Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by country- Germany 39 cases 10 % · €204.8m
- Italy 26 cases 7 % · €462.4m
- France 25 cases 7 % · €823.9m
- EU level 20 cases 5 % · €3.8bn
- Netherlands 18 cases 5 % · €463.6m
- Slovakia 17 cases 4 % · €142.7m
- Austria 16 cases 4 % · €86m
- Poland 15 cases 4 % · €37.2m
- Estonia 13 cases 3 % · €426,000
- Romania 13 cases 3 % · €354,279
- 18 more180 cases
What for?
by area of lawAll areas of law
- Data protection 136 cases 36 % · €2bn
- Competition law 82 cases 21 % · €2.73bn
- Capital markets and financial supervision 36 cases 9 % · €16.7m
- Money laundering and terrorist financing 34 cases 9 % · €101.3m
- Consumer protection and online retail 33 cases 9 % · €204.2m
- AI and digital regulation 16 cases 4 % · €2.5bn
- Information security and cyber 8 cases 2 % · €464,702
- Bribery and corruption 8 cases 2 % · €102.8m
- Health and safety and employment law 7 cases 2 % · €953,069
- Whistleblower protection 7 cases 2 % · €29,200
- 4 more15 cases
Who?
by sectorAll sectors
- Financial services and insurance 83 cases 22 % · €144.9m
- Retail and e-commerce 44 cases 12 % · €1.37bn
- Telecoms, IT and software 36 cases 9 % · €1.58bn
- Other 33 cases 9 % · €45.8m
- Media and online platforms 31 cases 8 % · €1.96bn
- Energy and utilities 23 cases 6 % · €271.3m
- Healthcare 22 cases 6 % · €29.7m
- Public sector 22 cases 6 % · €14.4m
- Construction and real estate 21 cases 5 % · €126m
- Transport, logistics and shipping 20 cases 5 % · €819.9m
- 6 more47 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 14 | €26.5m |
| Q1 2024 | 15 | €92.2m |
| Q2 2024 | 10 | €54.9m |
| Q3 2024 | 14 | €821.6m |
| Q4 2024 | 38 | €878.1m |
| Q1 2025 | 26 | €82.6m |
| Q2 2025 | 40 | €2.12bn |
| Q3 2025 | 35 | €509.4m |
| Q4 2025 | 54 | €857.8m |
| Q1 2026 | 45 | €257.6m |
| Q2 2026 | 44 | €398.5m |
| Q3 2026 | 47 | €1.56bn |
382 cases
23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering €890m
In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.
Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Jul 2026
- Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
- IP/26/1670: Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Sep 2026 Plaček Pet Products s.r.o.Plaček Pet Products: 36.4 million CZK for minimum prices on pet food €1.49m
From January 2013 to March 2022, the distributor of premium pet food and pet supplies imposed minimum resale prices on its retailers and threatened sanctions if they were undercut. In a settlement procedure, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 36.438 million CZK; the company ended the conduct after the inspection and introduced a compliance programme.
Never enforce recommended retail prices with supply stops or sanctions – sales teams need clear rules on this.
Price requirements imposed on retailers in sales
Missing or inadequate training played a role in the decision.
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Verbot vertikaler Preisbindung (tschechisches Wettbewerbsgesetz, Art. 101 AEUV)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Mitigating circumstances
- Termination immediately after the inspection, information of customers about free pricing, full cooperation, settlement and newly introduced compliance programme.
- Published
- 24 Sep 2026
Original amount 36,438,000 CZK, converted at the ECB reference rate of 24 Sep 2026.
- Distributor krmiv pro domácí zvířata dostal pokutu 36 milionů korun za diktování cen maloobchodníkům Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2026 Audax Renovables, S.A. – Sucursal em PortugalPortugal: 22,000 EUR against Audax Renovables over missing gas reserves and hotline €22,000
On a total of 249 days, the Portuguese branch of the energy supplier failed to hold the mandatory natural gas security reserves, did not correctly show network charges on invoices, did not publish, or published late, mandatory information and its quality report, and failed to meet the standards for hotline waiting times. In a settlement procedure, the Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) set a fine of 44,000 EUR and reduced it to 22,000 EUR.
Security of supply and service obligations in the energy sector are sanctioned individually – a compliance calendar for reserves and reports helps.
- Authority / court
- Entidade Reguladora dos Serviços Energéticos (ERSE)
- Area of law
- Other
- Legal basis
- Regime Sancionatório do Setor Energético (RSSE), Art. 28, 29; Decreto-Lei n.º 62/2020, Art. 96; RRC; RQS
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- Settlement (transação) with full admission, remediation of all infringements
- ERSE – Decisões sancionatórias: Processos n.º 47/2024 e 62/2025 – Audax Renovables, S.A. – Sucursal em Portugal Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Sep 2026 Lesy České republiky, s.p. (Lesy ČR)Lesy ČR: 17.3 million CZK for export ban on wood chips €710,383
From July 2021 to July 2024, the state forestry company contractually prohibited a customer from actively and passively exporting wood chips and logging residues and secured the ban with a right of termination. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) considered this a restriction of competition by object under Czech and EU law and imposed 17.268 million CZK (first instance, not final).
State-owned companies are also subject to competition law – have export and resale bans in framework agreements legally reviewed before signing.
