution and marketing of Madeira bananas (name not given) required producers to sign exclusivity declarations. In a settlement procedure (PRC/2025/6), it ended the practice and paid 30,000 EUR (date = press release).

What organisations can take from it

Dominant buyers must not tie suppliers through exclusivity clauses – even small regional markets are being watched.

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Abuse of market power
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 11.º; Art. 102 AEUV
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Settlement (transação), full cooperation, immediate cessation, short duration
Published
13 Aug 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR RomaniaData breaches and data security €2,990

A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.

What organisations can take from it

Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.

Relevance to training and awareness

Identity verification and fraud detection in remote applications

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
12 Aug 2025

Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2025 Paxos Trust Company, LLCNYDFS: 26.5 million USD against Paxos over AML deficiencies in Binance business USA, NYCustomer due diligence €22.8m

The New York State Department of Financial Services (NYDFS) imposed a penalty of 26.5 million USD on the crypto trust company because Paxos did not maintain an effective BSA/AML programme before 2023: KYC checks and risk ratings were inadequate, and transaction monitoring and suspicious activity reporting procedures had gaps, including in connection with the business relationship with Binance, contrary to a 2020 agreement. In addition, Paxos must invest at least 22 million USD in its compliance programme.

What organisations can take from it

Companies that distribute products via partner platforms must include those platforms' customer and transaction risks in their own AML programme.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
New York Banking Law §§ 39, 44; AML-Vorschriften des NYDFS und Bank Secrecy Act
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
7 Aug 2025

Original amount 26,500,000 USD, converted at the ECB reference rate of 7 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2025 Liberty Mutual Insurance CompanyLiberty Mutual: declination against 4.7 million USD after bribery of Indian state bank employees USABribery of public officials €4.04m

From 2017 to 2022, the Indian subsidiary Liberty General Insurance paid around 1.47 million USD to employees of six state-owned banks so that they would refer bank customers to its insurance products; the payments were booked as marketing expenses and routed through third parties. The DOJ declined to prosecute; Liberty Mutual is disgorging 4,699,088 USD in profits.

What organisations can take from it

Employees of state-owned banks are public officials – sales commissions paid to them are bribes, even if they are booked as marketing.

Relevance to training and awareness

Distribution partnerships with state-owned banks, payments disguised as marketing

Authority / court
U.S. Department of Justice (Fraud Section; USAO District of Massachusetts)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA, 15 U.S.C. § 78dd-2; Corporate Enforcement and Voluntary Self-Disclosure Policy (Declination)
Action
Disgorgement of profits
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure (March 2024), full cooperation, root cause analysis, termination of those involved, improved controls including rules on messaging apps.
Published
7 Aug 2025

Original amount 4,699,088 USD, converted at the ECB reference rate of 7 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner AustriaCookies and tracking €6,200

In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.

What organisations can take from it

Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
Action
Fine
Status of proceedings
final
Sector
Media and online platforms

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2025 Infinite Styles Services Co. Ltd (Shein)AGCM: 1 million EUR fine against Shein for misleading environmental claims ItalyMisleading environmental and sustainability claims €1m

Italy's competition and consumer protection authority (Autorità Garante della Concorrenza e del Mercato, AGCM) objected to vague and in part false claims about circular design and recyclability, about the ‘green’ evoluSHEIN collection (only a small share of the range) and about emission targets, while emissions rose in 2023/2024. The ultra-fast-fashion model is subject to a heightened duty of care, the authority held; it imposed 1 million EUR (case PS12709).

What organisations can take from it

Communicate climate targets and recycling promises only if they are specific, substantiated and consistent with actual developments.

Relevance to training and awareness

Verifiable sustainability communication in online retail

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Environment and sustainability · Misleading environmental and sustainability claims
Legal basis
Codice del Consumo (unlautere Geschäftspraktiken), Verfahren PS12709
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
4 Aug 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Jul 2025 Aero Turbine Inc.; Gallant Capital Partners LLCAero Turbine and Gallant pay 1.75 million USD after self-disclosure on cyber obligations USAOther €1.53m

From 2018 to 2020, the engine maintenance company allegedly failed to implement the NIST controls of an Air Force contract and, in 2019, together with its private equity owner, passed files containing sensitive defence data to an unauthorised software company in Egypt. The companies had made several written self-disclosures, cooperated and remedied the issues promptly; the U.S. Department of Justice (DOJ) granted them cooperation credit for this. Settlement of 1.75 million USD.

What organisations can take from it

Companies that pass controlled defence data to service providers must check their authorisation – self-disclosure and cooperation significantly reduce the consequences.

Relevance to training and awareness

Handling controlled defence data and service providers

Authority / court
U.S. Department of Justice (Civil Division) / USAO Eastern District of California
Area of law
Other
Legal basis
False Claims Act; NIST SP 800-171
Action
Other
Status of proceedings
final
Sector
Defence and security
Mitigating circumstances
Several written self-disclosures, cooperation and prompt remedial measures.
Published
31 Jul 2025

Original amount 1,750,000 USD, converted at the ECB reference rate of 31 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Jul 2025 BGH: no before-and-after images for nose and chin correction with hyaluronic acid GermanyMisleading advertising and pricing Order

A practice for aesthetic treatments advertised hyaluronic acid filler injections for the nose and chin on its website and on Instagram using before-and-after images. In an action brought by a consumer advice centre (Verbraucherzentrale), the BGH upheld the injunction issued by the Higher Regional Court of Hamm (OLG Hamm): such procedures are deemed to be surgical cosmetic procedures, for which this kind of advertising is prohibited.

What organisations can take from it

Instagram posts are also advertising – the strict limits of the law on advertising for medicinal products and treatments (Heilmittelwerberecht) apply to aesthetic procedures.

Relevance to training and awareness

Social media advertising for healthcare services

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 170/24
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 11 Abs. 1 Satz 3 Nr. 1, § 1 Abs. 1 Nr. 2 Buchst. c HWG; UKlaG
Action
Order
Status of proceedings
final
Sector
Healthcare
Published
31 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2025 Sigma Broking LimitedFCA: £1.09m fine for Sigma Broking over deficient transaction reports United KingdomDisclosure and reporting obligations €1.26m

The FCA fined Sigma Broking Limited £1,087,300. The FCA found that between December 2018 and December 2023 almost all of the firm's transaction reports were incomplete or inaccurate, affecting 924,584 transactions. The cause was a reporting system set up incorrectly from the start, whose errors were not fixed for years. The fine includes a 30% discount.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 26 UK MiFIR; FCA Principle 3; section 206 FSMA 2000
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance

Original amount 1,087,300 GBP, converted at the ECB reference rate of 29 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2025 Cadence Design Systems Inc.Cadence pleads guilty: chip design software for Chinese military university USAExport control and dual-use goods €120.1m

From 2015 to 2021, the San José provider of chip design software supplied hardware, software and semiconductor IP at least 59 times to the National University of Defense Technology (NUDT), a military university on the Entity List, disguised under the alias Central South CAD Center. Cadence pleaded guilty before the US Department of Justice to conspiracy to commit export control violations; criminal penalties of almost 118 million USD and civil penalties of more than 95 million USD imposed by the Bureau of Industry and Security (BIS) result, after crediting, in a net total of more than 140 million USD.

What organisations can take from it

Include cover names and known aliases of listed customers in screening; sales and compliance must escalate indications of military end users.

Relevance to training and awareness

Recognising aliases and cover names of listed customers

Authority / court
U.S. Department of Justice; Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations (Entity List); ECRA; Verschwörung zu Exportkontrollverstößen
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Culpability
intentional
Published
28 Jul 2025

Original amount 140,000,000 USD, converted at the ECB reference rate of 28 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2025 Peken Global Limited (KuCoin)FINTRAC: CAD 19,552,000 penalty on Peken Global Limited (KuCoin) for 3 violations of anti-money laundering obligations CanadaSuspicious activity reports €12.2m

According to FINTRAC, Peken Global Limited (KuCoin) is an entity determined to be a foreign money services business operating in Canada. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 19,552,000 on the company on 28 July 2025. According to FINTRAC's findings, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned money services business registration requirements, large virtual currency transaction reporting and suspicious transaction reporting. Specifically, FINTRAC found 33 instances of unreported suspicious transactions; the regulator identified unreported virtual currency receipts of CAD 10,000 or more using blockchain analytics, and registration as a foreign money services business was not completed despite the opportunity to do so. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Peken Global Limited", published 25 September 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-09-25-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 11.1; PCMLTF Regulations 33(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
25 Sep 2025

Original amount 19,552,000 CAD, converted at the ECB reference rate of 28 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2025 2294235 Ontario Inc.FINTRAC: CAD 70,537.50 penalty on 2294235 Ontario Inc. for 6 violations of anti-money laundering obligations CanadaCustomer due diligence €44,108

According to FINTRAC, 2294235 Ontario Inc. is a money services business based in Niagara Falls, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 70,537.50 on the company on 28 July 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 6 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme, the prescribed review of the compliance programme, providing documents requested by notice and record keeping. The publication does not mention any pending review. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on 2294235 Ontario Inc.", published 2 December 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-12-02-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
PCMLTFA s. 9.6(2), 63.1(2); PCMLTF Regulations 36(i), 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f), 156(2), 156(3); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Dec 2025

Original amount 70,537.5 CAD, converted at the ECB reference rate of 28 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jul 2025 DMCL Chartered Professional AccountantsFINTRAC: accountancy firm DMCL without compliance programme – 72,750 CAD CanadaInternal controls €45,370

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) imposed 72,750 CAD on the auditing and accountancy firm with four offices in British Columbia: approved written compliance policies, a documented risk assessment and the prescribed two-yearly effectiveness review were all lacking. The penalty was paid.

What organisations can take from it

Firms that handle money movements for clients are themselves obliged entities and need their own AML programme.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Proceeds of Crime (Money Laundering) and Terrorist Financing Act, Part 1, und zugehörige Verordnungen
Action
Fine
Status of proceedings
final
Sector
Other
Published
9 Oct 2025

Original amount 72,750 CAD, converted at the ECB reference rate of 25 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jul 2025 Tamro Eesti OÜTamro Eesti: order against unfair payment terms for food supplements EstoniaAbuse of market power Order

In consignment agreements, the pharmaceutical wholesaler had made payment to suppliers of food supplements dependent on subsequent resale (payment period over 30 days) and had reserved the right to hold suppliers liable for spoiled goods. The Konkurentsiamet (Estonian Competition Authority) found infringements of the act on unfair trading practices in the food supply chain and ordered amended contractual terms.

What organisations can take from it

Purchasing terms in the food sector – including for food supplements – must comply with the 30-day payment period and the prohibition on shifting risk.

Authority / court
Konkurentsiamet (Estnische Wettbewerbsbehörde)
Area of law
Competition law · Abuse of market power
Legal basis
§ 4 Abs. 1 und 2, § 5 Abs. 2, § 7 Abs. 1 PTEKS (UTP-Richtlinie (EU) 2019/633)
Action
Order
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jul 2025 „Билла България“ ЕООД (Billa Bulgaria)Billa advertises oil containing 80% sunflower oil as olive oil – 405,936 leva BulgariaMisleading advertising and pricing €207,555

In June 2024, the retail chain advertised the product ‘Маслиново масло екстра върджин 20% – Basso Blend’ on its website, on radio, on television and online in such a way that olive oil was in the foreground, although the product consisted of 80% sunflower oil. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) opened proceedings of its own motion, considered the advertising misleading (Art. 32(1) in conjunction with Art. 33 ZZK – Bulgarian Protection of Competition Act) and imposed 0.032% of 2024 turnover, i.e. 405,936 leva.

What organisations can take from it

Advertising must not highlight the share of a high-quality ingredient in a way that misleads customers about the composition – responsibility lies with the advertiser, not the agency.

Relevance to training and awareness

Product advertising and labelling of composition

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 32 Abs. 1 i. V. m. Art. 33 ZZK
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Original amount 405,936 BGN, converted at the ECB reference rate of 24 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jul 2025 Metex Heat Treating Ltd.Heat treatment firm Metex: CA$144,000 after flash fire during furnace start-up Canada, ONWorkplace safety and accidents €89,949

When restarting a hardening furnace (hydrogen and oil quench bath) that had been shut down for weeks, residual vapours ignited because too much time elapsed between the nitrogen purge and ignition; two workers were seriously injured. Only one was wearing flame-resistant clothing; the other had not been provided with any. Fine of CA$144,000 plus victim fine surcharge.

What organisations can take from it

Infrequently performed tasks such as restarting equipment require fixed step-by-step procedures and complete protective equipment for everyone involved.

Relevance to training and awareness

Start-up procedures for industrial furnaces; protective clothing

Authority / court
Ontario Court of Justice Brampton (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 25(2)(h) Occupational Health and Safety Act (Ontario)
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Mitigating circumstances
Guilty plea.
Published
21 Aug 2025

Original amount 144,000 CAD, converted at the ECB reference rate of 24 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jul 2025 Slovenský pozemkový fondSlovak Land Fund: 6,000 EUR for late examination of a whistleblower report SlovakiaMissing or inadequate reporting channel €6,000

The state land fund examined a report from September 2022 only after 128 days and, until November 2024, did not sufficiently inform employees about the reporting procedure, protection options and the responsible person. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 6,000 EUR.

What organisations can take from it

Whistleblower reports are subject to statutory examination deadlines – anyone who misses them and does not publicise the procedure will be sanctioned.

Relevance to training and awareness

Deadlines and transparency in the internal reporting system

Authority / court
Úrad na ochranu oznamovateľov (Slowakei)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
§ 10 Abs. 5 und 8, § 19 Gesetz Nr. 54/2019 über den Schutz von Hinweisgebern (UOO-277/2025)
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Culpability
negligent

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers EstoniaData subject rights and transparency Order

The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.

What organisations can take from it

Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jul 2025 Condor Courtiers & Conseillers S.à r.l.Condor Courtiers & Conseillers: licence withdrawn for using unlicensed introducers LuxembourgOrganisational requirements Other

Following an on-site inspection in 2024, the Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broker’s licence (effective 15 September 2025): there was no effective management by approved managers, unlicensed ‘introducers’ were de facto selling insurance, and the broker’s licence, together with its sub-intermediary network, was improperly made available to third parties.

What organisations can take from it

A distribution licence is not transferable – anyone who ‘rents it out’ to third parties or lets introducers sell risks having it withdrawn.

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 273, 274, 283, 286, 303
Action
Other
Status of proceedings
unknown
Sector
Financial services and insurance
Published
16 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords CroatiaData breaches and data security €320,000

The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).

What organisations can take from it

Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.

Relevance to training and awareness

Secure password storage in software development

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 31, Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
22 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2025 British Columbia Lottery CorporationFINTRAC: CAD 1,075,000 penalty on British Columbia Lottery Corporation for 3 violations of anti-money laundering obligations CanadaSuspicious activity reports €674,531

According to FINTRAC, British Columbia Lottery Corporation is a reporting entity in the casino sector based in Kamloops, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 1,075,000 on the company on 17 July 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, written compliance policies and procedures and enhanced measures for high-risk situations. Specifically, according to FINTRAC, two suspicious transaction reports were missing; the corporation also failed to identify a patron as high risk despite the rate of play and volume of funds and did not apply enhanced due diligence. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on British Columbia Lottery Corporation", published 28 August 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-08-28-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1), 9.6(3); PCMLTF Regulations 156(1)(b), 157; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
28 Aug 2025

Original amount 1,075,000 CAD, converted at the ECB reference rate of 17 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2025 Interactive Brokers LLCOFAC: USD 11.8 million settlement with Interactive Brokers over services for customers in sanctioned jurisdictions and blocked persons USABreaches of sanctions and embargoes €10.1m

Online broker Interactive Brokers LLC of Greenwich, Connecticut, is paying USD 11,832,136 under a settlement with OFAC for apparent violations of multiple sanctions programmes. According to OFAC's findings, between July 2016 and January 2024 the company provided brokerage and investment services to persons in Iran, Cuba, Syria and Crimea, processed trades in securities covered by the Chinese Military-Industrial Complex programme, carried out transactions involving blocked persons under several programmes and made prohibited new investment in Russia; 12,367 transactions were involved in total. OFAC treated the apparent violations as non-egregious and voluntarily self-disclosed and credited significant remediation and cooperation; the base penalty was USD 60,130,059. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "Interactive Brokers LLC Settles with OFAC for $11,832,136 Related to Apparent Violations of Multiple Sanctions Regulations", 15 July 2025, https://ofac.treasury.gov/media/934501/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
E.O. 13685 § 1(a)(iii), E.O. 14024 §§ 1, 4(a), E.O. 14071 § 1(a)(i); 31 C.F.R. § 515.201 (Kuba), §§ 542.201, 542.207 (Syrien), § 560.204 (Iran), § 583.201 (Global Magnitsky), § 586.201 (Chinese Military-Industrial Complex), § 587.201 (Russian Harmful Foreign Activities), § 591.201 (Venezuela); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
15 Jul 2025

Original amount 11,832,136 USD, converted at the ECB reference rate of 15 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2025 Barclays Bank PlcFCA: £39.3m fine for Barclays Bank Plc over money laundering risks of a corporate client United KingdomCustomer due diligence €45.4m

On 14 July 2025 the FCA fined Barclays Bank Plc £39,314,700 for breaching Principle 2 (due skill, care and diligence). The FCA found that between January 2015 and April 2021 the bank did not properly identify, assess and monitor the money laundering risks posed by one corporate client: apart from March 2019 to May 2020 it treated the client as low risk without knowing enough about its business or where its wealth and funds came from, and it did not reassess that rating when new warning signs emerged. Barclays settled with the FCA and received a 30% discount; without it the fine would have been £56,163,900.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
FCA Principle 2; section 206 FSMA 2000
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance

Original amount 39,314,700 GBP, converted at the ECB reference rate of 14 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2025 Barclays Bank UK PLCFCA: £3.1m fine for Barclays Bank UK over opening a client money account for a wealth manager United KingdomCustomer due diligence €3.57m

The FCA fined Barclays Bank UK PLC £3,093,600. The FCA found that between January 2021 and April 2023 the bank did not gather sufficient information on the purpose and risks of a client money account it opened for a wealth manager; around £34 million was paid into the account. The FCA saw this as evidence of wider weaknesses in opening such accounts. The bank also agreed a voluntary payment of about £6.3 million for the wealth manager's clients.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
FCA Principle 3; SYSC 6.1.1R; section 206 FSMA 2000
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance

Original amount 3,093,600 GBP, converted at the ECB reference rate of 14 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Jul 2025 Canadian National Exhibition AssociationFINTRAC: CAD 199,000 penalty on Canadian National Exhibition Association for 2 violations of anti-money laundering obligations CanadaInternal controls €124,321

According to FINTRAC, Canadian National Exhibition Association is a reporting entity in the casino sector based in Toronto, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 199,000 on the company on 11 July 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 2 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned assessing and documenting money laundering and terrorist financing risks and the prescribed review of the compliance programme. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on CNE Casino", published 4 September 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-09-04-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(c), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
4 Sep 2025

Original amount 199,000 CAD, converted at the ECB reference rate of 11 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert ItalyIncident reporting obligations €80,000

A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.

What organisations can take from it

Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.

Relevance to training and awareness

Identity verification for customer requests by e-mail (social engineering)

Authority / court
Garante per la protezione dei dati personali
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jul 2025 Wise US, Inc.Six US states: 4.2 million USD against Wise US over AML programme deficiencies USA, NYSuspicious activity reports €3.59m

In a coordinated multistate proceeding brought by six states – the New York State Department of Financial Services (NYDFS) with the supervisory authorities of CA, MN, NE, TX and MA – the money transmitter must pay 4.2 million USD. An examination (July 2022 to September 2023) found, among other things, a lack of independent AML reviews at an appropriate frequency, late suspicious activity reports, data quality problems in transaction monitoring and unremedied earlier findings; Wise does not admit any legal infringements and must conduct a lookback.

What organisations can take from it

Remedy findings from earlier examinations and audits on time – otherwise they become a ground for sanctions in their own right.

Authority / court
New York State Department of Financial Services (NYDFS) mit den Aufsichtsbehörden von CA, MN, NE, TX und MA
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Bundes- und einzelstaatliches Recht zu Geldtransfer und BSA/AML (u. a. 31 CFR 1022.320)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Remedial measures already initiated and lookback
Published
9 Jul 2025

Original amount 4,200,000 USD, converted at the ECB reference rate of 9 Jul 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jul 2025 Share buyback disclosed too late: BVwG reduces FMA penalty against real estate company AustriaDisclosure and reporting obligations €300,000

On Saturday, 17 December 2022, the management board of a listed real estate company (anonymised in the judgment) approved by email a new share buyback programme including its volume, period and price, but only published it after a formal resolution on Monday, 19 December 2022. Austria's Financial Market Authority (FMA) imposed a penalty of 375,000 EUR; the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) upheld the breach of the ad hoc disclosure obligation but reduced the penalty to 300,000 EUR.

What organisations can take from it

A final decision by a corporate body triggers the ad hoc disclosure obligation immediately – weekends and outstanding contractual details do not postpone it.

Relevance to training and awareness

Ad hoc disclosure obligation for decisions of corporate bodies, including at weekends

Authority / court
Bundesverwaltungsgericht (Beschwerde gegen Straferkenntnis der Finanzmarktaufsicht FMA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 MAR i. V. m. § 156 Abs. 3 Z 2, Abs. 4 BörseG 2018
Action
Fine
Status of proceedings
reduced
Sector
Construction and real estate
Culpability
negligent

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jul 2025 TreasureMeta CorporationFINTRAC: CAD 24,750 penalty on TreasureMeta Corporation for one violation of anti-money laundering obligations CanadaInternal controls €15,440

According to FINTRAC, TreasureMeta Corporation is a money services business based in Markham, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 24,750 on the company on 9 July 2025. According to FINTRAC's findings, made in the course of its supervisory activity, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned money services business registration requirements. The publication does not mention any pending review. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on TreasureMeta Corporation", published 5 February 2026, https://fintrac-canafe.canada.ca/pen/amps/pen-2026-02-05-1-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTF Registration Regulations s. 4(b), 5; Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Feb 2026

Original amount 24,750 CAD, converted at the ECB reference rate of 9 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jul 2025 Department of National Defence (Kanada)Canada's Department of National Defence pays 10,000 CAD for destroyed hawk nest Canada, ABEnvironment and sustainability €6,238

During fence removal work at Canadian Forces Base Suffield, heavy machinery destroyed an occupied nest of the protected ferruginous hawk together with three eggs. The Department of National Defence pleaded guilty to two counts under the Species at Risk Act and was fined 10,000 CAD.

What organisations can take from it

Construction and dismantling work on military land also requires a prior species protection assessment and briefed machine operators.

Relevance to training and awareness

Species protection during construction work

Authority / court
Alberta Court of Justice (Anklage: Environment and Climate Change Canada)
Area of law
Environment and sustainability
Legal basis
Species at Risk Act, s. 32(1) und s. 33
Action
Fine
Status of proceedings
final
Sector
Defence and security
Employees
10,000 or more
Published
30 Jul 2025

Original amount 10,000 CAD, converted at the ECB reference rate of 9 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jul 2025 Barents Reinsurance S.A.Barents Reinsurance: maximum fine of 250,000 EUR over governance deficiencies LuxembourgOrganisational requirements €250,000

The reinsurer breached the principle of specialisation in reinsurance business, its approved manager was not effectively present on site and had insufficient powers, the governance system including oversight of outsourced functions was inadequate, and orders from a 2019 inspection had not been implemented or only partially. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed the statutory maximum of 250,000 EUR; the company cooperated.

What organisations can take from it

On-site substance is a supervisory requirement: management, powers and oversight of outsourced functions must genuinely be located in the home country.

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 49, 71, 81, 274, 303
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cooperation with the CAA during and after the inspection.
Published
8 Aug 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2025 Monzo Bank LimitedFCA: £21 million against Monzo over lax account opening for high-risk customers United KingdomCustomer due diligence €24.5m

The UK Financial Conduct Authority (FCA) imposed £21,091,300 (after a 30% discount) because, from 2018 to 2020, Monzo onboarded customers on the basis of sparse and sometimes obviously implausible information – such as well-known London landmarks given as addresses. Despite a requirement not to take on any more high-risk customers, the bank opened more than 34,000 such accounts up to 2022.

What organisations can take from it

Automated onboarding needs plausibility checks – and supervisory requirements must be implemented in a technically effective way.

Relevance to training and awareness

Plausibility checks in customer onboarding

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
FCA Principle 3 (PRIN 3); s. 55L FSMA (Verstoß gegen Auflage)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Published
8 Jul 2025

Original amount 21,091,300 GBP, converted at the ECB reference rate of 7 Jul 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 ATE, s. r. o.; AŽD Praha s.r.o.; EPLcond a.s.; MONZAS, a.s.; První SaZ Plzeň a.s.; STARMON s.r.o.Railway signalling: 157.7 million CZK against six companies for bid rigging CzechiaCartels and collusion €6.39m

The six companies colluded on cover bids, market sharing and prices in 26 contracts awarded by the state railway infrastructure administration (total value over 850 million CZK, 2015–2021). In a settlement procedure, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a total of 157.693 million CZK at first instance; two companies appealed against the amount.

What organisations can take from it

A cover bid submitted ‘as a favour’ is bid rigging – sales and costing teams must be aware of this.

Relevance to training and awareness

Cover bids and collusion in public tenders

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (Submissionsabsprachen)
Action
Fine
Status of proceedings
under appeal
Sector
Construction and real estate
Culpability
intentional
Mitigating circumstances
Settlement (20% reduction, no procurement ban), leniency application by one participant and compliance programmes at two companies.
Published
2 Jul 2025

Original amount 157,693,000 CZK, converted at the ECB reference rate of 2 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Key Holding, LLCLogistics company Key Holding: Colombian subsidiary organised 36 shipments to Cuba USABreaches of sanctions and embargoes €517,929

After the acquisition of a Colombian logistics company in December 2021, the latter organised 36 freight shipments to Cuba worth around 3.06 million USD up to July 2023. Neither the US parent nor the subsidiary had a sanctions compliance programme for foreign companies; the US Treasury's Office of Foreign Assets Control (OFAC) assessed the case as non-egregious and voluntarily self-disclosed.

What organisations can take from it

After an acquisition, roll out the sanctions compliance programme to the new foreign subsidiary immediately – the Cuba embargo applies to US-controlled subsidiaries worldwide.

Relevance to training and awareness

Sanctions compliance after acquisitions

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Cuban Assets Control Regulations (31 C.F.R. part 515)
Action
Fine
Status of proceedings
final
Sector
Transport, logistics and shipping
Culpability
negligent
Repeat case
no
Mitigating circumstances
Voluntary self-disclosure, no prior violations, remedial measures after discovery
Published
2 Jul 2025

Original amount 608,825 USD, converted at the ECB reference rate of 2 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data CroatiaData breaches and data security €101,000

Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.

Relevance to training and awareness

Access control and deletion periods for register data

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cap due to public tasks (Art. 44 of the Implementing Act).
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Swilly Mulroy Credit Union LimitedIreland: small credit union accepted cash from non-members without checks IrelandCustomer due diligence €36,273

Between 2014 and 2021, the credit union solicited cash from persons without an account and accepted 2,329 cash deposits totalling 8.75 million EUR without the required anti-money laundering checks; the board had known about the risk since 2015, and there was no self-reporting. The Central Bank of Ireland imposed a reprimand and 36,273 EUR (after a 30% discount on 51,819 EUR).

What organisations can take from it

Even small cooperative banks must identify cash from non-customers – and would do better to self-report known risks.

Relevance to training and awareness

Identification for cash deposits by non-customers

Authority / court
Central Bank of Ireland
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010; Credit Union Act 1997
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
30% settlement discount
Liability of senior managers
The board had known about the risks since 2015 without taking remedial action
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 9321-0599 Québec Inc.FINTRAC: CAD 23,100 penalty on 9321-0599 Québec Inc. for 2 violations of anti-money laundering obligations CanadaInternal controls €14,401

According to FINTRAC, 9321-0599 Québec Inc. is a real estate brokerage based in Brossard, Québec. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 23,100 on the company on 2 July 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 2 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures and assessing and documenting money laundering and terrorist financing risks. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on 9321-0599 Québec Inc.", published 20 November 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-11-20-1-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Construction and real estate
Published
20 Nov 2025

Original amount 23,100 CAD, converted at the ECB reference rate of 2 Jul 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Jul 2025 Healthline Media LLCCalifornia: $1.55 million against Healthline over disclosure of illness-related article titles USA, CACookies and tracking €1.31m

Despite objections, the health portal continued to pass data to advertising partners and transmitted article titles suggestive of diagnoses for targeted advertising; the consent banner did not stop the tracking. In addition, the required contractual clauses with advertising partners were missing. The settlement was reached with the Attorney General of California.

What organisations can take from it

Test consent banners technically: if rejecting does not actually switch off tracking, that is misleading and unlawful.

Authority / court
Attorney General of California (California Department of Justice)
Area of law
Data protection · Cookies and tracking
Legal basis
California Consumer Privacy Act (CCPA), Unfair Competition Law
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
1 Jul 2025

Original amount 1,550,000 USD, converted at the ECB reference rate of 1 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2025 SIA "Mārupes komunālie pakalpojumi"Water utility Mārupes komunālie pakalpojumi abuses monopoly over additional meters LatviaAbuse of market power €78,056

From January 2022, by internal instruction, the municipal water utility reserved to itself the installation of additional water meters (for example for garden water), thereby excluding other providers; customers also had to pay for sewerage they did not use. The Konkurences padome (Latvian Competition Council) found an abuse of a dominant position, imposed 78,055.79 EUR and ordered remedies.

What organisations can take from it

Municipal utilities are also subject to competition law – internal instructions that foreclose neighbouring markets are risky.

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 13 Konkurences likums
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
9 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2025 Harman International Industries, Inc.OFAC: USD 1.45 million settlement with Harman over diversion of products to Iran via a UAE distributor USABreaches of sanctions and embargoes €1.25m

Audio electronics group Harman International Industries, Inc. of Connecticut is paying USD 1,454,145 under a settlement with OFAC for eleven apparent violations of the Iran sanctions. According to OFAC's findings, from May 2018 to October 2020 its long-standing distributor in the United Arab Emirates sold Harman products to customers in Iran with the knowledge and support of 13 UK-based employees of its US subsidiary Harman Professional, Inc.; their conduct is attributable to Harman. OFAC treated the apparent violations as egregious but voluntarily self-disclosed; the base penalty was USD 2,077,350. Harman satisfies USD 400,000 of the settlement amount by investing in additional sanctions controls. OFAC signed the settlement agreement on 25 June 2025 and published it on 8 July 2025. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "Harman International Industries, Inc. Settles with OFAC for $1,454,145 Related to Apparent Violations of Iranian Transactions and Sanctions Regulations", 8 July 2025, https://ofac.treasury.gov/media/934471/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204(a) (elf mutmaßliche Verstöße); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Published
8 Jul 2025

Original amount 1,454,145 USD, converted at the ECB reference rate of 25 Jun 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names GreeceData processors €700,000

Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.

What organisations can take from it

Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.

Relevance to training and awareness

Identity verification when concluding contracts in partner distribution

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2025 Brantner Fatra, s.r.o.Brantner Fatra: 180,200 EUR for excessive landfill prices charged to two towns upheld SlovakiaAbuse of market power €180,200

In 2019–2022, the waste management company charged the towns of Martin and Vrútky significantly higher prices for landfilling residual waste than other municipalities without objective justification, although they had no alternative. The Council of the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) upheld the fine of 180,200 EUR; the decision became final on 3 July 2025.

What organisations can take from it

Suppliers without a local alternative must be able to justify and document price differences between customers on objective grounds.

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Abuse of market power
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Missbrauch einer marktbeherrschenden Stellung)
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Published
9 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2025 Banca Privata Leasing SpaBanca d'Italia: 60,000 EUR against Banca Privata Leasing over deficiencies in AML organisation ItalyInternal controls €60,000

An on-site inspection from February to May 2024 revealed deficiencies in organisation and internal controls relating to customer profiling, due diligence obligations and active cooperation (suspicious transaction reports). The Bank of Italy (Banca d'Italia) imposed an administrative fine of 60,000 EUR, taking into account the corrective measures taken.

What organisations can take from it

Sound customer profiling is the basis for risk-appropriate due diligence and reporting.

Authority / court
Banca d'Italia
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–20, 24, 25, 35, 36 d.lgs. 231/2007
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Corrective measures taken

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2025 Pacesetter Marketing Ltd.FINTRAC: CAD 41,085 penalty on Pacesetter Marketing Ltd. for 3 violations of anti-money laundering obligations CanadaInternal controls €25,815

According to FINTRAC, Pacesetter Marketing Ltd. is a real estate brokerage based in Vancouver, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 41,085 on the company on 24 June 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks and the prescribed review of the compliance programme. According to FINTRAC, the company is paying the penalty in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Pacesetter Marketing Ltd.", published 20 November 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-11-20-2-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(f), 156(3); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Published
20 Nov 2025

Original amount 41,085 CAD, converted at the ECB reference rate of 24 Jun 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2025 BirthlinkICO: £18,000 fine for charity Birthlink over destroyed records United KingdomData breaches and data security €21,109

The ICO fined the Scottish charity Birthlink £18,000. The ICO found that the organisation had destroyed around 4,800 personal records; according to the ICO, up to ten per cent of them may be irreplaceable.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5(1)(f), 5(2), 32(1)-(2) und 33 UK GDPR; section 155 DPA 2018
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 18,000 GBP, converted at the ECB reference rate of 24 Jun 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2025 Slovenská asociácia palivového priemyslu a obchoduFirst labour market cartel: fuel association sanctioned for no-poach rule SlovakiaCartels and collusion €10,000

In a ‘code of ethics’, the industry association obliged its members not to poach each other’s employees. In its first decision on labour market cartels, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a symbolic fine of 10,000 EUR (first instance) as a warning to business.

What organisations can take from it

No-poach agreements between competitors are cartels – HR departments and associations should review existing codes.

Relevance to training and awareness

No-poach agreements and HR departments

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Beschluss einer Unternehmensvereinigung)
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2025 C2D Payment Solutions LimitedMalta: 243,537 EUR against C2D Payment Solutions for ignoring cash risks MaltaCustomer due diligence €243,537

The financial institution did not take into account its customers’ significant cash exposure in its customer risk assessment, so that almost all customers were rated low risk – even with cash deposits of over 100,000 EUR. The Financial Intelligence Analysis Unit (FIAU) imposed 243,537 EUR and a follow-up directive; the fine was open to appeal at the time of publication.

What organisations can take from it

Cash is an explicit high-risk factor – a risk model that ignores it is worthless.

Relevance to training and awareness

Recognising cash as a risk factor

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 7(1)(c), 7(1)(d), 7(2)(a), 21 PMLFTR
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
23 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jun 2025 Saxony: 7,000 EUR fine against art dealer over due diligence obligations and risk management GermanyInternal controls €7,000

The Saxony State Directorate (Landesdirektion Sachsen), as anti-money laundering supervisor for the non-financial sector, imposed a fine of 7,000 EUR on an art dealer, announced in anonymised form, for breaches of the due diligence obligations and risk management requirements under the German Money Laundering Act (GwG). The authority had previously issued several orders on risk management in the art trade, backed by the threat of penalty payments.

What organisations can take from it

Art dealers need a written risk analysis and must identify buyers for transactions of 10,000 EUR or more.

Relevance to training and awareness

AML obligations in the art trade

Authority / court
Landesdirektion Sachsen (Geldwäscheaufsicht Nichtfinanzsektor)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Geldwäschegesetz (Sorgfaltspflichten, Risikomanagement); Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jun 2025 Exclusive Networks Corporate SASIT distributor Exclusive Networks: CJIP of 16 million EUR following a whistleblower report FranceCommercial bribery €16.1m

In 2021, a whistleblower reported payments by subsidiaries in Indonesia, Malaysia, Vietnam, Thailand and India to contractual partners; the investigation concerned private-sector bribery and bribery of foreign public officials. The CJIP provides for a public interest fine of 16,074,511 EUR (including 1 million EUR already seized) and a three-year AFA compliance programme.

What organisations can take from it

A functioning whistleblowing system uncovers foreign risks – companies should investigate reports themselves before the authorities do.

Relevance to training and awareness

Payments to sales partners in Asia, whistleblowing systems

Authority / court
Parquet national financier (PNF); Validierung durch das Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Commercial bribery
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung im privaten Sektor und ausländischer Amtsträger
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
1,000 to 9,999
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2025 Waxholms Ångfartygs AktiebolagWaxholmsbolaget: fine for processing a captain’s breathalyser test results SwedenEmployee data €6,801

The shipping company processed results of on-board breath alcohol tests that could be attributed to a complainant employed as a captain. The Swedish Authority for Privacy Protection (IMY) regarded this as processing without a legal basis and as unlawful processing of health data and imposed 75,000 SEK.

What organisations can take from it

Monitoring data such as alcohol test results are employees’ health data – access, storage and legal basis must be settled before such tests are introduced.

Relevance to training and awareness

Employee health data (alcohol tests)

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Employee data
Legal basis
DSGVO Art. 6, Art. 9
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
18 Jun 2025

Original amount 75,000 SEK, converted at the ECB reference rate of 18 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2025 AliExpressAliExpress: DSA commitments on illegal products and trader transparency made binding EU levelPlatform obligations Order

The European Commission declared binding commitments by AliExpress relating, among other things, to the detection of illegal products such as medicines and food supplements (including via hidden links and affiliate programmes), the notice and complaint system, the transparency of advertising and recommender systems, the traceability of traders and data access for researchers; an independent monitoring trustee oversees implementation. In parallel, it made a preliminary finding of a breach of the obligation to carry out a risk assessment.