Anticompetitive clauses in supply contracts
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (Exportverbot, S0733/2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Voluntary termination immediately after proceedings were opened.
- Published
- 17 Sep 2026
Original amount 17,268,000 CZK, converted at the ECB reference rate of 17 Sep 2026.
- Lesy ČR banned wood-chip exports and were imposed a fine of more than CZK 17 million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers €177,187
As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.
Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- No established damage to investors; remedial measures already taken during the investigation.
- Published
- 16 Sep 2026
Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.
- FI ger AIFM Capital en anmärkning och en sanktionsavgift (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies Order
Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.
Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 16 Sep 2026
- Finantsinspektsioon tegi Wallester AS-ile ettekirjutuse (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker €12,350
In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.
External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.
Conflicts of interest of external advisers in procurement procedures
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Other
- Legal basis
- Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Published
- 15 Sep 2026
Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.
- ÚOHS uložil pokutu 300 tisíc korun resortu životního prostředí kvůli neošetření možného střetu zájmů Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator €8,000
Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.
Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante – Provvedimento n. 619 del 3 settembre 2026 [10294255] (ASIS Trento) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports €97,622
The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.
Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction
- Published
- 4 Sep 2026
- Settlement Agreement Publication Notice – EM@NEY P.L.C. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination €160,099
At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.
A customer risk assessment belongs before business starts, not in a later remediation project.
Risk-based customer profiles and source of funds
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction; remediation demonstrated
- Published
- 2 Sep 2026
- Settlement Agreement Publication Notice – MiFinity Malta Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 Flower bulb business failed to disclose hours of Polish seasonal workers – fine of around 95,600 EUR €95,588
A lily and tulip grower with an average of around 50 (at peak 75) employees, where Polish migrant workers are employed (anonymised in the judgment), was unable to produce sufficient records of hours worked and wages paid for 18 employees for September 2020 to February 2021. The Dutch Minister of Social Affairs and Employment (Minister van Sociale Zaken en Werkgelegenheid) imposed 118,000 EUR in 2024 (112,100 EUR after objection); the North Netherlands District Court (Rechtbank Noord-Nederland) reduced the fine to 95,587.50 EUR, partly because of measures taken and excessively long proceedings.
Companies employing seasonal workers must be able to document hours and wage payments for each person without gaps – missing records are fined separately for each employee.
- Authority / court
- Rechtbank Noord-Nederland (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid / Nederlandse Arbeidsinspectie)
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- Art. 18b Abs. 2 Wet minimumloon en minimumvakantiebijslag (Wml)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Food and agriculture
- Employees
- 50 to 249
- Mitigating circumstances
- Reduction of 12.5 % for appropriate measures, 5 % for delay and 2,500 EUR for exceeding the reasonable length of proceedings.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking €11.7m
From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.
Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.
Coordination with cooperation partners on customers and tenders
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Published
- 26 Aug 2026
Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.
- Fines exceeding CZK 280 million imposed on O2 Czech Republic and SHERLOG Technology for cartel agreement Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants Order
In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.
Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.
- Authority / court
- Konkurrencerådet (Danish Competition Council)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Konkurrenceloven; AEUV Art. 102
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 26 Aug 2026
- KFST – Wolt has abused its dominant position (26.08.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Elizabeta Promet d.o.o., SolinCroatia: 10,000 EUR against Elizabeta Promet for deliveries without a written contract €10,000
As a buyer with significant bargaining power, the company from Solin purchased agricultural and food products from two suppliers without written contracts. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) considered this an unfair trading practice and, taking mitigating circumstances into account, imposed 10,000 EUR (date = publication).
In food purchasing, the mere absence of written supply contracts is an infringement – a simple contract standard prevents this.
Written form for supply contracts in food purchasing
- Authority / court
- Agencija za zaštitu tržišnog natjecanja (AZTN)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Several mitigating circumstances taken into account
- Published
- 25 Aug 2026
- Provedba ZNTP-a: AZTN kaznio ELIZABETU PROMET d.o.o., Solin s 10.000,00 eura zbog nametanja nepoštenih trgovačkih praksi Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 WH Media GmbHKommAustria penalises person responsible for W24 over advertising in news programme €500
On 29 May 2024, the Vienna broadcaster W24 aired advertising in split screen within the programme ‘24 Stunden Wien’, did not adequately separate advertising from programming and, at around 50 minutes, significantly exceeded the permitted 12 minutes of advertising per hour. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) imposed fines totalling 500 EUR (plus 50 EUR in costs) on the body authorised to represent the company externally; the GmbH is jointly and severally liable under § 9 (7) VStG (Austrian Administrative Penal Act).
Advertising time limits and the separation requirement also apply to small regional broadcasters – management is personally liable via § 9 VStG.
- Authority / court
- Kommunikationsbehörde Austria (KommAustria)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 64 Abs. 2 Z 9 i. V. m. §§ 43 Abs. 2, 44 Abs. 1, 45 Abs. 1 AMD-G; § 9 VStG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- negligent
- Mitigating circumstances
- No previous record, duration of proceedings, remorseful confession and remedial measures initiated.
- Liability of senior managers
- Fine imposed on the body responsible externally (§ 9 (1) VStG); the company is jointly and severally liable.
- Published
- 19 Aug 2026
- KommAustria, Straferkenntnis KOA 05.910 / 2025-0.418.178-6-A (W24) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link