What organisations can take from it

Marketplaces must systematically detect illegal products – including where they are offered via detours such as affiliate links.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Art. 71 Digital Services Act (Verordnung (EU) 2022/2065)
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2025 Banque Pictet et Cie SABanque Pictet: 2 million CHF fine for laundering Petrobras bribes SwitzerlandInternal controls €2.13m

Between 2010 and 2013, an asset manager at the bank validated 54 transfers through which bribes of around 4.1 million USD connected with SBM Offshore's charter contracts with Petrobras were concealed. The bank had not classified high-risk accounts as such and had inadequately monitored transfers; the Office of the Attorney General of Switzerland (Bundesanwaltschaft) imposed a fine of 2 million CHF, and the former employee received a suspended prison sentence.

What organisations can take from it

Risk classification and transaction monitoring must take effect before individual relationship managers approve payments.

Relevance to training and awareness

High-risk clients and transaction monitoring

Authority / court
Bundesanwaltschaft
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 102 Abs. 2 StGB i. V. m. Art. 305bis und Art. 322septies StGB
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Time elapsed since the offence, very good cooperation, organisational corrective measures after the Petrobras affair became known.
Liability of senior managers
Former asset manager: suspended prison sentence of six months (probation period of two years).
Published
17 Jun 2025

Original amount 2,000,000 CHF, converted at the ECB reference rate of 17 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2025 Safran S.A.Safran/Collins: clearance only in exchange for sale of actuation businesses United KingdomMerger control Order

The Competition and Markets Authority (CMA) found that Safran’s acquisition of part of the actuation and flight control business of Collins Aerospace (RTX) would result in a substantial lessening of competition in horizontal stabiliser trim actuators. Clearance was granted only in return for the undertaking to divest Safran’s North American actuation business, including sites in Mexico, California and Canada, to a pre-approved purchaser (Woodward).

What organisations can take from it

In acquisitions in concentrated supply markets, prepare remedies including a buyer early – here the CMA required an upfront buyer.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Competition law · Merger control
Legal basis
Enterprise Act 2002, s. 73 (Undertakings in lieu of reference)
Action
Order
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Employees
10,000 or more
Published
23 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2025 Unicat Catalyst Technologies, LLCCatalyst manufacturer Unicat supplied Iran and blocked Venezuelan company USABreaches of sanctions and embargoes €3.35m

In 2016–2021, the Texas supplier of catalysts for refineries and steelworks supplied products and advice to customers in Iran via its former CEO, employees and agents, and sold goods to a blocked Venezuelan company. The US Treasury's Office of Foreign Assets Control (OFAC) considered it an egregious but voluntarily self-disclosed case; there were parallel settlements with the DOJ and BIS, which were taken into account in determining the amount.

What organisations can take from it

When senior management itself steers embargo business, only independent controls and whistleblower channels help – voluntary self-disclosure after discovery reduces the penalty but does not prevent it.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations; Venezuela Sanctions Regulations; IEEPA
Action
Fine
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure, cooperation and remedial measures after discovery
Liability of senior managers
According to OFAC, the violations were carried out by the former CEO and co-founder as well as former employees.
Published
16 Jun 2025

Original amount 3,882,797 USD, converted at the ECB reference rate of 16 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2025 Ústredie práce, sociálnych vecí a rodinyCentral Office ÚPSVaR: 5,000 EUR – reporting office for children’s homes not operated SlovakiaMissing or inadequate reporting channel €5,000

For months, the central authority failed to perform the tasks of the reporting office for three centres for children and families under its authority and did not make the responsible person known to employees. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 5,000 EUR; the appeal decision of 12 September 2025 reworded the operative part but left the fine at 5,000 EUR.

What organisations can take from it

Anyone running the reporting office for subordinate units must also make it visible there and handle reports from those units.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 3 und 5, § 19 Abs. 3
Action
Fine
Status of proceedings
final
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2025 GVA Capital Ltd.OFAC: USD 216 million penalty on GVA Capital over managing an investment for a sanctioned oligarch USABreaches of sanctions and embargoes €186.3m

OFAC has imposed the statutory maximum penalty of USD 215,988,868 on San Francisco venture capital firm GVA Capital Ltd. by way of a Penalty Notice. According to OFAC's findings, between April 2018 and May 2021 GVA Capital knowingly managed an investment for a sanctioned Russian oligarch despite knowing of his blocked status, working with a relative who acted as his proxy. The company also failed to comply fully with an OFAC subpoena for 28 months. OFAC treated the violations as egregious and not voluntarily self-disclosed. The Penalty Notice was preceded by Pre-Penalty Notices dated 13 September 2023 and 22 August 2024. The publication does not mention any pending review. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "OFAC Imposes $215,988,868 Penalty on GVA Capital Ltd. for Violating Ukraine/Russia-Related Sanctions and Reporting Obligations", 12 June 2025, https://ofac.treasury.gov/media/934366/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Ukraine-/Russia-Related Sanctions Regulations, 31 C.F.R. §§ 589.201(a)(3), 589.201(b)(1), 589.213(a); Reporting, Procedures and Penalties Regulations, 31 C.F.R. § 501.602 (28 Verstöße, Subpoena); Penalty Notice nach 31 C.F.R. § 589.703 und den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
12 Jun 2025

Original amount 215,988,868 USD, converted at the ECB reference rate of 12 Jun 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2025 Department of Social Protection (DSP)DPC: 550,000 EUR against Irish social protection ministry over facial matching without legal basis IrelandData subject rights and transparency €550,000

For registration for the Public Services Card, the ministry created biometric facial templates of a large part of the population without a sufficiently clear legal basis, with deficient information and an incomplete data protection impact assessment. Ireland's Data Protection Commission (DPC) issued a reprimand, imposed 550,000 EUR and ordered the biometric processing to be stopped within nine months if no valid legal basis is found.

What organisations can take from it

Biometric procedures require a precise statutory basis and a complete impact assessment before they are rolled out widely.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und e, Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 Abs. 7 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Mitigating circumstances
No deficiencies were found in the technical and organisational security measures.
Published
12 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2025 Ville de LongueuilCity of Longueuil pays 30,000 CAD for mowing that destroyed a protected bird's nest Canada, QCEnvironment and sustainability €18,979

During mowing work in the municipal Parc des Sorbiers in July 2024, at least one nest of the protected bobolink was destroyed; a citizen reported the find. The city pleaded guilty under the Species at Risk Act and is paying 30,000 CAD.

What organisations can take from it

Maintenance plans for green spaces must take into account the breeding seasons of protected species, and the teams carrying out the work must be briefed accordingly.

Relevance to training and awareness

Species protection in green space maintenance

Authority / court
Court of Québec (Anklage: Environment and Climate Change Canada)
Area of law
Environment and sustainability
Legal basis
Species at Risk Act, s. 33
Action
Fine
Status of proceedings
final
Sector
Public sector
Published
12 Jun 2025

Original amount 30,000 CAD, converted at the ECB reference rate of 12 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Jun 2025 Svea Finance AS200,000 EUR fine against Svea Finance over deficient creditworthiness assessment EstoniaConsumer protection and online retail €200,000

Between December 2023 and February 2024, Svea Finance’s internal rules on consumer lending did not comply with the law (50,000 EUR), and the company concluded credit agreements without assessing all prescribed creditworthiness components (150,000 EUR). Fines totalling 200,000 EUR for two misdemeanours. Date = publication.

What organisations can take from it

Creditworthiness assessments must cover all factors prescribed by law – gaps in internal policies are sanctioned separately.

Relevance to training and awareness

Responsible lending

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail
Legal basis
§ 98 Abs. 2 und § 99 Abs. 2 KAVS
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jun 2025 SMCP SA; European TopSoho S.à r.l.; Dynamic Treasure GroupSMCP: threshold notifications missed, misleading announcement, inside information not protected FranceMarket abuse and insider dealing €1.72m

In connection with the change of control at the fashion group SMCP in 2021/22, the major shareholder European TopSoho (ETS) and Dynamic Treasure Group failed to make threshold notifications; ETS also disseminated a misleading press release. SMCP itself failed to maintain the confidentiality of inside information. Sanctions imposed by the Enforcement Committee of France's financial markets authority (Autorité des marchés financiers, AMF): Chenran Qiu 1 million EUR, ETS 400,000 EUR, DTG 300,000 EUR, SMCP 20,000 EUR.

What organisations can take from it

Issuers must effectively shield inside information even when the conflict originates with the major shareholder.

Relevance to training and awareness

Ensuring the confidentiality of inside information

Authority / court
Autorité des marchés financiers (AMF), Commission des sanctions
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Art. L. 233-7 Code de commerce; Art. 223-14 RG AMF; Art. 12 Abs. 1 lit. c MAR; Art. 2 Abs. 1 DVO (EU) 2016/1055
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce
Liability of senior managers
Chenran Qiu: 1,000,000 EUR (ETS's infringements attributed to her)
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Jun 2025 AmazonAmazon commits to the CMA to tougher action against fake reviews United KingdomFake reviews Order

Following an investigation into fake reviews and "catalogue abuse" (transferring good reviews to other products), Amazon undertook to the CMA to detect and remove such reviews quickly, to sanction infringing sellers up to and including a ban on selling, and to set up simple reporting channels.

What organisations can take from it

Anyone who publishes reviews must maintain active processes against fakes and the transfer of reviews.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Enterprise Act 2002, Part 8 (Verpflichtungszusagen nach altem Durchsetzungsregime)
Action
Order
Status of proceedings
final
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Voluntary undertakings without a fine.
Published
6 Jun 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Jun 2025 South Yorkshire PoliceICO: Reprimand for South Yorkshire Police after loss of body-worn video footage United KingdomData breaches and data security Reprimand or warning

The ICO issued a reprimand to South Yorkshire Police. The ICO found that during a data transfer in July 2023, carried out by a third-party supplier within the digital evidence management system, 96,174 original body-worn video recordings were accidentally deleted. The ICO found that the force lacked appropriate technical and organisational security measures and could not demonstrate compliance. The action was based on the law-enforcement processing rules in Part 3 of the DPA 2018.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
section 34(3) und section 40 DPA 2018 (Part 3)
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data United KingdomData breaches and data security €2.74m

From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.

What organisations can take from it

Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
negligent
Published
17 Jun 2025

Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2025 CaixaBank, S.A.AEPD: 200,000 EUR against CaixaBank over continued storage of a non-customer's data SpainMarketing and consent €200,000

A person who was not (or no longer) a customer received a letter from CaixaBank about an update to its privacy statement, announcing that she would be contacted about her advertising preferences. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) considered the continued storage of her data to be an infringement of the principle of storage limitation and imposed 200,000 EUR; the bank's request for reconsideration was dismissed as inadmissible.

What organisations can take from it

Before mass mailings, check whether the recipients' data may still be stored at all – former customers should be deleted, not written to.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2025 Vodafone GmbHBfDI: 45 million EUR against Vodafone over fraud in partner agencies and authentication gaps GermanyData processors €45m

Malicious employees in partner agencies that broker contracts for Vodafone had created fictitious contracts and contract changes to the detriment of customers. The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed 15 million EUR for inadequate vetting and monitoring of the partner agencies (Art. 28) and 30 million EUR for authentication deficiencies in ‘MeinVodafone’ in combination with the hotline, through which unauthorised persons were able, among other things, to retrieve eSIM profiles; in addition, a reprimand was issued under Art. 32.

What organisations can take from it

Companies that outsource sales to partner agencies must audit how those agencies handle customer data and make misuse technically harder.

Relevance to training and awareness

Insider threats and oversight of sales partners

Authority / court
Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Area of law
Data protection · Data processors
Legal basis
Art. 28 Abs. 1 S. 1, Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Full cooperation including self-incrimination, modernisation of systems, separation from fraudulent partners; fines accepted and paid, plus donations amounting to millions.
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jun 2025 Delivery Hero SE, Glovoapp23 SAEU: 329 million EUR against Delivery Hero and Glovo – first labour market cartel EU levelCartels and collusion €329m

From July 2018 to July 2022, Delivery Hero and Glovo agreed a mutual no-poach arrangement, exchanged commercially sensitive information and allocated national markets; this was facilitated by Delivery Hero's minority stake in Glovo. Fines: Delivery Hero 223.285 million EUR, Glovo 105.732 million EUR (settlement procedure, 10 % reduction).

What organisations can take from it

No-poach clauses and information flows from stakes in competitors are high-risk under competition law and must be shielded by clean-team rules.

Relevance to training and awareness

No-poach agreements and information exchange via minority stakes

Authority / court
Europäische Kommission
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV, Art. 53 EWR-Abkommen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Settlement procedure (10 % reduction)

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jun 2025 LocalBitcoins OyLocalBitcoins: 500,000 EUR for failing to identify customers when opening accounts FinlandCustomer due diligence €500,000

During an inspection in 2024, the Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) found that the crypto trading platform had not identified and verified its customers when establishing permanent business relationships. Taking the company’s financial situation into account, it imposed 500,000 EUR; LocalBitcoins has appealed to the Helsinki Administrative Court.

What organisations can take from it

KYC is a prerequisite for every business relationship – not an obligation to be met retrospectively once volumes grow.

Relevance to training and awareness

Customer identification (KYC)

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Finnisches Geldwäschegesetz – Identifizierung und Verifizierung von Kunden
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
3 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jun 2025 HRA Group HoldingsFINTRAC: CAD 132,000 penalty on HRA Group Holdings for 4 violations of anti-money laundering obligations CanadaInternal controls €84,383

According to FINTRAC, HRA Group Holdings is a dealer in precious metals and stones based in Vancouver, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 132,000 on the company on 2 June 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme and the prescribed review of the compliance programme. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on HRA Group Holdings", published 2 October 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-10-02-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Published
2 Oct 2025

Original amount 132,000 CAD, converted at the ECB reference rate of 2 Jun 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 May 2025 Southern Gas Networks plcSouthern Gas Networks plc: 5.8 million GBP – gas leaks attended too slowly United KingdomOther €6.89m

In 2022/23, the gas distribution network operator failed to meet the licence requirement in its southern England network to attend 97% of reported gas escapes within one or two hours respectively. Following self-reporting, it acknowledged the breach and paid 5.8 million GBP into the Energy Industry Voluntary Redress Fund; the Office of Gas and Electricity Markets (Ofgem) pointed to the significant risk to the public.

What organisations can take from it

Emergency response times are a core duty for utility networks – staff and deployment planning must also cover peak loads.

Authority / court
Office of Gas and Electricity Markets (Ofgem)
Area of law
Other
Legal basis
Gas Transporter Licence, Standard Special Condition D10 2(h)
Action
Other
Status of proceedings
final
Sector
Energy and utilities
Mitigating circumstances
Self-reporting before the formal data submission; targets met for two years since.

Original amount 5,800,000 GBP, converted at the ECB reference rate of 30 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 May 2025 Cadent Gas LimitedCadent Gas Limited: 1.5 million GBP – gas leaks attended too slowly United KingdomOther €1.78m

In 2022/23, the gas distribution network operator failed to meet the licence requirement in its North London and North West networks to attend 97% of reported gas escapes within one or two hours respectively. Following self-reporting, it acknowledged the breach and paid 1.5 million GBP into the Energy Industry Voluntary Redress Fund; the Office of Gas and Electricity Markets (Ofgem) pointed to the significant risk to the public.

What organisations can take from it

Emergency response times are a core duty for utility networks – staff and deployment planning must also cover peak loads.

Authority / court
Office of Gas and Electricity Markets (Ofgem)
Area of law
Other
Legal basis
Gas Transporter Licence, Standard Special Condition D10 2(h)
Action
Other
Status of proceedings
final
Sector
Energy and utilities
Mitigating circumstances
Self-reporting before the formal data submission; targets met for two years since.

Original amount 1,500,000 GBP, converted at the ECB reference rate of 30 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 May 2025 Scotland Gas Networks plcScotland Gas Networks plc: 700,000 GBP – gas leaks attended too slowly United KingdomOther €832,145

In 2022/23, the gas distribution network operator failed to meet the licence requirement in its Scottish network to attend 97% of reported gas escapes within one or two hours respectively. Following self-reporting, it acknowledged the breach and paid 700,000 GBP into the Energy Industry Voluntary Redress Fund; the Office of Gas and Electricity Markets (Ofgem) pointed to the significant risk to the public.

What organisations can take from it

Emergency response times are a core duty for utility networks – staff and deployment planning must also cover peak loads.

Authority / court
Office of Gas and Electricity Markets (Ofgem)
Area of law
Other
Legal basis
Gas Transporter Licence, Standard Special Condition D10 2(h)
Action
Other
Status of proceedings
final
Sector
Energy and utilities
Mitigating circumstances
Self-reporting before the formal data submission; targets met for two years since.

Original amount 700,000 GBP, converted at the ECB reference rate of 30 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 May 2025 Xfera Móviles, S.A.U.AEPD: 200,000 EUR against Xfera (MásMóvil) over number porting without consent SpainData breaches and data security €200,000

A customer's mobile number was ported to MásMóvil without the customer having requested it; the new SIM card was handed over to a third party who did not identify themselves. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found processing without a legal basis, imposed 200,000 EUR and ordered measures against such incidents; the company's request for reconsideration was unsuccessful.

What organisations can take from it

Issue SIM cards and carry out porting only after robust identity verification – couriers and sales partners must comply with this too.

Relevance to training and awareness

Identity verification for porting and SIM handover (SIM swapping)

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 May 2025 Immobilienmakler aus Calgary, Alberta (anonymisiert)FINTRAC: CAD 117,975 penalty on Calgary real estate brokerage – CAD 63,987.50 paid after appeal was resolved CanadaCustomer due diligence €41,033

According to FINTRAC, the company concerned is a real estate brokerage based in Calgary, Alberta; its name is not given here. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 117,975 on the company on 29 May 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 5 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme, the prescribed review of the compliance programme and record keeping. According to FINTRAC, the policies were a generic template not tailored to the business; the account number was missing in all ten receipt of funds records reviewed. FINTRAC originally set the penalty at CAD 117,975. According to the regulator, the company appealed to the Federal Court; on 28 February 2026 the appeal was resolved, the company paid CAD 63,987.50 and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Public notice of administrative monetary penalties" (list, entry of 20 November 2025), https://fintrac-canafe.canada.ca/pen/4-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
PCMLTFA s. 6, 9.6(1); PCMLTF Regulations 58(1)(a), 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
reduced
Sector
Construction and real estate
Published
20 Nov 2025

Original amount 63,987.5 CAD, converted at the ECB reference rate of 29 May 2025.

Sources

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 AS Watson (Health & Beauty Continental Europe) B.V.AP reduces cookie fine against Kruidvat operator AS Watson to 50,000 EUR after objection NetherlandsCookies and tracking €50,000

The company behind the Kruidvat drugstore chain tracked visitors to Kruidvat.nl with tracking cookies without their knowledge or consent, enabling it to build profiles from location, pages visited, shopping basket and purchases. The Dutch data protection authority (Autoriteit Persoonsgegevens, AP) had imposed 600,000 EUR in 2024, upheld the objection in May 2025 and reduced the fine to 50,000 EUR.

What organisations can take from it

Set tracking cookies in an online shop only after genuine consent – pre-ticked or hidden consent is not sufficient.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 6 Abs. 1 i. V. m. Art. 5 Abs. 1 lit. a DSGVO (Tracking-Cookies ohne Einwilligung)
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
12 Jun 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine FinlandCookies and tracking overturned

In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).

What organisations can take from it

Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.

Relevance to training and awareness

Tracking pixels on sensitive websites

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
Area of law
Data protection · Cookies and tracking
Legal basis
DSGVO Art. 9, Art. 25, Art. 32
Action
Fine
Status of proceedings
overturned
Sector
Healthcare
Published
4 Jun 2025

Amount in EUR; no ECB reference rate is available for this currency.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2025 L3 Technologies Inc.L3 Technologies pays 62 million USD over false cost data for communications technology USAOther €54.8m

Between October 2006 and February 2014, the Communications System West division allegedly failed to disclose complete and current cost and pricing data when selling ROVER, VORTEX and SIR receivers to the Air Force, Army, Navy and other agencies. Settlement under the False Claims Act and the Truth in Negotiations Act of 62 million USD.

What organisations can take from it

In fixed-price negotiations with the government, costing data must be disclosed completely and on a current basis; price review processes belong in the compliance system.

Authority / court
U.S. Department of Justice (Civil Division) / USAO District of Utah
Area of law
Other
Legal basis
False Claims Act; Truth in Negotiations Act
Action
Other
Status of proceedings
final
Sector
Defence and security
Employees
10,000 or more
Published
22 May 2025

Original amount 62,000,000 USD, converted at the ECB reference rate of 22 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2025 Brunner Manufacturing & Sales Ltd. (Tecna Forge)Forge Tecna Forge: fatal fall during first-time press maintenance – CA$220,000 Canada, ONWorkplace safety and accidents €140,306

In 2023, two employees of the forge in Niagara Falls removed a spacer from a press for the first time; instead of the guide bolts prescribed in the manual, they used makeshift steel bolts and left the piston assembly, weighing around 1.25 t, hanging from the crane. The load swung out, and a worker fell to the ground with it and died. The company had not informed the employees of the dangers of deviating from the operating manual; fine of CA$220,000 plus victim fine surcharge.

What organisations can take from it

Maintenance tasks performed for the first time require instruction based on the manufacturer's manual – improvising with heavy loads ends in fatalities.

Relevance to training and awareness

Working in accordance with the operating manual on infrequent maintenance tasks

Missing or inadequate training played a role in the decision.

Authority / court
Provincial Offences Court Welland (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Section 25(2)(d) Occupational Health and Safety Act (Ontario)
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Mitigating circumstances
Guilty plea.
Published
20 Jun 2025

Original amount 220,000 CAD, converted at the ECB reference rate of 22 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 May 2025 HomeLife New World Realty Inc.FINTRAC: CAD 36,135 penalty on HomeLife New World Realty Inc. for 3 violations of anti-money laundering obligations CanadaCustomer due diligence €22,985

According to FINTRAC, HomeLife New World Realty Inc. is a real estate brokerage based in Toronto and Richmond Hill, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 36,135 on the company on 21 May 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks and record keeping. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on HomeLife New World Realty Inc.", published 20 November 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-11-20-4-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
PCMLTFA s. 6, 9.6(1); PCMLTF Regulations 58(1)(a), 58(1)(b), 156(1)(b), 156(1)(c), 156(2); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Published
20 Nov 2025

Original amount 36,135 CAD, converted at the ECB reference rate of 21 May 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 May 2025 London Borough of Hammersmith and FulhamICO: Reprimand for London Borough of Hammersmith and Fulham over hidden data in FOI response United KingdomData breaches and data security Reprimand or warning

The ICO issued a reprimand to the London Borough of Hammersmith and Fulham. The ICO found that, in answering a Freedom of Information request, the council released a spreadsheet that contained hidden data. This exposed personal data of 6,528 people, 2,342 of them children. The ICO criticised inadequate security measures and a failure to demonstrate compliance.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5(1)(f), 5(2), 24(1), 32(1)(b) UK GDPR; Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 May 2025 Primary Capital Inc.FINTRAC: CAD 93,390 penalty on Primary Capital Inc. for 4 violations of anti-money laundering obligations CanadaCustomer due diligence €59,693

According to FINTRAC, Primary Capital Inc. is a securities dealer or wealth management firm based in Toronto, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 93,390 on the company on 15 May 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the prescribed review of the compliance programme and determining politically exposed persons. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Primary Capital Inc.", published 18 September 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-09-18-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
PCMLTFA s. 9.3(1), 9.6(2); PCMLTF Regulations 119(1), 156(1)(b), 156(1)(c), 156(1)(f), 156(2), 156(3); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
18 Sep 2025

Original amount 93,390 CAD, converted at the ECB reference rate of 15 May 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 May 2025 Greater Manchester PoliceICO: Reprimand for Greater Manchester Police over subject access request backlog United KingdomData subject rights and transparency Reprimand or warning

The ICO issued a reprimand to the Chief Constable of Greater Manchester Police. The ICO found that, because of a persistent backlog of historic requests, the force repeatedly failed to answer subject access requests on time. The ICO found infringements of both the UK GDPR and the law-enforcement provisions of the DPA 2018.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12(3) und Art. 15 UK GDPR; section 45 und section 54 DPA 2018 (Part 3); Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2025 SAP SESAP: failure to publish notice on the 2022 annual financial report GermanyDisclosure and reporting obligations €1.75m

SAP had not published an announcement stating from when and at which internet address the 2022 annual financial report was publicly available in addition to the company register (Hinweisbekanntmachung). BaFin imposed a fine of 1.75 million EUR; the notice is final.

What organisations can take from it

Even seemingly formal disclosure steps such as the notice announcement need a fixed place in the financial calendar – the range of fines extends up to five per cent of total turnover.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 114 Abs. 1 Satz 2 WpHG
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
27 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2025 Canaccord Genuity Corp.FINTRAC: CAD 544,500 penalty on Canaccord Genuity Corp. for 4 violations of anti-money laundering obligations CanadaSuspicious activity reports €348,324

According to FINTRAC, Canaccord Genuity Corp. is a securities dealer or wealth management firm based in Vancouver, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 544,500 on the company on 14 May 2025. According to FINTRAC's findings, made during a compliance examination in 2023, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks and enhanced measures for high-risk situations. Specifically, FINTRAC found three missing suspicious transaction reports in 100 case files reviewed; in 14 files of high-risk clients reviewed, beneficial ownership and client information had not been updated. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Canaccord Genuity Corp.", published 3 July 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-07-03-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(2), 9.6(3); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(2); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
3 Jul 2025

Original amount 544,500 CAD, converted at the ECB reference rate of 14 May 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2025 Norfolk Southern Railway CompanyNorfolk Southern: EPA fine for locomotives without valid emissions certification USAEmissions and permits €266,631

In the view of the U.S. Environmental Protection Agency (EPA), the freight railway operated locomotives without a certificate of conformity, did not comply with the conditions of a testing exemption for several locomotives and operated locomotives in breach of the applicable emission standards. Under the settlement (Consent Agreement and Final Order), the company is paying a civil penalty of 299,000 USD.

What organisations can take from it

Converted vehicles or vehicles exempted for testing are also subject to certification and restoration obligations, which must be tracked in fleet management.

Authority / court
U.S. Environmental Protection Agency (EPA), Region 3
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Clean Air Act §§ 203(a), 213(d) (42 U.S.C. §§ 7522(a), 7547(d)); 40 C.F.R. § 1068.101
Action
Fine
Status of proceedings
final
Sector
Transport, logistics and shipping
Employees
10,000 or more

Original amount 299,000 USD, converted at the ECB reference rate of 14 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 May 2025 AS Asphaltstraßensanierung, BITUNOVA, Mainka u. a. (Straßenerhaltungskartell, 7 Unternehmen)Bundeskartellamt: 10.5 million EUR against seven road repair companies GermanyCartels and collusion €10.5m

From 2016 to 2019, seven road repair companies allocated contracting authorities regionally, determined in advance who should win the contract and set each other minimum prices for cover bids. The Bundeskartellamt imposed fines of 10.5 million EUR; BITUNOVA cooperated as leniency applicant, and all proceedings ended in settlements. Addressees: AS Asphaltstraßensanierung GmbH, bausion Strassenbau-Produkte GmbH, BITUNOVA GmbH, Gerhard Herbers GmbH, Liesen … alles für den Bau GmbH, Mainka GmbH Straßenunterhaltung, MOT Müritzer Oberflächentechnik GmbH.

What organisations can take from it

Cover bids are not only subject to fines but, for the employees involved, a criminal offence of bid rigging.

Relevance to training and awareness

Cover bids and territorial agreements in tenders

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Mitigating circumstances
Leniency programme (BITUNOVA), settlement
Liability of senior managers
Criminal prosecution of the individuals involved by the Düsseldorf public prosecutor's office
Published
13 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2025 „Кауфланд България ЕООД енд Ко“ КДKaufland demanded payments from suppliers for marketing and logistics – 500,000 leva BulgariaAbuse of market power €255,650

Following a preliminary investigation into rising food prices, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that Kaufland had demanded and received payments from five suppliers for ‘marketing services’ and for ‘optimisation of goods flows’ and logistics that were not fully connected with the sale of their products. For the two prohibited trading practices (Art. 37b(1)(4) ZZK – Bulgarian Protection of Competition Act) it imposed 250,000 leva each, a total of 500,000 leva. An appeal has been lodged against the decision.

What organisations can take from it

Charges to suppliers are only permissible if they are matched by a specific service connected with the sale.

Relevance to training and awareness

Fair terms towards suppliers

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 37b Abs. 1 Nr. 4 ZZK (verbotene Handelspraktiken in der Lebensmittelkette, UTP-Richtlinie)
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce

Original amount 500,000 BGN, converted at the ECB reference rate of 8 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2025 Spence Diamonds Ltd.FINTRAC: CAD 264,000 penalty on Spence Diamonds Ltd. for 5 violations of anti-money laundering obligations CanadaSuspicious activity reports €168,217

According to FINTRAC, Spence Diamonds Ltd. is a dealer in precious metals and stones. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 264,000 on the company on 8 May 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 5 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme and the prescribed review of the compliance programme. Specifically, according to FINTRAC, one suspicious transaction report was missing; the company could also not demonstrate that all employees had been trained or that its compliance programme had been reviewed. According to FINTRAC, the company is paying the penalty in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Spence Diamonds Ltd.", published 23 September 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-09-23-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Published
23 Sep 2025

Original amount 264,000 CAD, converted at the ECB reference rate of 8 May 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 May 2025 Sennheiser electronic SE & Co. KG, Sonova Consumer Hearing Sales Germany GmbHBundeskartellamt: almost 6 million EUR against Sennheiser and Sonova over resale price maintenance GermanyCartels and collusion €6m

Since at least 2015, Sennheiser coordinated consumer prices for premium headphones with dealers, monitored them using price comparison services and specialist software and intervened when prices were too low; Sonova continued this after acquiring the business unit in March 2022 until September 2022. The employees had received competition law training but used this knowledge to conceal their conduct (code language). The Bundeskartellamt imposed fines of almost 6 million EUR on both companies and three responsible employees (settlement).

What organisations can take from it

Price monitoring software is no licence: anyone who responds to deviations by putting pressure on dealers is engaging in prohibited resale price maintenance – and employees are personally liable.

Relevance to training and awareness

Price discussions with dealers and price monitoring

Missing or inadequate training played a role in the decision.

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB (vertikale Preisbindung)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Mitigating circumstances
Extensive cooperation and settlement
Liability of senior managers
Fines imposed on three responsible employees (not named)
Published
7 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 May 2025 Todd Snyder, Inc.Todd Snyder: 345,178 USD – tracking opt-out ineffective for 40 days USA, CACookies and tracking €304,793

For 40 days, the fashion retailer’s misconfigured privacy portal did not process objections to the sale and sharing of personal data; in addition, the company required too much data and identity verification before an opt-out. The California Privacy Protection Agency (CPPA) imposed 345,178 USD and required correct configuration of consent management and employee training.

What organisations can take from it

A consent management platform does not relieve companies of responsibility: check regularly whether opt-outs are actually implemented technically.

Relevance to training and awareness

Configuration and monitoring of consent management platforms

Missing or inadequate training played a role in the decision.

Authority / court
California Privacy Protection Agency (CPPA), Board
Area of law
Data protection · Cookies and tracking
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce

Original amount 345,178 USD, converted at the ECB reference rate of 6 May 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China IrelandInternational data transfers €530m

TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.

What organisations can take from it

Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · International data transfers
Legal basis
Art. 46 Abs. 1, Art. 13 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
2 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 May 2025 Ατλάντα Αντιπροσωπείαι – Διανομαί Α.Ε.Greece: 127,314 EUR against breakfast cereal distributor Atlanta for resale price maintenance GreeceCartels and collusion €127,314

From March to August 2021, the distribution partner for breakfast cereals set resale prices, which retailers and supermarket chains largely adopted. The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) accepted the settlement proposal and, by Decision 878/2025, imposed a reduced fine of 127,314 EUR; date = press release.

What organisations can take from it

Even short periods of imposing prices on retailers carry fines – sales teams must know the line between recommendation and requirement.

Relevance to training and awareness

Resale price maintenance towards retailers

Authority / court
Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 1 Gesetz 3959/2011; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Settlement procedure with fine reduction
Published
2 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 May 2025 Raytheon Company; RTX Corporation; Nightwing Group LLC; Nightwing Intelligence Solutions LLCRaytheon and Nightwing pay 8.4 million USD over cybersecurity deficiencies in DoD contracts USAOther €7.39m

Between 2015 and 2021, the companies allegedly failed to prepare a system security plan for an internal development system used for 29 Department of Defense contracts and did not comply with the clauses DFARS 252.204-7012 and FAR 52.204-21. Settlement under the False Claims Act of 8.4 million USD; a former director of engineering received 1.512 million USD as a whistleblower.

What organisations can take from it

Internal development environments are also covered by contractual cybersecurity obligations and need a documented security plan.

Authority / court
U.S. Department of Justice (Civil Division) / USAO District of Columbia
Area of law
Other
Legal basis
False Claims Act; DFARS 252.204-7012; FAR 52.204-21
Action
Other
Status of proceedings
final
Sector
Defence and security
Employees
10,000 or more
Published
1 May 2025

Original amount 8,400,000 USD, converted at the ECB reference rate of 30 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Apr 2025 Bondora ASBondora must pay 200,000 EUR for breaching responsible lending rules EstoniaConsumer protection and online retail €200,000

From 6 December 2023 to 24 February 2024, Bondora concluded consumer credit agreements without assessing all criteria provided for by law and satisfying itself of the borrowers’ ability to repay. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed 200,000 EUR. Date = publication.

What organisations can take from it

Automated credit decisions do not release lenders from the full statutory creditworthiness assessment.

Relevance to training and awareness

Responsible lending

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Consumer protection and online retail
Legal basis
§ 99 Abs. 2 KAVS
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
30 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Apr 2025 Luxembourg engineering firm: 7,000 EUR for incomplete record of processing activities LuxembourgData protection €7,000

In an audit campaign on records of processing activities, the Commission nationale pour la protection des données (Luxembourg data protection authority, CNPD) found that an engineering and design consultancy (pseudonymised as ‘Société A’) had omitted mandatory information such as name and contact details, categories of data subjects and data, and retention periods. It imposed 7,000 EUR.

What organisations can take from it

The record of processing activities is the first thing supervisory authorities request – it must be complete, including retention periods.

Authority / court
Commission nationale pour la protection des données (CNPD) – formation restreinte
Area of law
Data protection
Legal basis
DSGVO Art. 30 Abs. 1 lit. a, c, f
Action
Fine
Status of proceedings
unknown
Sector
Manufacturing and mechanical engineering

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Apr 2025 Gilead Sciences, Inc.Gilead: 202 million USD – speaker programmes with fees, luxury meals and travel USAGifts, hospitality and benefits €177.8m

Gilead paid physicians who spoke at or attended events on its HIV medicines fees, meals and travel expenses to promote prescriptions; high prescribers received hundreds of thousands of dollars, and events took place at luxury restaurants. The court-approved settlement of 202 million USD contains extensive admissions of fact.

What organisations can take from it

Selecting speakers by prescription volume turns continuing education into bribery – selection criteria and hospitality limits must be documented.

Relevance to training and awareness

Fees and hospitality at professional events

Authority / court
U.S. Attorney's Office, Southern District of New York; U.S. District Court (S.D.N.Y.)
Area of law
Bribery and corruption · Gifts, hospitality and benefits
Legal basis
Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)); False Claims Act (31 U.S.C. §§ 3729 ff.)
Action
Other
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more
Published
29 Apr 2025

Original amount 202,000,000 USD, converted at the ECB reference rate of 28 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Apr 2025 Johnson & Johnson Consumer NV; Boehringer Ingelheim SComm; Haleon Belgium NVJohnson & Johnson, Boehringer, Haleon: 11.2 million EUR for shelf-placement collusion in pharmacies BelgiumCartels and collusion €11.2m

Over more than 15 years, the three OTC medicine manufacturers jointly developed the category management project ‘SMAN’, through which they steered the placement of non-prescription medicines in selected pharmacies in their favour and disadvantaged or excluded competing products. In a settlement procedure, the Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (Belgian Competition Authority, BMA) imposed a total of 11,249,280.48 EUR.

What organisations can take from it

Category management agreements with retailers must not push competitors off the shelf – joint planograms with competitors are off limits.

Relevance to training and awareness

Competition law limits of category management

Authority / court
Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (BMA)
Area of law
Competition law · Cartels and collusion
Legal basis
Code de droit économique Art. IV.1; AEUV Art. 101
Action
Fine
Status of proceedings
final
Sector
Chemicals and pharmaceuticals
Employees
10,000 or more
Published
24 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Apr 2025 Dante International SADante International fails to act on erasure requests – 10,000 EUR RomaniaData subject rights and transparency €10,000

Although the platform operator had repeatedly confirmed to a customer that his e-mail addresses had been deleted, he continued to receive feedback requests; in addition, certain partners could see the address. The Romanian data protection authority (ANSPDCP) found breaches of transparency and erasure obligations, imposed 49,770 lei (10,000 EUR) and ordered, among other things, training of the staff responsible.

What organisations can take from it

A confirmed erasure must actually be implemented in all systems – including feedback and partner tools.

Relevance to training and awareness

Handling erasure requests in customer service

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12 Abs. 1 i. V. m. Art. 17 und 19 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
24 Apr 2025

Original amount 49,770 RON, converted at the ECB reference rate of 24 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2025 AppleDMA: 500 million EUR against Apple over anti-steering in the App Store EU levelPlatform obligations €500m

In one of the first non-compliance decisions under the Digital Markets Act (DMA), the European Commission found that Apple prevents app developers from informing customers free of charge about cheaper offers outside the App Store and steering them there. In addition to a fine of 500 million EUR, the removal of the restrictions within 60 days was ordered, failing which periodic penalty payments may be imposed.

What organisations can take from it

Gatekeepers must allow business users to communicate freely with their customers; technical or commercial hurdles are treated as circumvention.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Apr 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Apr 2025 MetaDMA: 200 million EUR against Meta over ‘consent or pay’ model EU levelPlatform obligations €200m

Between March and November 2024, Meta offered users of Facebook and Instagram only the choice between consenting to the combination of their data for personalised advertising and a paid subscription. The European Commission saw this as a breach of the obligation under the Digital Markets Act (DMA) to offer an equivalent, less data-intensive alternative, and imposed 200 million EUR.

What organisations can take from it

A binary ‘consent or pay’ is not sufficient where the law requires an equivalent option involving less data processing.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Einwilligung zur Datenzusammenführung
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
23 Apr 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2025 Iberinform Internacional, S.A.AEPD: 720,000 EUR against business information agency Iberinform for purchased data on entrepreneurs SpainData subject rights and transparency €720,000

Since 2008, Iberinform had obtained data on sole traders through a supply contract with Camerdata and used it to enrich its own files for commercial information services. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) found no legal basis for this and no information of the data subjects, and imposed 360,000 EUR for each (720,000 EUR in total) as well as an order to bring the processing into compliance; the request for reconsideration (recurso de reposición) was rejected.

What organisations can take from it

Companies that purchase personal data from third parties need their own legal basis and must actively inform the data subjects.

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 6 Abs. 1, Art. 14 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2025 DPP Law LtdICO: £60,000 against law firm DPP Law over hack and late notification United KingdomData breaches and data security €69,458

In 2022, attackers used brute force to penetrate the law firm's network via a rarely used administrator account without MFA and stole 32 GB of highly sensitive data, which appeared on the dark web. The firm only learned of this from the National Crime Agency and reported the incident to the UK Information Commissioner's Office (ICO) only 43 days later.

What organisations can take from it

Even small law firms need MFA on admin accounts and a reporting process that meets the 72-hour deadline.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1 und 2, Art. 33 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Published
16 Apr 2025

Original amount 60,000 GBP, converted at the ECB reference rate of 14 Apr 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Apr 2025 Svarog Shipping & Trading Company LimitedTanker shipping company Svarog left OFSI information request unanswered United KingdomBreaches of sanctions and embargoes €5,768

In the context of investigations into dealings with a Sovcomflot subsidiary, the fuel shipping company registered in the UK and operating from Cyprus did not respond in time to a formal information request from HM Treasury's Office of Financial Sanctions Implementation (OFSI); a response only came after contact via its auditors. No sanctions breach as such was found, but the information offence was.

What organisations can take from it

Information requests from sanctions authorities need a clear intake channel and deadline monitoring – merely missing the deadline is already an offence.

Relevance to training and awareness

Handling requests from authorities and deadlines

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russia (Sanctions) (EU Exit) Regulations 2019, regs. 72, 74(1)(a)
Action
Fine
Status of proceedings
final
Sector
Transport, logistics and shipping
Culpability
negligent
Mitigating circumstances
Minor, indirect harm; the response was provided subsequently
Published
8 May 2025

Original amount 5,000 GBP, converted at the ECB reference rate of 11 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Apr 2025 OGH: gyms may not impose fee increases by way of deemed consent AustriaInformation duties in online retail Order

Two gym operators announced a fee increase of 6 EUR a month and treated silence or the failure to exercise a special right of termination as consent. In an action brought by the Austrian Federal Chamber of Labour (Bundesarbeitskammer), the OGH upheld the prohibition of such increases without express agreement and the publication of the judgment; it dismissed claims for repayment and information.

What organisations can take from it

Price increases in ongoing consumer contracts require genuine consent – silence is not enough.

Authority / court
Oberster Gerichtshof (OGH), GZ 4 Ob 51/25s
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 6 Abs. 1 Z 2, § 28a KSchG; §§ 1a, 14 UWG
Action
Order
Status of proceedings
final
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Apr 2025 Block, Inc.NYDFS: 40 million USD against Block (Cash App) over AML deficiencies USA, NYCustomer due diligence €36.1m

The New York State Department of Financial Services (NYDFS) imposed 40 million USD on the operator of Cash App for serious gaps in its BSA/AML programme, including insufficient customer due diligence, a lack of risk-based controls and untimely transaction monitoring. Rapid growth in 2019/2020 led to a considerable backlog of alerts; an independent monitor is being appointed.

What organisations can take from it

Scale compliance capacity with growth – a backlog of alerts is a supervisory infringement in its own right.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
BSA/AML-, Geldtransfer- und Virtual-Currency-Vorschriften des NYDFS
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Cooperation and remedial measures already initiated
Published
10 Apr 2025

Original amount 40,000,000 USD, converted at the ECB reference rate of 10 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Apr 2025 Luka Inc.Garante: 5 million EUR against Replika operator Luka over lack of legal basis ItalyAI systems €5m

The US operator of the Replika chatbot had not determined a legal basis for the processing, had an inadequate privacy notice and, despite declaring that minors were excluded, had no age verification. Italy's data protection authority (Garante per la protezione dei dati personali) imposed 5 million EUR and opened further proceedings concerning the training of the underlying language model.

What organisations can take from it

A declared exclusion of minors is worthless without effective age verification at registration and during use.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO (Rechtmäßigkeit, Transparenz, Schutz Minderjähriger)
Action
Fine
Status of proceedings
under appeal
Sector
Telecoms, IT and software
Published
19 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2025 Slovenské národné múzeumSlovak National Museum: 7,000 EUR – employees not informed about reporting system SlovakiaMissing or inadequate reporting channel €7,000

The museum published no information on the protection options or on the external reporting channel and could not prove that employees were familiar with the internal reporting rules – there were no signature lists and no proof of intranet access. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 7,000 EUR.

What organisations can take from it

Informing employees about the reporting system must be documented – without proof, it is deemed not to have taken place.

Relevance to training and awareness

Informing employees about internal and external reporting channels

Missing or inadequate training played a role in the decision.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 5, § 19 Abs. 3
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Apr 2025 Taepyung Salt FarmCBP import stop for sea salt from South Korea's Taepyung Salt Farm USAForced and child labour Order

U.S. Customs and Border Protection (CBP) issued a Withhold Release Order: sea salt products from Taepyung Salt Farm (South Korea) are being detained at all US ports of entry because there are indications of forced labour (ILO indicators including physical violence, debt bondage, deception, restriction of movement and withholding of wages (ten indicators)).

What organisations can take from it

Food manufacturers should also include inconspicuous ingredients such as salt in their forced labour risk analysis.

Authority / court
U.S. Customs and Border Protection
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
19 U.S.C. § 1307 (Tariff Act of 1930, Section 307)
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Published
3 Apr 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO MaltaData subject rights and transparency €20,000

Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.

What organisations can take from it

Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.

Relevance to training and awareness

Implementing rectification requests promptly

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Apr 2025 BMW, Ford, Honda, Hyundai/Kia, Jaguar Land Rover, Mazda, Mitsubishi, Opel/GM, Renault/Nissan, Stellantis, Suzuki, Toyota, Volkswagen, Volvo, ACEA (Mercedes-Benz Kronzeuge)EU: 458 million EUR against carmakers and ACEA over end-of-life vehicle recycling cartel EU levelCartels and collusion €457.9m

The Commission imposed fines of around 458 million EUR on 15 carmakers and the association ACEA. From 2002 to 2017, they had agreed not to pay dismantlers for recycling end-of-life vehicles and not to advertise recycling rates or recycled content; ACEA organised the meetings. Mercedes-Benz received full immunity as leniency applicant, and all parties reached a settlement (10 % reduction).

What organisations can take from it

Agreements on purchasing terms or on refraining from advertising claims are also cartels – association meetings require antitrust supervision.

Relevance to training and awareness

Agreements in association bodies; refraining from purchasing or advertising can also be a cartel

Authority / court
Europäische Kommission
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV, Art. 53 EWR-Abkommen
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Employees
10,000 or more
Mitigating circumstances
Leniency programme (Mercedes-Benz 100 %, Stellantis/Opel 50 %, Mitsubishi 30 %, Ford 20 %), 10 % settlement reduction, lesser involvement of Honda, Mazda, Mitsubishi, Suzuki

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Apr 2025 OKCoin Europe LimitedMalta: 1.05 million EUR against crypto exchange OKCoin Europe over anti-money laundering deficiencies MaltaInternal controls €1.05m

During an on-site examination in 2023, the Financial Intelligence Analysis Unit (FIAU) found deficiencies at the crypto service provider in its business risk assessment (including product risks), customer risk assessment, customer profiles, ongoing monitoring, suspicious transaction reporting and record-keeping. It imposed 1,054,269 EUR and a follow-up directive; the fine was open to appeal at the time of publication.

What organisations can take from it

Crypto providers are held to the same due diligence standards as banks – the risk assessment must cover their own products.

Relevance to training and awareness

Anti-money laundering for crypto-assets

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Reg. 5(1), 5(4), 5(5), 7, 11, 15(3), 21 PMLFTR; FIAU Implementing Procedures
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
3 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Mar 2025 FXNET LimitedCyprus: FXNET pays 225,000 EUR under settlement over organisational and CFD breaches CyprusOrganisational requirements €225,000

The investigation covering 2021 to 2022 concerned compliance organisation, product governance, record-keeping obligations, safeguarding of client funds, client information, suitability and appropriateness assessments and the CFD restrictions for retail investors. Following board resolutions of 17 and 31 March 2025, the Cyprus Securities and Exchange Commission (CySEC) concluded a settlement of 225,000 EUR, which has been paid.

What organisations can take from it

Safeguarding client funds and keeping proper records are basic duties of every investment firm – gaps quickly add up in a settlement.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 17, 22(1), 25, 26(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
11 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Mar 2025 Ontario International College Inc.Private college and director: CA$410,000 for ignored orders to pay wages Canada, ONMinimum wage and undeclared work €265,475

The college failed to pay 14 employees wages of almost CA$185,000 and ignored the labour inspectorate's orders to pay from 2019/2020; the director did not pay either. The court imposed CA$270,000 on the company and CA$140,000 on the director, in addition to the outstanding wages.

What organisations can take from it

Outstanding wage claims do not go away – the fine comes on top of the back pay and also hits management personally.

Authority / court
Provincial Offences Court Toronto (Ermittlung: Ontario Ministry of Labour, Immigration, Training and Skills Development)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Employment Standards Act, 2000 (Ontario), ss. 103(8), 106, 132, 136
Action
Fine
Status of proceedings
unknown
Sector
Other
Liability of senior managers
Director Anchuan Jiang personally fined CA$140,000.
Published
28 May 2025

Original amount 410,000 CAD, converted at the ECB reference rate of 28 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Mar 2025 AFK Letters Co LtdICO: £90,000 fine for AFK Letters Co over unwanted marketing calls United KingdomMarketing and consent €108,020

The ICO fined AFK Letters Co Ltd £90,000 and also issued an enforcement notice. The ICO found that between January and September 2023 the company made around 95,000 marketing calls to numbers registered with the Telephone Preference Service, which led to complaints to the ICO and the TPS. The company could not show that the people called had consented. Early payment reduces the penalty to £72,000.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulation 21 PECR; section 55A DPA 1998; section 40 DPA 1998 (Enforcement Notice)
Action
Fine
Status of proceedings
unknown
Sector
Other

Original amount 90,000 GBP, converted at the ECB reference rate of 27 Mar 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Mar 2025 Advanced Computer Software Group LtdICO: £3 million against NHS service provider Advanced after ransomware without MFA United KingdomData processors €3.68m

Advanced, a processor for the NHS and care providers, was attacked with ransomware in August 2022 via a customer account without multi-factor authentication; services such as NHS 111 were disrupted. Data on 79,404 people was stolen, including instructions on how to gain entry to the homes of 890 people receiving care at home.

What organisations can take from it

MFA must apply to every single access point without gaps – one unprotected account is enough for attackers.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data processors
Legal basis
UK GDPR Art. 32 Abs. 1 (als Auftragsverarbeiter)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Provisionally £6.09 million; reduced, among other things, for proactive cooperation with the NCSC and the National Crime Agency.
Published
27 Mar 2025

Original amount 3,076,320 GBP, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2025 Società Cooperativa Culture (CoopCulture)Colosseum tickets: CoopCulture 7 million EUR, around 20 million in total over ticket bots ItalyMisleading advertising and pricing €7m

The Colosseum's ticketing service provider did not prevent tour operators from buying up basic tickets in bulk using bots, and itself reserved large allocations for more expensive packages; as a result, visitors could hardly find regular tickets. The AGCM imposed a fine of 7 million EUR on CoopCulture and further fines on six tour providers (including Tiqets, GetYourGuide, Musement), almost 20 million EUR in total.

What organisations can take from it

Anyone selling a scarce allocation must actively prevent bot purchases and must not steer access towards expensive packages.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 20, comma 2 Codice del Consumo (CoopCulture); Artt. 24, 25, 23 comma 1 lett. bb-bis (Touranbieter)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
8 Apr 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Mar 2025 BT, IMG, ITV, BBC (Sky Kronzeuge)CMA: 4.24 million GBP against BT, IMG, ITV and BBC over collusion on freelancer fees United KingdomCartels and collusion €5.06m

Sports broadcasters and production companies exchanged sensitive information in 15 instances about day rates and fee increases for freelance camera operators and sound technicians in order to coordinate pay. Fines: BT 1,738,453 GBP, IMG 1,737,820 GBP, BBC 424,165 GBP, ITV 339,918 GBP; Sky received immunity as the first to come forward.

What organisations can take from it

HR and the procurement of freelance work are also subject to competition law – salary and fee information must not be shared with competitors.

Relevance to training and awareness

Exchanges about salaries and fees with competitors (labour market)

Authority / court
Competition and Markets Authority (CMA)
Area of law
Competition law · Cartels and collusion
Legal basis
Chapter I Competition Act 1998
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
20 % settlement discount for all; leniency discounts for BT, IMG, ITV; immunity for Sky
Published
21 Mar 2025

Original amount 4,240,356 GBP, converted at the ECB reference rate of 21 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Mar 2025 Hub Capital Inc.FINTRAC: CAD 99,000 penalty on Hub Capital Inc. for 4 violations of anti-money laundering obligations CanadaInternal controls €63,662

According to FINTRAC, Hub Capital Inc. is a securities dealer or wealth management firm based in Woodbridge, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 99,000 on the company on 21 March 2025. According to FINTRAC's findings, made during a compliance examination in 2023, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme and the prescribed review of the compliance programme. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Hub Capital Inc.", published 12 June 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-06-12-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTFA s. 9.6(2); PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f), 156(2), 156(3); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
12 Jun 2025

Original amount 99,000 CAD, converted at the ECB reference rate of 21 Mar 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Mar 2025 Východoslovenská vodárenská spoločnosť, a.s.East Slovak water company: 2,000 EUR for missing information on external reporting channels SlovakiaMissing or inadequate reporting channel €2,000

The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) initially imposed 10,000 EUR because the water utility’s policy named an e-mail address that had been deactivated since October 2022 as a reporting channel available around the clock and because employees were not informed comprehensibly about external reporting channels. On appeal, the head of the authority dropped the e-mail allegation for procedural reasons, set aside the part concerning the failure to acknowledge a report and set the fine at 2,000 EUR solely for the missing information on reporting channels to the competent authorities (September 2023 to September 2024).

What organisations can take from it

Test reporting channels regularly: an undeliverable whistleblower address is as good as none at all.

Relevance to training and awareness

Functioning internal reporting channels for whistleblowers

Authority / court
Úrad na ochranu oznamovateľov (Slowakei)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
§ 10 Abs. 5, § 19 Abs. 3 Gesetz Nr. 54/2019 über den Schutz von Hinweisgebern
Action
Fine
Status of proceedings
reduced
Sector
Energy and utilities
Culpability
negligent

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2025 The London Metal Exchange (LME)London Metal Exchange: 9.2 million GBP – controls and escalation failed in nickel turmoil United KingdomCritical infrastructure €11m

When the nickel price rose to over 100,000 USD within just over an hour on 8 March 2022, only junior staff were on duty during Asian trading hours, and they had not been trained to recognise a disorderly market; they did not escalate and even switched off price bands. The Financial Conduct Authority (FCA) imposed a fine on the recognised investment exchange for the first time: 9.2 million GBP after a 30% discount.

What organisations can take from it

Critical infrastructure needs trained staff around the clock and clear escalation paths – including at night and at off-peak times.

Relevance to training and awareness

Escalation of unusual market conditions; training of shift staff

Missing or inadequate training played a role in the decision.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
FCA REC 2.5.1 (Recognition Requirements); Art. 18 RTS 7 (MiFID II)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Early settlement (30% discount); improvements since March 2022.

Original amount 9,200,000 GBP, converted at the ECB reference rate of 20 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2025 Hino Motors, Ltd.Hino Motors: over 1.6 billion USD in fines and forfeiture for emissions fraud USAEmissions and permits €1.48bn

Between 2010 and 2019, the Toyota subsidiary submitted false certification applications, altered emissions data and fabricated test results; more than 105,000 non-compliant diesel engines were imported into the USA. The court imposed a fine of 521.76 million USD and forfeiture of 1.087 billion USD, plus five years of probation with an import ban on Hino diesel engines.

What organisations can take from it

Manipulated test data in approval procedures lead to penalties that threaten a company's existence and to market bans; testing processes need independent controls.

Relevance to training and awareness

Data integrity in testing and approval procedures

Authority / court
U.S. District Court for the Eastern District of Michigan (Ermittlungen: EPA Criminal Investigation Division, FBI)
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Clean Air Act; Verschwörung zum Betrug der Vereinigten Staaten und Schmuggel (Schuldbekenntnis)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Employees
10,000 or more
Culpability
intentional
Published
19 Mar 2025

Original amount 1,608,760,000 USD, converted at the ECB reference rate of 19 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2025 AppleApple: Commission sets out specific interoperability obligations for iOS by DMA decision EU levelPlatform obligations Order

In two specification decisions under the Digital Markets Act, the European Commission set out which interoperability measures Apple must take: access for manufacturers of connected devices to nine iOS features (such as notifications on smartwatches, peer-to-peer Wi-Fi, NFC, pairing) and a more transparent and faster procedure for developers’ interoperability requests.

What organisations can take from it

Gatekeepers must actively open interfaces – anyone handling third-party requests sluggishly risks detailed regulatory requirements.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Markets Act (Verordnung (EU) 2022/1925): Interoperabilitätspflicht, Spezifizierungsbeschlüsse
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Mar 2025 Greater Manchester PoliceICO: Reprimand for Greater Manchester Police over lost CCTV footage and late subject access response United KingdomData breaches and data security Reprimand or warning

The ICO issued a reprimand to the Chief Constable of Greater Manchester Police. The ICO found that CCTV footage from a police station custody suite in 2021, which was to be retained because of serious allegations against officers, was not checked for completeness when it was preserved and was partly lost. In addition, the individual concerned did not receive their data on time after a subject access request. The action was based on the law-enforcement processing rules in the DPA 2018.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
section 45(3)(a) und (b) DPA 2018; sechster Datenschutzgrundsatz (section 40 DPA 2018, Part 3)
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Mar 2025 Sahara Hands; Peculiar Peoples' Palace Ministries; Impact PlanetOFSI: breaches of information requirements by three charities published instead of a penalty United KingdomBreaches of sanctions and embargoes Other

On 14 March 2025 OFSI published a report on breaches by three UK charities – Sahara Hands, Peculiar Peoples' Palace Ministries and Impact Planet – of information requirements under counter-terrorism sanctions law; OFSI did not impose a monetary penalty. According to OFSI's findings, the organisations had failed without reasonable excuse to provide information in response to a formal request, despite three letters. OFSI made clear that this concerns an information offence only and that it holds no information indicating any further breach of the sanctions regulations. OFSI considers it possible that out-of-date contact details on the Charity Commission register played a role, but did not treat this as mitigating. Type of measure: Breach published by OFSI instead of a monetary penalty (disclosure under s. 149(3) PACA 2017). The publication does not mention any pending review. Source: Office of Financial Sanctions Implementation (OFSI), HM Treasury, "Disclosure notice: 14 March 2025", 14 March 2025, https://www.gov.uk/government/publications/disclosure-notice-14-march-2025. Contains public sector information licensed under the Open Government Licence v3.0 (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/).

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Counter-Terrorism (International Sanctions) (EU Exit) Regulations 2019, reg. 36(6); Veröffentlichung nach s. 149(3) Policing and Crime Act 2017
Action
Other
Status of proceedings
unknown
Sector
Other
Published
14 Mar 2025

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Mar 2025 Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC)Cyprus: reprimand for electricity supplier EAC over insecure app registration CyprusData breaches and data security Reprimand or warning

A customer denied having registered in the EAC Mobile App and having changed his billing address there; the supplier could not prove that the mobile number used for identification originated from the customer himself. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) found breaches of accountability and data security, issued a reprimand and ordered the delivery address to be clarified with the customer in writing.

What organisations can take from it

Self-registration in customer portals needs robust identity verification – otherwise invoices and data can be redirected.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24, Art. 32 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long CyprusData subject rights and transparency €10,000

The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.

What organisations can take from it

Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Mar 2025 American Honda Motor Co., Inc.CPPA: $632,500 against Honda over obstructed privacy requests USA, CAData subject rights and transparency €582,573

Honda required excessive information for opt-out requests, used a cookie tool without equivalent choices, made it harder to appoint authorised agents and passed data on to ad-tech firms without the required contracts. The order of the California Privacy Protection Agency (CPPA) requires, among other things, a simplified procedure and training for employees.

What organisations can take from it

Do not undermine data subject rights through form hurdles or asymmetric consent dialogues.

Authority / court
California Privacy Protection Agency (CPPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
California Consumer Privacy Act (CCPA)
Action
Fine
Status of proceedings
final
Sector
Automotive
Employees
10,000 or more
Published
12 Mar 2025

Original amount 632,500 USD, converted at the ECB reference rate of 7 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication PolandData breaches and data security €13,604

Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.

What organisations can take from it

Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.

Relevance to training and awareness

Protection of data subjects in press reports; encryption of storage media

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
Action
Fine
Status of proceedings
under appeal
Sector
Media and online platforms
Published
11 Mar 2025

Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2025 SIA "VSV ZOO"Pet shop VSV ZOO fails to respond to review of privacy policy – 500 EUR LatviaData subject rights and transparency €500

As part of a preventive review of the privacy policy on zoopasaule.lv, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) repeatedly asked the online pet retailer for information from July 2024 onwards. The company let the first deadlines lapse, later twice asked for an extension citing the absence of its programmer, and still did not deliver thereafter. The DVI imposed 500 EUR for failure to cooperate with the supervisory authority.

What organisations can take from it

A preventive request from the supervisory authority is also binding – anyone who does not respond is sanctioned before the actual deficiency is even addressed.

Relevance to training and awareness

Handling letters from the data protection authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. d und e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2025 Crystal Currency Exchange Inc.FINTRAC: CAD 348,067.50 penalty on Crystal Currency Exchange Inc. for 9 violations of anti-money laundering obligations CanadaSuspicious activity reports €226,047

According to FINTRAC, Crystal Currency Exchange Inc. is a money services business based in Burnaby, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 348,067.50 on the company on 5 March 2025. According to FINTRAC's findings, made during a compliance examination, the company committed 9 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, large cash transaction reporting, international electronic funds transfer reporting, appointing a compliance officer, written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks, the compliance training programme and the prescribed review of the compliance programme. Specifically, FINTRAC found three missing suspicious transaction reports and several unreported series of cash receipts and incoming and outgoing international transfers that together reached at least CAD 10,000 within 24 hours. According to FINTRAC, the company has appealed the decision to the Federal Court. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Crystal Currency Exchange Inc.", published 29 May 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-05-29-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7, 9.6(1); PCMLTF Regulations 30(1)(a), 30(1)(b), 30(1)(c), 156(1)(a), 156(1)(b), 156(1)(c), 156(1)(d), 156(1)(e), 156(1)(f), 156(3); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
29 May 2025

Original amount 348,067.5 CAD, converted at the ECB reference rate of 5 Mar 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Mar 2025 MAKI podjetje za turizem, trgovino in storitve d.o.o. KoperBureau de change MAKI: transaction limit of 1,000 EUR over unresolved anti-money laundering deficiencies SloveniaInternal controls Order

During a follow-up inspection, Banka Slovenije (Bank of Slovenia) found that the company had not remedied the anti-money laundering deficiencies it had been ordered to address in 2023; some infringements are considered serious. It limited transactions to 1,000 EUR per customer per day, ordered monthly reports and set a deadline of 30 June 2025.

What organisations can take from it

Supervisory orders that are not implemented lead to business restrictions – working through them requires responsible persons and deadline control.

Relevance to training and awareness

Anti-money laundering in small financial service providers

Authority / court
Banka Slovenije
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 164 ZPPDFT-2, Art. 280 ZBan-3, Art. 42.a ZBS-1
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Mar 2025 Cambrian Credit UnionFINTRAC: CAD 116,160 penalty on Cambrian Credit Union for 4 violations of anti-money laundering obligations CanadaSuspicious activity reports €76,907

According to FINTRAC, Cambrian Credit Union is a credit union based in Winnipeg, Manitoba. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 116,160 on the company on 3 March 2025. According to FINTRAC's findings, made during a compliance examination in 2023, the company committed 4 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned suspicious transaction reporting, international electronic funds transfer reporting, written compliance policies and procedures and assessing and documenting money laundering and terrorist financing risks. Specifically, according to FINTRAC, one suspicious transaction report and two reports of incoming international transfers were missing; policies on ongoing monitoring and the risk assessment were insufficiently documented. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Cambrian Credit Union", published 10 June 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-06-10-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
PCMLTFA s. 7; PCMLTF Regulations 7(1)(c), 156(1)(b), 156(1)(c), 156(2); PCMLTF Suspicious Transaction Reporting Regulations s. 9(1); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
10 Jun 2025

Original amount 116,160 CAD, converted at the ECB reference rate of 3 Mar 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Feb 2025 Morgan Stanley (Switzerland) GmbHMorgan Stanley (Switzerland): 1 million CHF fine for organisational deficiency in money laundering case SwitzerlandInternal controls €1.06m

In 2010, the company's legal predecessor did not take all necessary and reasonable organisational precautions to prevent a relationship manager from committing aggravated money laundering with assets derived from bribery offences in Greece. The Office of the Attorney General of Switzerland (Bundesanwaltschaft) concluded the proceedings with a summary penalty order of 1 million CHF.

What organisations can take from it

Under corporate criminal law, organisational deficiencies do not become time-barred when the employee leaves – controls must be demonstrably effective.

Authority / court
Bundesanwaltschaft
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 102 Abs. 2 StGB i. V. m. Art. 305bis StGB
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
27 Feb 2025

Original amount 1,000,000 CHF, converted at the ECB reference rate of 27 Feb 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2025 Inetum (drei Gesellschaften der Unternehmensgruppe)Portugal: 3.09 million EUR against Inetum for no-poach agreements, upheld by court PortugalCartels and collusion €3.09m

From 2014 to 2021, the IT consultancy group participated in bilateral agreements not to poach competitors’ employees. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 3,092,000 EUR on three companies; in March 2026, the Competition, Regulation and Supervision Court (TCRS) upheld the fine in full – the first judicial confirmation of a labour market cartel fine in Portugal.

What organisations can take from it

Agreements not to poach each other’s skilled staff are cartels – HR and managers must be aware of this.

Relevance to training and awareness

Prohibition of no-poach agreements between competitors

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
19 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2025 Smart Home Ensured LimitedICO: Enforcement notice against Smart Home Ensured over marketing calls United KingdomMarketing and consent Order

The ICO issued an enforcement notice to Smart Home Ensured Limited. The ICO found that between July and August 2023 the company made 14,508 unsolicited marketing calls to numbers that had been registered with the Telephone Preference Service for at least 28 days. The notice requires the company to stop such calls. The notice is an enforcement notice and does not impose a fine.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Marketing and consent
Legal basis
Regulation 21 PECR; section 40 DPA 1998 (Enforcement Notice)
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2025 Mako Financial Markets Partnership LLPFCA: £1.66m fine for Mako over control failings in OTC equity trading United KingdomInternal controls €2m

The FCA fined Mako Financial Markets Partnership LLP £1,662,700, of which £1,137,283 is disgorgement. The FCA found that between December 2013 and November 2015 Mako executed over-the-counter trades for clients introduced by another broker group, without adequate systems and controls against fraud and money laundering. Customer due diligence and transaction monitoring were, in the FCA's view, inadequate, and red flags in certain equity trades were missed. The fine includes a settlement discount.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
FCA Principles 2 und 3; section 206 FSMA 2000
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance

Original amount 1,662,700 GBP, converted at the ECB reference rate of 17 Feb 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Feb 2025 Obec SološnicaMunicipality of Sološnica: 200 EUR – contradictory reporting rules and missing information on protection SlovakiaMissing or inadequate reporting channel €200

The municipality did not publish any information on the protection available to whistleblowers and at times had two valid, contradictory sets of rules on the internal reporting procedure online without stating which applied. The Office imposed a fine of 200 EUR.

What organisations can take from it

Reporting rules must be unambiguous and up to date – remove outdated versions from the internet.

Authority / court
Úrad na ochranu oznamovateľov (Slowakisches Amt für Hinweisgeberschutz)
Area of law
Whistleblower protection · Missing or inadequate reporting channel
Legal basis
Zákon č. 54/2019 Z. z. o ochrane oznamovateľov protispoločenskej činnosti, § 10 Abs. 5, § 19 Abs. 2
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2025 Synot W, a.s.; Ing. Igor Vicel (Unternehmer)Gambling takeover without notification: 428,500 EUR for gun-jumping SlovakiaMerger control €428,500

In 2020, Synot and a sole trader jointly acquired control of the gambling operator SLOV-MATIC, transferred shares and replaced corporate bodies before notifying the concentration. Under a settlement, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 400,000 EUR on Synot and 28,500 EUR on the entrepreneur; final since 7 March 2025.

What organisations can take from it

Before closing, neither replace corporate bodies nor steer finances – M&A teams need a gun-jumping checklist.

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Merger control
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Anmeldepflicht und Vollzugsverbot)
Action
Fine
Status of proceedings
final
Sector
Other
Mitigating circumstances
Voluntary subsequent notification, admission and settlement (50% reduction).
Published
10 Mar 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Feb 2025 KLUBB France SASVehicle body builder KLUBB France: CJIP over an ambulance contract in Algeria FranceBribery of public officials €558,024

Following a referral from the public prosecutor's office in Rennes, the PNF investigated bribery of foreign public officials in the performance of a contract for the supply of ambulances to Algeria. KLUBB France is paying a public interest fine of 558,024 EUR and is undergoing a three-year AFA compliance programme.

What organisations can take from it

Medium-sized exporters are also in the spotlight: companies supplying foreign authorities need a robust anti-corruption programme under Sapin II (the French anti-corruption law).

Relevance to training and awareness

Export contracts with state bodies

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Employees
50 to 249
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
11 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Feb 2025 Fatal pallet fall in warehouse: 100,000 EUR fine for industrial door manufacturer NetherlandsWorkplace safety and accidents €100,000

In January 2023, in the warehouse of a manufacturer of industrial doors in Didam (anonymised in the judgment), a 792 kg pallet fell from an unstable stack four high onto a new employee, who died; the forklift used, fitted with fork extensions, had no CE marking of its own and was unsuitable for the load, the risk assessment was incomplete and the instruction of the victim, who did not speak Dutch, was inadequate. The Overijssel District Court (Rechtbank Overijssel, economic division) imposed 100,000 EUR (of which 25,000 EUR suspended) for intentional violations of the Dutch Working Conditions Act (Arbowet), plus 17,500 EUR in damages to the mother (ECLI:NL:RBOVE:2025:711).

What organisations can take from it

Instruct employees in a language they understand – and draw consequences from earlier reportable accidents.

Relevance to training and awareness

Instruction of employees who speak other languages; safe stacking

Missing or inadequate training played a role in the decision.

Authority / court
Rechtbank Overijssel (economische kamer)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
Art. 32 Arbeidsomstandighedenwet i. V. m. Art. 5 Abs. 1, 8 Abs. 1 Arbeidsomstandighedenwet; Art. 3.17, 7.2 Abs. 1, 7.18 Abs. 2 Arbeidsomstandighedenbesluit
Action
Fine
Status of proceedings
unknown
Sector
Manufacturing and mechanical engineering
Culpability
intentional
Mitigating circumstances
No previous convictions of the company; part of the fine suspended.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Feb 2025 EPPO freezes assets: Chinese stainless steel declared as Korean ItalyCustoms Order

In 110 imports via a customs agency in Ferrara, two companies are alleged to have declared stainless steel coils from China as being of South Korean origin, thereby evading almost 2.4 million EUR in additional duty under the 2019 EU anti-dumping regulation; 60 further imports by one of the companies using the same method involve around 950,000 EUR. At the request of the Bologna office of the European Public Prosecutor's Office (EPPO), assets totalling more than 3.3 million EUR were frozen; searches took place in Ferrara, Varese, Milan and La Spezia.

What organisations can take from it

False origin declarations for steel subject to anti-dumping duties are prosecuted across borders by the EU prosecutor – with asset freezes already at the investigation stage.

Relevance to training and awareness

Origin declarations for steel imports and liability of management

Authority / court
Europäische Staatsanwaltschaft (EPPO), Büro Bologna
Area of law
Sanctions and export control · Customs
Legal basis
EU-Antidumpingverordnung von 2019 (Edelstahlcoils aus China); Hinterziehung von Einfuhrzöllen
Action
Order
Status of proceedings
unknown
Sector
Steel and metals
Liability of senior managers
Those responsible at the companies are alleged to have certified the South Korean origin.
Published
10 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent CyprusData breaches and data security Reprimand or warning

An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.

What organisations can take from it

Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.

Relevance to training and awareness

Disclosure of customer data to agents and colleagues in their own matters

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The company implemented the order

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Feb 2025 Lockheed Martin CorporationLockheed Martin pays 29.74 million USD over inflated price proposals for the F-35 USAOther €28.7m

From 2013 to 2015, Lockheed Martin allegedly failed to provide the Joint Program Office with accurate cost and pricing data for five production and sustainment contracts for the F-35 programme and thereby obtained inflated prices. The settlement amounts to 29.74 million USD, in addition to 11.3 million USD that had already been paid to the Department of Defense; it was triggered by a qui tam action.

What organisations can take from it

Whistleblower actions from within the company make pricing errors costly even years later – internal reporting channels must pick up such issues early.

Authority / court
U.S. Department of Justice (Civil Division) / USAO Eastern District of Texas
Area of law
Other
Legal basis
False Claims Act; Truth in Negotiations Act
Action
Other
Status of proceedings
final
Sector
Defence and security
Employees
10,000 or more
Published
6 Feb 2025

Original amount 29,740,000 USD, converted at the ECB reference rate of 6 Feb 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Feb 2025 Медицински център „Люлин Мед“ ООДMC Lyulin Med presented practice as branch of the Military Medical Academy – 9,236 leva BulgariaMisleading advertising and pricing €4,722

Following a tip-off from the Military Medical Academy (VMA), the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that the centre presented its gynaecological practice as a VMA branch with signs reading ‘МЦ „ЛЮЛИН МЕД“ АГ – ВМА ФИЛИАЛ’ and corresponding online information. For misleading conduct (Art. 31 ZZK – Bulgarian Protection of Competition Act) it imposed 0.4% of 2023 turnover, i.e. 9,236 leva. An appeal has been lodged against the decision.

What organisations can take from it

Cooperation with renowned institutions must not be presented as affiliation on signage and in online profiles.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 31 ZZK (Irreführung)
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare

Original amount 9,236 BGN, converted at the ECB reference rate of 6 Feb 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Feb 2025 Glasgow City CouncilICO: Reprimand for Glasgow City Council over late subject access responses United KingdomData subject rights and transparency Reprimand or warning

The ICO issued a reprimand to Glasgow City Council. The ICO found that between April 2023 and March 2024 the council answered only 45% of subject access requests within the statutory deadline. The ICO found infringements of the requirements to respond on time.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12(3), 15(1) und 15(3) UK GDPR; Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Feb 2025 City of Edinburgh CouncilICO: Reprimand for City of Edinburgh Council over late subject access responses United KingdomData subject rights and transparency Reprimand or warning

The ICO issued a reprimand to the City of Edinburgh Council. The ICO found that in 2023 the council failed to answer 40% of subject access requests within the one-month statutory deadline. The ICO found infringements of the requirements to respond on time.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12(3), 15(1) und 15(3) UK GDPR; Art. 58(2)(b) UK GDPR
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Feb 2025 Customs investigators: machinery manufacturer allegedly declared Indian steel as British GermanyCustoms Incident

From March 2021, a machinery manufacturer from the Rhein-Neckar district is alleged to have declared steel products worth more than 2.9 million EUR as being of British origin in more than 100 customs clearances, although the steel came from India and was only imported via the UK; correctly, 25% higher import duties would have been payable. In December 2024, the Stuttgart customs investigation office (Zollfahndungsamt Stuttgart), acting on behalf of the European Public Prosecutor's Office (EPPO), searched business premises in Germany and at the British seller; the damage is estimated at several hundred thousand euros.

What organisations can take from it

For steel, the actual origin determines the customs burden – check supplier declarations from intermediaries for plausibility.

Relevance to training and awareness

Preferential and origin rules when buying steel via intermediaries

Authority / court
Zollfahndungsamt Stuttgart im Auftrag der Europäischen Staatsanwaltschaft (EPPO)
Area of law
Sanctions and export control · Customs
Legal basis
Verdacht der Steuerhinterziehung (Einfuhrabgaben nach EU-Zollrecht, falsche Ursprungsangaben)
Action
Incident without known action
Status of proceedings
unknown
Sector
Steel and metals
Published
3 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Jan 2025 Trafigura Beheer B.V.Swiss Federal Criminal Court (Bundesstrafgericht) convicts Trafigura of bribery in Angola SwitzerlandBribery of public officials €143.3m

Between 2009 and 2011, more than 4 million EUR and more than 600,000 USD were paid to a senior employee of the Angolan state oil distributor in order to promote ship chartering and bunkering business of the Trafigura group. The court convicted the then parent company for lacking rules on the supervision of intermediaries, imposing a fine of 3 million CHF and a compensatory claim (Ersatzforderung) of 145,634,268 USD (amount converted at the ECB rate of 31 January 2025: 148,933,982 USD in total); three individuals received prison sentences. It was the first judgment of the Federal Criminal Court on corporate criminal liability for foreign bribery; it is not final.

What organisations can take from it

In Switzerland, companies are liable if their organisation fails to prevent bribery – and the compensatory claim can exceed the fine many times over.

Relevance to training and awareness

Payments via intermediaries to employees of state-owned oil companies

Authority / court
Bundesstrafgericht (Strafkammer); Anklage durch die Bundesanwaltschaft
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 102 StGB i. V. m. Art. 322septies StGB (Bestechung fremder Amtsträger); SK.2023.49
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Employees
10,000 or more
Culpability
intentional
Liability of senior managers
A former senior manager of the group received a prison sentence of 32 months (12 of them unsuspended), the intermediary 24 months suspended, and the Angolan public official 36 months (names anonymised).
Published
31 Jan 2025

Original amount 148,933,982 USD, converted at the ECB reference rate of 31 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jan 2025 Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; Beijing DeepSeek Artificial Intelligence Co., Ltd.Garante blocks DeepSeek: immediate limitation of processing for Italian users ItalyAI systems Order

After the Chinese providers had declared that they did not operate in Italy and were not subject to the GDPR, Italy's data protection authority (Garante per la protezione dei dati personali) ordered, as a matter of urgency and with immediate effect, the limitation of the processing of Italian users' data and opened an investigation.

What organisations can take from it

Companies that offer AI services to European users are subject to the GDPR – regardless of where they are headquartered.

Authority / court
Garante per la protezione dei dati personali
Area of law
AI and digital regulation · AI systems
Legal basis
DSGVO, Art. 58 Abs. 2 lit. f (Beschränkung der Verarbeitung)
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
30 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2025 Mobile TeleSystems Public Joint Stock Company (MTS)Federal Court dismisses mobile operator MTS's challenge to sanctions listing CanadaBreaches of sanctions and embargoes Order

Russia's largest mobile and fixed-line operator challenged its inclusion on the Canadian Russia sanctions list directly in court. The Federal Court (2025 FC 181) upheld the striking out of the application, sought by the Attorney General of Canada, without leave to amend, because MTS should first have used the delisting procedure before the Minister provided for in the Regulations.

What organisations can take from it

The route against a sanctions listing is first the administrative delisting procedure; business partners must observe the listing until then.

Authority / court
Federal Court (2025 FC 181); Attorney General of Canada
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Special Economic Measures Act; Regulations Amending the Special Economic Measures (Russia) Regulations, SOR/2023-163, s. 8
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2025 Cembra Money Bank AGFDPIC ruling: Cembra Money Bank answered access requests too late and in generic terms SwitzerlandData subject rights and transparency Order

From December 2023 to September 2024, Cembra answered 9 of 13 access requests after the 30-day deadline had expired, and responded to all 13 people only with standard letters instead of the data actually processed about them. The Swiss Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) required the bank to provide the data subsequently.

What organisations can take from it

Access requests need a process with resources and deadline monitoring – boilerplate text is no substitute for genuine disclosure of data.

Relevance to training and awareness

Handling access requests

Authority / court
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSG Art. 25 Abs. 2 lit. b, Art. 25 Abs. 7
Action
Order
Status of proceedings
final
Sector
Financial services and insurance
Published
1 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jan 2025 OGH raises gun-jumping fine against food retailer from 1.5 to 70 million EUR AustriaMerger control €70m

A food retail group anonymised in the decision (R*) had, through its subsidiary, implemented a notifiable concentration without merger control clearance by means of a long-term lease of store space in a shopping centre (1 July 2018 to 20 September 2022). The Cartel Court (Kartellgericht) imposed a fine of 1.5 million EUR; Austria's Supreme Court (Oberster Gerichtshof, OGH) upheld the appeals of the Federal Competition Authority (Bundeswettbewerbsbehörde, BWB) and the Federal Cartel Prosecutor (Bundeskartellanwalt) and set the fine at 70 million EUR, taking into account the group turnover of 92.3 billion EUR and an earlier fine for prohibited implementation.

What organisations can take from it

Taking over stores by way of a lease or tenancy agreement can also be a notifiable concentration – expansion departments must check merger control requirements.

Relevance to training and awareness

Notification requirement for site takeovers through leases or tenancy agreements

Authority / court
Oberster Gerichtshof als Kartellobergericht (Antrag der Bundeswettbewerbsbehörde)
Area of law
Competition law · Merger control
Legal basis
§ 29 Z 1 lit a iVm § 17 Abs 1 KartG 2005
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Jan 2025 Infinox Capital LimitedFCA: £99,200 fine for Infinox over missing transaction reports United KingdomDisclosure and reporting obligations €117,946

The FCA fined Infinox Capital Limited £99,200. The FCA found that between October 2022 and March 2023 the firm failed to report to the FCA trades from its single-stock CFD business routed through one corporate account. In total 46,053 transaction reports were missing and were only back-reported in December 2023. The fine includes a 30% settlement discount.

Authority / court
Financial Conduct Authority (FCA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 26(1) UK MiFIR; section 206 FSMA 2000
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance

Original amount 99,200 GBP, converted at the ECB reference rate of 27 Jan 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jan 2025 GoogleGoogle commits to the CMA to tougher action against fake reviews United KingdomFake reviews Order

Google undertook to the CMA to improve the detection and removal of fake reviews, to ban repeat offenders worldwide, to place warnings on business profiles with manipulated reviews and deactivate their review function, and to set up simple reporting channels; the CMA will monitor implementation for three years.

What organisations can take from it

Companies that buy reviews risk visible warnings and the loss of their reviews on platforms.

Authority / court
Competition and Markets Authority (CMA)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Britisches Verbraucherschutzrecht (Verpflichtungszusagen)
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
Voluntary undertakings without a fine.
Published
24 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA USA, NYSecurity measures and risk management €1.92m

When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.

What organisations can take from it

Anyone changing data flows must know the security processes – training development teams is part of cyber defence.

Relevance to training and awareness

Secure software development and change processes

Missing or inadequate training played a role in the decision.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
PayPal has since remedied the deficiencies.
Published
23 Jan 2025

Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jan 2025 Užimtumo tarnyba prie Lietuvos Respublikos socialinės apsaugos ir darbo ministerijosEmployment service sends Excel file with data of 29,636 clients – 9,000 EUR LithuaniaData breaches and data security €9,000

An employee accidentally attached an Excel file containing data of 29,636 clients, including health data, to an e-mail sent to 292 clients. The Valstybinė duomenų apsaugos inspekcija (Lithuanian State Data Protection Inspectorate, VDAI) found that measures to prevent data leakage had not been sufficiently tested and that the employee had not been involved in data classification and had been insufficiently instructed; fine of 9,000 EUR. Date = publication; source: archived copy.

What organisations can take from it

One wrong attachment is enough for a mass data breach – DLP tools only help if all employees are trained and involved.

Relevance to training and awareness

Checking e-mail attachments, data classification

Missing or inadequate training played a role in the decision.

Authority / court
Valstybinė duomenų apsaugos inspekcija (VDAI)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
21 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2025 Pharnext SAPharnext: FDA setbacks disclosed late and glossed over FranceDisclosure and reporting obligations €800,000

The biotech company did not disclose as soon as possible the FDA's request for an additional study on PXT-3003 and the subsequent rejection of an SPA application, and disseminated misleading communications to shareholders. Sanctions: Pharnext 500,000 EUR, former CEO Daniel Cohen 200,000 EUR, former CEO David Horn Solomon 100,000 EUR.

What organisations can take from it

Negative feedback from regulatory authorities is regularly inside information and must not be given a positive spin in letters to shareholders.

Authority / court
Autorité des marchés financiers (AMF), Commission des sanctions
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 MAR; Art. 12 Abs. 1 lit. c und Art. 15 MAR
Action
Fine
Status of proceedings
under appeal
Sector
Chemicals and pharmaceuticals
Liability of senior managers
Daniel Cohen (co-founder, directeur général until April 2020): 200,000 EUR; David Horn Solomon (directeur général from April 2020): 100,000 EUR
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees RomaniaData breaches and data security €14,974

Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.

Relevance to training and awareness

BCC, use of messaging apps, sending customer documents

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
20 Jan 2025

Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jan 2025 Haas Automation, Inc.Haas Automation: CNC parts and unlock codes for blocked Russian defence companies USABreaches of sanctions and embargoes €1.01m

According to the US Treasury's Office of Foreign Assets Control (OFAC), from December 2019 to March 2022 the Californian machine tool manufacturer indirectly supplied, via its dealer network, one CNC machine, 13 spare parts orders and seven unlock codes for machines of blocked Russian defence and energy companies. According to OFAC, Haas agreed to a settlement of 1,044,781 USD with OFAC (OFAC treated eight of the 21 apparent violations as egregious; no voluntary self-disclosure); at the same time, Haas reached a separate settlement of 1.5 million USD with the US Commerce Department's Bureau of Industry and Security (BIS), which is not included in the amount shown. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "Haas Automation, Inc. Settles with OFAC for $1,044,781 for Apparent Violations of the Ukraine-/Russia-related Sanctions Regulations", 17 January 2025, https://ofac.treasury.gov/media/933956/download?inline; summarised in our own words.

What organisations can take from it

Spare parts and software unlock codes for machines already delivered are also services relevant to sanctions – end customers behind dealers must be known.

Relevance to training and awareness

End-customer screening in dealer sales, software unlocks as a service

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC); parallel U.S. Department of Commerce, Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Ukraine-/Russia-Related Sanctions Regulations (31 C.F.R. part 589; E.O. 13662); Export Administration Regulations
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Mitigating circumstances
Substantial remedial measures and extensive cooperation
Published
17 Jan 2025

Original amount 1,044,781 USD, converted at the ECB reference rate of 17 Jan 2025.

Checked against the official source on 25 Sep 2026 · Version 2 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jan 2025 Two Sigma Investments LP und Two Sigma Advisers LPTwo Sigma: 90 million USD – known weaknesses in investment models left unremedied for years USAOrganisational requirements €87.6m

Employees identified weaknesses in investment models that could affect client returns by March 2019 at the latest, but Two Sigma only acted in August 2023; there were no policies, and one employee made unauthorised changes to more than a dozen models. In addition, separation agreements required employees to declare that they had not filed any complaint with authorities. The U.S. Securities and Exchange Commission (SEC) imposed 90 million USD; Two Sigma had already repaid 165 million USD to clients.

What organisations can take from it

Model risks need a change and approval procedure – and identified weaknesses need a binding deadline for remediation.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Investment Advisers Act of 1940 (Antifraud, Compliance Rule 206(4)-7); Exchange Act Rule 21F-17(a)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Mitigating circumstances
Voluntary repayment of 165 million USD to affected funds and accounts.

Original amount 90,000,000 USD, converted at the ECB reference rate of 16 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jan 2025 Family International Realty LLCOFAC: USD 1.08 million settlement with Family International Realty over concealing properties of sanctioned oligarchs USABreaches of sanctions and embargoes €1.05m

Miami real estate company Family International Realty LLC and its owner are paying USD 1,076,923 under a joint settlement with OFAC for 73 apparent violations of the Ukraine-/Russia-related sanctions. According to OFAC's findings, between 2018 and 2023 the company and its owner, in a wilful evasion scheme, transferred nominal ownership of three luxury condominiums belonging to two sanctioned Russian oligarchs to non-sanctioned relatives and their shell companies and continued to rent them out; the company earned around USD 182,442 in commissions and reimbursements. OFAC treated the apparent violations as egregious and not voluntarily self-disclosed; the base penalty equalled the statutory maximum of USD 30,080,709. USD 182,442 is deemed satisfied by a forfeiture payment to the DOJ. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "Family International Realty LLC and its Owner Settle with OFAC for $1,076,923 Related to Apparent Violations of Ukraine-/Russia-Related Sanctions", 16 January 2025, https://ofac.treasury.gov/media/933941/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
E.O. 13685 §§ 2(a), 5(a), 6(a) (73 mutmaßliche Verstöße); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Published
16 Jan 2025

Original amount 1,076,923 USD, converted at the ECB reference rate of 16 Jan 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jan 2025 Hino Motors, Ltd.; Hino Motors Manufacturing U.S.A., Inc.; Hino Motors Sales U.S.A., Inc.Hino Motors: over 1 billion USD in penalties for falsified emissions test data USAEmissions and permits €1.02bn

From 2010 to 2019, the Toyota subsidiary altered test data, carried out tests improperly or fabricated them entirely for more than 50 engine families (around 105,000 on-road and 5,700 off-road diesel engines). The resolution with the U.S. Environmental Protection Agency (EPA) and the U.S. Department of Justice comprises a civil penalty of 525 million USD and a criminal fine of 521.76 million USD (together 1.047 billion USD), five years of probation and an import ban on diesel engines; including the recall and mitigation measures, the overall resolution totals more than 1.6 billion USD.

What organisations can take from it

Certification data is evidence – companies that embellish test results risk their existence, loss of market access and criminal prosecution.

Relevance to training and awareness

Integrity of test and certification data

Authority / court
U.S. Environmental Protection Agency / U.S. Department of Justice
Area of law
Environment and sustainability · Emissions and permits
Legal basis
Clean Air Act
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Culpability
intentional

Original amount 1,046,760,000 USD, converted at the ECB reference rate of 15 Jan 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jan 2025 Saxony: fine against estate agent for breach of AML due diligence obligations GermanyCustomer due diligence €800

The Saxony State Directorate (Landesdirektion Sachsen), as anti-money laundering supervisor for the non-financial sector, imposed a fine of 800 EUR on an estate agent, announced in anonymised form, for breach of the due diligence obligations under the German Money Laundering Act (GwG). The list of announcements shows numerous further fines and reprimands against agents ranging from 50 to 5,000 EUR.

What organisations can take from it

Estate agents must identify both contracting parties in good time – even small offices are subject to active anti-money laundering supervision.

Relevance to training and awareness

Identification of contracting parties in property brokerage

Authority / court
Landesdirektion Sachsen (Geldwäscheaufsicht Nichtfinanzsektor)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Geldwäschegesetz (Sorgfaltspflichten); Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Construction and real estate

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jan 2025 Donghai JA Solar Technology Co., Ltd.UFLPA list: solar manufacturer Donghai JA Solar Technology added USAForced and child labour Order

The U.S. Forced Labor Enforcement Task Force (FLETF) added the manufacturer of silicon ingots, wafers and solar modules from Jiangsu Province to the Uyghur Forced Labor Prevention Act (UFLPA) Entity List because it sources material from Xinjiang. The company's goods are therefore presumed to have been produced with forced labour on import into the US unless the importer rebuts this.

What organisations can take from it

Companies procuring solar modules should have the origin of the polysilicon documented without gaps.

Authority / court
U.S. Department of Homeland Security (Forced Labor Enforcement Task Force)
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
Uyghur Forced Labor Prevention Act, Section 2(d)(2)(B)(v)
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Published
15 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jan 2025 Xinjiang Zijin Zinc Industry Co., Ltd.UFLPA list: zinc producer Xinjiang Zijin Zinc Industry added USAForced and child labour Order

The U.S. Forced Labor Enforcement Task Force (FLETF) listed the mining company from Kizilsu Prefecture on two grounds: for working with the Xinjiang government on the recruitment and transfer of persecuted groups, and for sourcing material from Xinjiang. The company's goods are therefore presumed to have been produced with forced labour on import into the US unless the importer rebuts this.

What organisations can take from it

Metal processors should know the smelters and mines of their upstream suppliers and screen them against the UFLPA Entity List.

Authority / court
U.S. Department of Homeland Security (Forced Labor Enforcement Task Force)
Area of law
Supply chain and human rights · Forced and child labour
Legal basis
Uyghur Forced Labor Prevention Act, Section 2(d)(2)(B)(ii) und (v)
Action
Order
Status of proceedings
unknown
Sector
Steel and metals
Published
15 Jan 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2025 AFCO (Tochtergesellschaft der Zep Inc.)Zep subsidiary AFCO: $161,310 proposed after nitrogen dioxide release USAWorkplace safety and accidents €157,452

In July 2024, nitrogen dioxide above the exposure limit was released during chemical processing at the plant of Zep subsidiary AFCO in Chambersburg (Pennsylvania); twelve employees were examined in hospital and two were admitted. The U.S. Occupational Safety and Health Administration (OSHA) criticised the lack of an emergency action plan, deficient respiratory protection and hazard communication programmes and a delayed evacuation, and proposed $161,310 (including one repeat violation).

What organisations can take from it

In the event of a chemical release, a rehearsed emergency and evacuation plan determines how many employees come to harm.

Relevance to training and awareness

Responding to gas releases and evacuation

Authority / court
U.S. Department of Labor – Occupational Safety and Health Administration (OSHA)
Area of law
Health and safety and employment law · Workplace safety and accidents
Legal basis
29 CFR 1910.120, 1910.134, 1910.1200
Action
Fine
Status of proceedings
unknown
Sector
Chemicals and pharmaceuticals
Repeat case
yes
Published
14 Jan 2025

Original amount 161,310 USD, converted at the ECB reference rate of 14 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Jan 2025 BMO Capital Markets Corp.BMO Capital Markets: 40.7 million USD – inadequate supervision of bond desk USAOrganisational requirements €39.9m

From December 2020 to May 2023, staff on the agency CMO bond desk sold mortgage-backed bonds worth around 3 billion USD using misleading metrics; the broker-dealer’s supervisory procedures contained no requirements for the structuring and sale of these bonds. BMO paid 19,417,908 USD in disgorgement, 2,241,507 USD in interest and a civil penalty of 19 million USD.

What organisations can take from it

Tailor supervisory procedures to the actual products and sales practices of each desk – generic policies are not enough.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Securities Exchange Act of 1934, Section 15(b)(4)(E) (Failure to supervise)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more

Original amount 40,659,415 USD, converted at the ECB reference rate of 13 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Jan 2025 Rio Tinto Fer et Titane inc.Rio Tinto Fer et Titane: 2 million CAD fine for nickel-bearing and acidic mine effluent Canada, QCWaste and hazardous substances €1.36m

At the Lac Tio mine near Havre-Saint-Pierre, there were nickel exceedances in 2023 after severed power cables disabled the effluent treatment, untreated acidic discharges in the summer, and a failure to take samples after an unauthorised discharge. The company pleaded guilty to eight counts and is paying 2 million CAD into the Environmental Damages Fund.

What organisations can take from it

Failures of effluent treatment must be covered by emergency plans and documented through the required sampling.

Relevance to training and awareness

Sampling and monitoring obligations after malfunctions

Authority / court
Court of Québec (Ermittlungen: Environment and Climate Change Canada)
Area of law
Environment and sustainability · Waste and hazardous substances
Legal basis
Fisheries Act, Subsection 36(3); Metal and Diamond Mining Effluent Regulations
Action
Fine
Status of proceedings
unknown
Sector
Steel and metals
Mitigating circumstances
Guilty plea.
Published
14 Jan 2025

Original amount 2,000,000 CAD, converted at the ECB reference rate of 13 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jan 2025 Markom Management LimitedOFSI: GBP 300,000 penalty for Markom Management over a refund to a designated person United KingdomBreaches of sanctions and embargoes €358,453

On 10 January 2025 OFSI imposed a monetary penalty of GBP 300,000 on the UK company Markom Management Limited, which in 2018 provided fiduciary, administration and bookkeeping services to companies. According to OFSI's findings, on 20 February 2018 the company instructed the return of an overpayment of around GBP 416,590 to a person designated under EU law, thereby making funds directly available to that person. OFSI attributed this to a lack of processes, poor knowledge of sanctions and a wish to make the payment quickly. The company reported the breach in October 2018; OFSI did not grant a disclosure discount. The notice of intent of 1 August 2024 had proposed GBP 400,000; after representations from the company OFSI reduced the amount. A ministerial review upheld the penalty on 4 June 2025. The publication does not mention any pending review. Source: Office of Financial Sanctions Implementation (OFSI), HM Treasury, "Imposition of monetary penalty: Markom Management Limited", 31 July 2025, https://www.gov.uk/government/publications/imposition-of-monetary-penalty-markom-management-limited. Contains public sector information licensed under the Open Government Licence v3.0 (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/).

Authority / court
HM Treasury, Office of Financial Sanctions Implementation (OFSI)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Ukraine (European Union Financial Sanctions) (No. 2) Regulations 2014 (Umsetzung der Verordnung (EU) Nr. 269/2014); Geldbuße nach s. 146 Policing and Crime Act 2017
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
31 Jul 2025

Original amount 300,000 GBP, converted at the ECB reference rate of 10 Jan 2025.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jan 2025 Εθνική Τράπεζα της Ελλάδος Α.Ε. (National Bank of Greece)Greece: 120,000 EUR against National Bank of Greece after misdirected payment via mobile number GreeceData breaches and data security €120,000

An IRIS transfer made by mobile number via the bank’s app ended up with an uninvolved customer instead of the intended recipient because the number had been assigned incorrectly. By Decision 3/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed 100,000 EUR for inaccurate data, insufficient security, lack of data protection by design and failure to notify the data breach, as well as 20,000 EUR for breach of the right of access.

What organisations can take from it

Even a single misdirected payment can be a notifiable data breach – customer complaints must be assessed internally as a possible incident.

Relevance to training and awareness

Recognising and reporting data breaches

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. d und f, Art. 15, 25, 32, 33, 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jan 2025 Arian Financial LLPFCA: small broker Arian Financial fined over cum-ex money laundering risks United KingdomInternal controls €344,791

From January to September 2015, the broker had no effective systems against financial crime and was therefore exposed to the risk of facilitating fraudulent trading and money laundering in connection with cum-ex trades. Following proceedings before the Upper Tribunal, the UK Financial Conduct Authority (FCA) set the fine at £288,962.53 instead of the £744,745 originally intended.

What organisations can take from it

Even small brokers must question unusually lucrative, circular trading patterns before executing them.

Relevance to training and awareness

Recognising warning signs in unusual trading structures

Authority / court
Financial Conduct Authority (FCA)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
FCA Principles 2 und 3 (PRIN 2, PRIN 3)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Mitigating circumstances
Reduction by the Upper Tribunal
Published
10 Jan 2025

Original amount 288,962.53 GBP, converted at the ECB reference rate of 9 Jan 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jan 2025 XCL Resources Holdings LLC, Verdun Oil Company II LLC, EP Energy LLCFTC: record penalty of 5.6 million USD for gun-jumping in oil producer acquisition USAMerger control €5.39m

During the HSR waiting period for the 1.4 billion USD acquisition of EP Energy, XCL and Verdun already took control of day-to-day operations: they halted drilling projects, managed customer contracts in Utah and coordinated prices in Texas (94 days). In a settlement filed by the DOJ on behalf of the FTC, the companies agreed to a civil penalty of 5.6 million USD – the highest ever for gun-jumping in the US; court approval under the Tunney Act was still pending at the time of publication.

What organisations can take from it

Until clearance, the buyer must not exert any influence on the target company's operations – integration teams need clear gun-jumping rules.

Relevance to training and awareness

Standstill obligation before clearance (gun-jumping) in integration planning

Authority / court
Federal Trade Commission (Klage durch das U.S. Department of Justice)
Area of law
Competition law · Merger control
Legal basis
Hart-Scott-Rodino Act
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
7 Jan 2025

Original amount 5,600,000 USD, converted at the ECB reference rate of 7 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Jan 2025 Luxembourg credit institution: 175,000 EUR for late responses to data subject requests LuxembourgData subject rights and transparency €175,000

Following 47 complaints, the Commission nationale pour la protection des données (Luxembourg data protection authority, CNPD) found that a Luxembourg credit institution (pseudonymised in the decision as ‘Société A’) had not responded to data subjects’ requests on time; the CNPD did not accept the reference to the COVID-19 pandemic. It issued a reprimand (rappel à l’ordre) and imposed 175,000 EUR.

What organisations can take from it

Data subject requests require deadline tracking and a monitored DPO mailbox – staff shortages are no excuse.

Relevance to training and awareness

Deadlines for data subject requests

Authority / court
Commission nationale pour la protection des données (CNPD) – formation restreinte
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 12 Abs. 3 und 4
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jan 2025 GGL Projects, Inc. (Sitejabber)Sitejabber: review platform counted reviews before goods were received USAFake reviews Order

According to the FTC, the AI-powered review platform collected star ratings for its business customers at the time of purchase, before customers had received the product or service, thereby inflating average ratings and review counts, including in search engine results. The FTC issued a final settlement order prohibiting such misrepresentations.

What organisations can take from it

Ratings submitted before use must not be included in averages as experience-based reviews.

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Section 5 FTC Act
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Published
3 Jan 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2024 SkyGeek Logistics, Inc.OFAC: USD 22,172 settlement with SkyGeek Logistics over shipments and refunds to designated aviation suppliers USABreaches of sanctions and embargoes €21,342

New York aviation products supplier SkyGeek Logistics, Inc. is paying USD 22,172 under a settlement with OFAC for six apparent violations of the Russia sanctions. According to OFAC's findings, between January and March 2024 the company sent four shipments worth USD 3,429.76 to two UAE-based companies and attempted two refunds totalling USD 17,511.63, although both had previously been added to the SDN List for their role in Russia's aerospace and technology sectors. Customers were initially not rescreened before refunds. OFAC treated the apparent violations as non-egregious and four of the six transactions as voluntarily self-disclosed; the base penalties totalled USD 27,715. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "SkyGeek Logistics, Inc. Settles with OFAC for $22,172 for Apparent Violations of the Russian Harmful Foreign Activities Sanctions Regulations", 31 December 2024, https://ofac.treasury.gov/media/933866/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Russian Harmful Foreign Activities Sanctions Regulations, 31 C.F.R. § 587.201 (sechs mutmaßliche Verstöße); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Published
31 Dec 2024

Original amount 22,172 USD, converted at the ECB reference rate of 31 Dec 2024.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Hrvatski lovački savezCroatia: 89,935 EUR against hunting association for predatory pricing in hunter training CroatiaAbuse of market power €89,935

From 2022 to March 2024, the Croatian Hunting Association offered hunter training below cost and financed this from areas in which it holds a statutory monopoly in order to drive out competitors. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed 89,935.20 EUR and ordered separate cost accounting; the High Administrative Court dismissed the action on 17 December 2025.

What organisations can take from it

An organisation holding a monopoly in one market must not use the profits from it to undercut in neighbouring markets – separate cost accounting provides evidence.

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 13 Nr. 1 Zakon o zaštiti tržišnog natjecanja (ZZTN)
Action
Fine
Status of proceedings
final
Sector
Other
Published
10 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father CyprusEmployee data Reprimand or warning

A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.

What organisations can take from it

HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.

Relevance to training and awareness

Confidential delivery of HR correspondence

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Dec 2024 Argosy Securities Inc.FINTRAC: CAD 66,000 penalty on Argosy Securities Inc. for 3 violations of anti-money laundering obligations CanadaInternal controls €44,159

According to FINTRAC, Argosy Securities Inc. is a securities dealer or wealth management firm based in Richmond Hill, Ontario. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 66,000 on the company on 20 December 2024. According to FINTRAC's findings, made during a compliance examination, the company committed 3 violations of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violations concerned written compliance policies and procedures, assessing and documenting money laundering and terrorist financing risks and the prescribed review of the compliance programme. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on Argosy Securities Inc.", published 13 February 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-02-13-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTF Regulations 156(1)(b), 156(1)(c), 156(1)(f), 156(2), 156(3); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
13 Feb 2025

Original amount 66,000 CAD, converted at the ECB reference rate of 20 Dec 2024.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Dec 2024 AAR Corp.Aviation services provider AAR pays 55.6 million USD for bribery in Nepal and South Africa USABribery of public officials €53.5m

Through an agent and a joint venture partner, AAR paid sham commissions to public officials in order to secure the sale of two Airbus A330s to Nepal Airlines and maintenance services for South African Airways Technical. SEC: 23,451,100 USD in disgorgement and 5,785,524 USD in interest; DOJ criminal penalty of 26,363,029 USD under a Non-Prosecution Agreement.

What organisations can take from it

State-owned airlines are public contracting entities – scrutinise commissions to intermediaries in aircraft transactions rigorously.

Relevance to training and awareness

Agents and joint venture partners in transactions with state-owned airlines

Authority / court
U.S. Securities and Exchange Commission (SEC); U.S. Department of Justice
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA (Anti-Bestechung, Buchführung, interne Kontrollen); Non-Prosecution Agreement
Action
Fine
Status of proceedings
final
Sector
Transport, logistics and shipping
Employees
1,000 to 9,999
Culpability
intentional
Mitigating circumstances
Disclosure following press reports, cooperation (forensics, translations, witnesses) and remedial measures.
Liability of senior managers
A former senior employee of an AAR subsidiary, Deepak Sharma (named in the SEC order), was involved.
Published
19 Dec 2024

Original amount 55,599,653 USD, converted at the ECB reference rate of 19 Dec 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Dec 2024 Danske Shoppingcentre P/SDanske Shoppingcentre: 350,000 DKK for camera above urinal in City2 shopping centre DenmarkVideo surveillance €46,909

Because of vandalism, the operator of the City2 shopping centre had installed cameras in toilet areas; one camera in the men’s toilets also captured the area in front of the urinal despite a black masking, and there were no signs. The court followed the Danish Data Protection Agency (Datatilsynet) and the public prosecutor and imposed 350,000 DKK for breach of the data minimisation principle.

What organisations can take from it

Cameras have virtually no place in toilet and changing areas – masking parts of the image is no substitute for checking the location.

Authority / court
Retten i Glostrup (auf Anzeige der Datatilsynet)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 5 Abs. 1 lit. c; databeskyttelsesloven § 41; tv-overvågningsloven
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate

Original amount 350,000 DKK, converted at the ECB reference rate of 19 Dec 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Dec 2024 CNIL: 40,000 EUR against estate agency over constant video surveillance of staff FranceVideo surveillance €40,000

An estate agency (name redacted in the publication) continuously filmed workstations and break areas with image and sound, accessible via a smartphone app, and used the software Time Doctor to record keyboard and mouse activity as well as screenshots of the computers; several people accessed this data via the administrator account of one of them. The French data protection authority (CNIL) found infringements of data minimisation, legal basis, information, security and the obligation to carry out an impact assessment, and imposed 40,000 EUR.

What organisations can take from it

Permanent video and audio recording of workplaces is practically never proportionate – not even in a small business.

Relevance to training and awareness

Permissible employee monitoring and password security

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. c, Art. 6, 12, 13, 32, 35 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Dec 2024 MSBG International Holdings Ltd.FINTRAC: CAD 24,750 penalty on MSBG International Holdings Ltd. for one violation of anti-money laundering obligations CanadaInternal controls €16,577

According to FINTRAC, MSBG International Holdings Ltd. is a money services business based in Vancouver, British Columbia. Canada's anti-money laundering regulator FINTRAC imposed an administrative monetary penalty of CAD 24,750 on the company on 19 December 2024. According to FINTRAC's findings, made during a compliance examination in 2023, the company committed one violation of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations. As described by the regulator, the violation concerned written compliance policies and procedures. According to FINTRAC, the penalty has been paid in full and the case is closed. Source: FINTRAC (Financial Transactions and Reports Analysis Centre of Canada), "Administrative monetary penalty on MSBG International Holdings Ltd.", published 25 February 2025, https://fintrac-canafe.canada.ca/pen/amps/pen-2025-02-25-eng; summarised in our own words; not an official version and not a reproduction of the original.

Authority / court
Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
PCMLTF Regulations 71(1)(b); Verwaltungsgeldbuße nach Teil 4.1 PCMLTFA
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
25 Feb 2025

Original amount 24,750 CAD, converted at the ECB reference rate of 19 Dec 2024.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2024 Ericsson Nikola Tesla d.d., Kodeks d.o.o., Retel d.o.o., Vatel d.o.o., LUMISS d.o.o., Mitel Austria GmbHCroatia: 1.17 million EUR against Ericsson Nikola Tesla and five partners for customer allocation CroatiaCartels and collusion €1.17m

From 2010 to 2015, the suppliers of Ericsson/Aastra/Mitel telephone systems (PBX) allocated customers among themselves so as not to undercut each other. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed a total of 1,170,968.24 EUR, of which 785,570.58 EUR on Ericsson Nikola Tesla; one leniency applicant (Steiner) was not penalised, and Kodeks received a reduction.

What organisations can take from it

Dealers of the same brand are also competitors – agreements on ‘own’ customers are a hardcore cartel.

Relevance to training and awareness

No agreements on customer or territorial allocation

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 8 Zakon o zaštiti tržišnog natjecanja (ZZTN)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Leniency programme for two participants
Published
5 Mar 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2024 Córdoba Music Group LLCOFAC: USD 41,591 settlement with Córdoba Music Group over instrument shipments to Iran USABreaches of sanctions and embargoes €39,626

Californian musical instrument manufacturer Córdoba Music Group LLC is paying USD 41,591 under a settlement with OFAC for apparent violations of the Iran sanctions. According to OFAC's findings, between November 2019 and March 2022 the company made nine shipments of instruments and accessories worth USD 118,831 to a trading company in Dubai, knowing that the goods were destined for an Iranian distributor. According to OFAC, the company apparently did not realise, partly owing to a lack of compliance training, that indirect exports to Iran were prohibited. This came to light after the company was acquired by a new owner. OFAC treated the apparent violations as non-egregious and voluntarily self-disclosed; the base penalty was USD 59,416. Source: U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC), enforcement release "Córdoba Music Group LLC Settles with OFAC for $41,591 Related to Apparent Violations of the Iranian Transactions and Sanctions Regulations", 18 December 2024, https://ofac.treasury.gov/media/933726/download?inline; summarised in our own words.

Authority / court
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Area of law
Sanctions and export control · Breaches of sanctions and embargoes
Legal basis
Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204(a) (neun Lieferungen); Vergleich nach den Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A
Action
Fine
Status of proceedings
final
Sector
Other
Published
18 Dec 2024

Original amount 41,591 USD, converted at the ECB reference rate of 18 Dec 2024.

Checked against the official source on 26 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification IrelandData breaches and data security €251m

In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).

What organisations can take from it

Make data breach notifications complete, and document every breach internally in a traceable manner.

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
17 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 Sambla Group OySambla Group: 950,000 EUR – loan applications accessible via unprotected links FinlandData breaches and data security €950,000

On the loan comparison portals lainaparkki.fi and rahoitu.fi, application data (including income, housing costs, marital status, children) could be accessed by anyone who knew the personal customer link; the links were targeted by phishing and data reached third parties. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 950,000 EUR and ordered the data subjects to be notified.

What organisations can take from it

Personal links are not access protection – sensitive customer data requires authentication and regular security testing.

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
20 Dec 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2024 GymBeam s.r.o.; Gymbeam Hungary Kft.GymBeam: 100 million HUF for impermissible health claims on food supplements HungaryMisleading advertising and pricing €244,230

The food supplement retailer made extensive use of prohibited medicinal claims and unauthorised health claims in its advertising, suggested false discounts with struck-through prices and did not inform customers about how customer reviews were checked. Following acknowledgement and a commitment to a compliance programme with training, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 100 million HUF.

What organisations can take from it

Product texts in online shops are advertising – content teams need the list of authorised health claims.

Relevance to training and awareness

Permissible advertising claims for foods and food supplements

Missing or inadequate training played a role in the decision.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Verbot unlauterer Geschäftspraktiken; EU-Health-Claims-Verordnung (VJ/51/2022)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Acknowledgement, waiver of legal remedies and compliance programme with internal training and membership of the advertising self-regulatory body.
Published
17 Dec 2024

Original amount 100,000,000 HUF, converted at the ECB reference rate of 17 Dec 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Load 20 more of 258

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial