Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EU Clear all filters
382cases from 28 jurisdictions
€7.66bnTotal of monetary amounts (325 cases with an amount)
€890mLargest single case: Google
€250,000Median per case with an amount

Click a bar to drill down one level.

Where?

by country
  1. EU level €3.8bn 50 % · 20 cases
  2. Ireland €895m 12 % · 10 cases
  3. France €823.9m 11 % · 25 cases
  4. Spain €563.1m 7 % · 10 cases
  5. Netherlands €463.6m 6 % · 18 cases
  6. Italy €462.4m 6 % · 26 cases
  7. Germany €204.8m 3 % · 39 cases
  8. Slovakia €142.7m 2 % · 17 cases
  9. Austria €86m 1 % · 16 cases
  10. Czechia €52.2m 1 % · 9 cases
  11. 18 more€163.4m

What for?

by area of law

All areas of law

  1. Competition law €2.73bn 36 % · 82 cases
  2. AI and digital regulation €2.5bn 33 % · 16 cases
  3. Data protection €2bn 26 % · 136 cases
  4. Consumer protection and online retail €204.2m 3 % · 33 cases
  5. Bribery and corruption €102.8m 1 % · 8 cases
  6. Money laundering and terrorist financing €101.3m 1 % · 34 cases
  7. Capital markets and financial supervision €16.7m 0 % · 36 cases
  8. Environment and sustainability €1m 0 % · 6 cases
  9. Health and safety and employment law €953,069 0 % · 7 cases
  10. Information security and cyber €464,702 0 % · 8 cases
  11. 4 more€490,550

Who?

by sector

All sectors

  1. Media and online platforms €1.96bn 26 % · 31 cases
  2. Telecoms, IT and software €1.58bn 21 % · 36 cases
  3. Retail and e-commerce €1.37bn 18 % · 44 cases
  4. Transport, logistics and shipping €819.9m 11 % · 20 cases
  5. Automotive €547m 7 % · 11 cases
  6. Chemicals and pharmaceuticals €488m 6 % · 5 cases
  7. Energy and utilities €271.3m 4 % · 23 cases
  8. Financial services and insurance €144.9m 2 % · 83 cases
  9. Construction and real estate €126m 2 % · 21 cases
  10. Manufacturing and mechanical engineering €99.5m 1 % · 9 cases
  11. 6 more€244.3m

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 202314€26.5m
Q1 202415€92.2m
Q2 202410€54.9m
Q3 202414€821.6m
Q4 202438€878.1m
Q1 202526€82.6m
Q2 202540€2.12bn
Q3 202535€509.4m
Q4 202554€857.8m
Q1 202645€257.6m
Q2 202644€398.5m
Q3 202647€1.56bn

382 cases

23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering EU levelPlatform obligations €890m

In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.

What organisations can take from it

Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Sep 2026 Plaček Pet Products s.r.o.Plaček Pet Products: 36.4 million CZK for minimum prices on pet food CzechiaCartels and collusion €1.49m

From January 2013 to March 2022, the distributor of premium pet food and pet supplies imposed minimum resale prices on its retailers and threatened sanctions if they were undercut. In a settlement procedure, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 36.438 million CZK; the company ended the conduct after the inspection and introduced a compliance programme.

What organisations can take from it

Never enforce recommended retail prices with supply stops or sanctions – sales teams need clear rules on this.

Relevance to training and awareness

Price requirements imposed on retailers in sales

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Verbot vertikaler Preisbindung (tschechisches Wettbewerbsgesetz, Art. 101 AEUV)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Termination immediately after the inspection, information of customers about free pricing, full cooperation, settlement and newly introduced compliance programme.
Published
24 Sep 2026

Original amount 36,438,000 CZK, converted at the ECB reference rate of 24 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Audax Renovables, S.A. – Sucursal em PortugalPortugal: 22,000 EUR against Audax Renovables over missing gas reserves and hotline PortugalOther €22,000

On a total of 249 days, the Portuguese branch of the energy supplier failed to hold the mandatory natural gas security reserves, did not correctly show network charges on invoices, did not publish, or published late, mandatory information and its quality report, and failed to meet the standards for hotline waiting times. In a settlement procedure, the Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) set a fine of 44,000 EUR and reduced it to 22,000 EUR.

What organisations can take from it

Security of supply and service obligations in the energy sector are sanctioned individually – a compliance calendar for reserves and reports helps.

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Other
Legal basis
Regime Sancionatório do Setor Energético (RSSE), Art. 28, 29; Decreto-Lei n.º 62/2020, Art. 96; RRC; RQS
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Settlement (transação) with full admission, remediation of all infringements

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Sep 2026 Lesy České republiky, s.p. (Lesy ČR)Lesy ČR: 17.3 million CZK for export ban on wood chips CzechiaCartels and collusion €710,383

From July 2021 to July 2024, the state forestry company contractually prohibited a customer from actively and passively exporting wood chips and logging residues and secured the ban with a right of termination. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) considered this a restriction of competition by object under Czech and EU law and imposed 17.268 million CZK (first instance, not final).

What organisations can take from it

State-owned companies are also subject to competition law – have export and resale bans in framework agreements legally reviewed before signing.

Relevance to training and awareness

Anticompetitive clauses in supply contracts

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (Exportverbot, S0733/2025)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Voluntary termination immediately after proceedings were opened.
Published
17 Sep 2026

Original amount 17,268,000 CZK, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers SwedenOrganisational requirements €177,187

As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.

What organisations can take from it

Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.

Authority / court
Finansinspektionen (FI)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
No established damage to investors; remedial measures already taken during the investigation.
Published
16 Sep 2026

Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies EstoniaInternal controls Order

Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.

What organisations can take from it

Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance
Published
16 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker CzechiaOther €12,350

In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.

What organisations can take from it

External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.

Relevance to training and awareness

Conflicts of interest of external advisers in procurement procedures

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Other
Legal basis
Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Published
15 Sep 2026

Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection ItalyMarketing and consent €5.51m

For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).

What organisations can take from it

An objection to advertising must take effect immediately and reliably across all channels – including app messages.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record ItalyEmployee data €24,000

Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).

What organisations can take from it

Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.

Relevance to training and awareness

Purpose limitation when accessing patient records

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator ItalyVideo surveillance €8,000

Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.

What organisations can take from it

Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports MaltaMoney laundering and terrorist financing €97,622

The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.

What organisations can take from it

Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction
Published
4 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination MaltaCustomer due diligence €160,099

At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.

What organisations can take from it

A customer risk assessment belongs before business starts, not in a later remediation project.

Relevance to training and awareness

Risk-based customer profiles and source of funds

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction; remediation demonstrated
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 Flower bulb business failed to disclose hours of Polish seasonal workers – fine of around 95,600 EUR NetherlandsMinimum wage and undeclared work €95,588

A lily and tulip grower with an average of around 50 (at peak 75) employees, where Polish migrant workers are employed (anonymised in the judgment), was unable to produce sufficient records of hours worked and wages paid for 18 employees for September 2020 to February 2021. The Dutch Minister of Social Affairs and Employment (Minister van Sociale Zaken en Werkgelegenheid) imposed 118,000 EUR in 2024 (112,100 EUR after objection); the North Netherlands District Court (Rechtbank Noord-Nederland) reduced the fine to 95,587.50 EUR, partly because of measures taken and excessively long proceedings.

What organisations can take from it

Companies employing seasonal workers must be able to document hours and wage payments for each person without gaps – missing records are fined separately for each employee.

Authority / court
Rechtbank Noord-Nederland (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid / Nederlandse Arbeidsinspectie)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Art. 18b Abs. 2 Wet minimumloon en minimumvakantiebijslag (Wml)
Action
Fine
Status of proceedings
reduced
Sector
Food and agriculture
Employees
50 to 249
Mitigating circumstances
Reduction of 12.5 % for appropriate measures, 5 % for delay and 2,500 EUR for exceeding the reasonable length of proceedings.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking CzechiaCartels and collusion €11.7m

From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.

What organisations can take from it

Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.

Relevance to training and awareness

Coordination with cooperation partners on customers and tenders

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Published
26 Aug 2026

Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants DenmarkAbuse of market power Order

In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.

What organisations can take from it

Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
Competition law · Abuse of market power
Legal basis
Konkurrenceloven; AEUV Art. 102
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Published
26 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records IrelandData breaches and data security €645,000

In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.

What organisations can take from it

Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.

Relevance to training and awareness

Physical security and retention of paper records

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector
Employees
10,000 or more
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Elizabeta Promet d.o.o., SolinCroatia: 10,000 EUR against Elizabeta Promet for deliveries without a written contract CroatiaAbuse of market power €10,000

As a buyer with significant bargaining power, the company from Solin purchased agricultural and food products from two suppliers without written contracts. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) considered this an unfair trading practice and, taking mitigating circumstances into account, imposed 10,000 EUR (date = publication).

What organisations can take from it

In food purchasing, the mere absence of written supply contracts is an infringement – a simple contract standard prevents this.

Relevance to training and awareness

Written form for supply contracts in food purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Several mitigating circumstances taken into account
Published
25 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 WH Media GmbHKommAustria penalises person responsible for W24 over advertising in news programme AustriaMisleading advertising and pricing €500

On 29 May 2024, the Vienna broadcaster W24 aired advertising in split screen within the programme ‘24 Stunden Wien’, did not adequately separate advertising from programming and, at around 50 minutes, significantly exceeded the permitted 12 minutes of advertising per hour. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) imposed fines totalling 500 EUR (plus 50 EUR in costs) on the body authorised to represent the company externally; the GmbH is jointly and severally liable under § 9 (7) VStG (Austrian Administrative Penal Act).

What organisations can take from it

Advertising time limits and the separation requirement also apply to small regional broadcasters – management is personally liable via § 9 VStG.

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 64 Abs. 2 Z 9 i. V. m. §§ 43 Abs. 2, 44 Abs. 1, 45 Abs. 1 AMD-G; § 9 VStG
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous record, duration of proceedings, remorseful confession and remedial measures initiated.
Liability of senior managers
Fine imposed on the body responsible externally (§ 9 (1) VStG); the company is jointly and severally liable.
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect CzechiaCartels and collusion €11.5m

From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.

What organisations can take from it

Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.

Relevance to training and awareness

Coordination of terms and conditions among competitors

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Published
17 Aug 2026

Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2026 Dante International S.A.; Extreme Digital-eMAG Kft. (Betreiber des eMAG-Webshops)eMAG: further 225 million HUF for unfulfilled commitments HungaryConsumer protection and online retail €620,091

In 2021, the operators of the online retailer eMAG had committed to a support programme for Hungarian businesses, but once again implemented it only partially and not with the prescribed content. In the follow-up review, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 225 million HUF; in total, the operators have already received fines of 710 million HUF.

What organisations can take from it

Commitments made binding by an authority require dedicated implementation and evidence controlling – otherwise the next fine follows.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Consumer protection and online retail
Legal basis
Nachprüfungsverfahren zu verbindlichen Zusagen (VJ/6/2025)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Repeat case
yes
Mitigating circumstances
The companies acknowledged the failures and waived legal remedies.
Published
13 Aug 2026

Original amount 225,000,000 HUF, converted at the ECB reference rate of 13 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2026 „О-Рент“ ЕООД (sowie „Инжконсулт“ ЕООД und „Земекоп“ ЕООД)Construction machinery cartel: fine for O-Rent, compliance programme for all participants BulgariaCartels and collusion €2,403

The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found a cartel in public tenders for mining and construction machinery (price fixing and market sharing, Art. 15 ZZK – Bulgarian Protection of Competition Act, Art. 101 TFEU). Inzhkonsult and Zemekop, as a single undertaking, were exempted from the fine; O-Rent received a sanction of 2,403.07 EUR. All three companies must introduce a competition law compliance programme within 60 days and report on it.

What organisations can take from it

The authority now expressly requires compliance programmes – anyone bidding in tenders should have one before it is ordered.

Relevance to training and awareness

Competition law in tenders; compliance programme

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 15 Abs. 1 Nr. 1 und 2 ZZK; Art. 101 Abs. 1 lit. a und c AEUV
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Mitigating circumstances
Immunity from fines for two participants (leniency programme)
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2026 Hair-Line Kft.Hair-Line: 68.5 million HUF for price and territorial restrictions on hairdressing supplies HungaryCartels and collusion €187,929

In 2018–2022, the distributor of professional hairdressing products (Alfaparf, Yellow) determined the prices at which its territorial representatives were allowed to sell to salons and retailers and restricted passive sales outside the territories. Under a settlement and with a commitment to a compliance programme, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 68.5 million HUF.

What organisations can take from it

Commercial agent systems with territorial protection must not restrict resale prices or passive sales either.

Relevance to training and awareness

Price and territorial restrictions in the distribution system

Missing or inadequate training played a role in the decision.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Cartels and collusion
Legal basis
Ungarisches Wettbewerbsgesetz, Verbot wettbewerbsbeschränkender Vereinbarungen (VJ/17/2022)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Cooperation, acknowledgement in the settlement and commitment to a comprehensive compliance programme.
Published
7 Aug 2026

Original amount 68,500,000 HUF, converted at the ECB reference rate of 7 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AS Asphaltstraßensanierung GmbH, BITUNOVA GmbH, Kutter Spezialstraßenbau GmbH & Co. KG, Possehl Construction GmbH (inkl. VSI), Liesen…alles für den Bau GmbH, OAT GmbH/Otto Alte-Teigeler GmbHBundeskartellamt: 60.3 million EUR against DSK road repair cartel GermanyCartels and collusion €60.3m

From around 2010 to September 2019, six suppliers of thin cold-laid asphalt surface layers (Dünne Asphaltdeckschichten in Kaltbauweise, DSK) allocated customers – primarily public contracting authorities – and contracts among themselves nationwide and coordinated prices. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines of around 60.3 million EUR; all proceedings ended in settlements.

What organisations can take from it

Anyone who "shares out" public contracts regionally risks fines running into millions – calculations and bids must always be prepared independently.

Relevance to training and awareness

Customer allocation and bid rigging in public contracts

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB, Art. 101 AEUV
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Mitigating circumstances
Leniency bonus for Possehl/VSI, Bitunova, Kutter and AS; settlement
Published
6 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 „Чили Хилс Фудс“ ООД (Chili Hills Foods OOD)Chili Hills Foods: 20,022 EUR for false copying allegations against competitor BulgariaCompetition law €20,022

From May 2024, in social media videos (campaign ‘Създавай! Не копирай!’), the company falsely accused a competing family business for hot chillies of having stolen its business, ideas and concept, and promoted the clips partly through paid advertising. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) regarded this as unfair damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act), imposed 4% of 2025 net turnover (500,555 EUR), i.e. 20,022 EUR, and ordered immediate cessation. Appeals have been lodged against the decision.

What organisations can take from it

Allegations against competitors on social media are only permissible if based on verifiable facts – paid reach aggravates the sanction.

Relevance to training and awareness

Statements about competitors on social media

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
Action
Fine
Status of proceedings
under appeal
Sector
Food and agriculture
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 Capwatt Retail Gás PT, S.A.Portugal: 12,000 EUR against Capwatt over gas reserves and dispute resolution notice PortugalOther €12,000

In several months of 2023 and 2024, the gas supplier did not hold the natural gas security reserves and did not name the competent alternative dispute resolution bodies in customer contracts. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) accepted the settlement proposal, set a fine of 24,000 EUR and reduced it to 12,000 EUR.

What organisations can take from it

Mandatory information in consumer contracts – for example on dispute resolution – belongs in a regularly reviewed contract template.

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Other
Legal basis
RSSE, Art. 29; Decreto-Lei n.º 62/2020, Art. 57, 96; Portaria n.º 59/2022; RRC Art. 22
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Settlement with admission and remediation

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2026 AS "Latvijas valsts meži"7.86 million EUR against Latvijas valsts meži for breach of competitive neutrality LatviaCompetition law €7.86m

From 2020 to April 2026, on the basis of old long-term logging contracts, the state forestry group supplied six wood processors with guaranteed quantities of roundwood outside public auctions, while all others could only buy through auctions. In its first decision on the competitive neutrality of public undertakings, the Konkurences padome (Latvian Competition Council) imposed 7,859,606.89 EUR and required equal sales conditions for all qualified bidders.

What organisations can take from it

State-owned companies must allocate resources without discrimination – review historical special contracts regularly for competitive neutrality.

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law
Legal basis
Art. 14.1 Konkurences likums (Wettbewerbsneutralität)
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
13 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2026 Lime Technology S.r.l., EmTransit S.r.l. (Dott), Bird Rides Italy S.r.l.Rome: 2.675 million EUR against e-scooter and e-bike sharing providers over blocked free rides ItalyInformation duties in online retail €2.68m

The three sharing providers made it difficult for holders of a Metrebus annual pass to access the free-ride passes promised when the concessions were awarded, through inadequate organisation, cumbersome activation and long waiting times, which shortened the usable time; Bird also deactivated accounts without prior notice. The AGCM imposed fines totalling 2.675 million EUR in three proceedings (Lime 1.4 million, Dott 525,000, Bird 750,000 EUR).

What organisations can take from it

Promised benefits must also be redeemable in organisational terms – sluggish processing can itself be unfair.

Relevance to training and awareness

Customer service and redemption of promised services

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Codice del Consumo (pratiche commerciali scorrette), Verfahren PS13028, PS13029, PS13030
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
6 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 AvisAvis: maximum fine of 1 million EUR for handling fee on traffic fines SpainInformation duties in online retail €1m

The car rental company charged customers an "administration fee" of 33.88 to 45 EUR when a rental car incurred a traffic offence – even though naming the driver is a statutory obligation of the rental company. Spain's Ministry of Social Rights, Consumer Affairs and 2030 Agenda classified this as a very serious infringement and imposed the maximum fine of 1 million EUR; a court had already declared the clause void in 2020.

What organisations can take from it

No additional fee may be charged for fulfilling statutory obligations – least of all after a court has prohibited the clause.

Authority / court
Ministerio de Derechos Sociales, Consumo y Agenda 2030
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Artt. 82, 87.5 y 87.6 TRLGDCU (Real Decreto Legislativo 1/2007)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Repeat case
yes
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 Österreichischer Rundfunk (ORF)KommAustria finds unlabelled product placement in ORF's ‘Sport aktuell’ AustriaMisleading advertising and pricing Order

In the programme ‘Sport aktuell’ on ORF 1 on 29 July 2025, a logo wall was visible as product placement without being labelled. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) found, with final effect, a violation of the ORF Act (ORF-Gesetz).

What organisations can take from it

Product placements must be identified and labelled by the editorial team – including logo walls in the background.

Relevance to training and awareness

Labelling of advertising and product placement

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 16 Abs. 5 Z 4 ORF-G
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2026 TrenitaliaTrenitalia removes hurdles to refunds for delays following AGCM proceedings ItalyInformation duties in online retail Order

For refunds in the event of delays of 60 minutes or more or cancellations, Trenitalia required prior written confirmation from the call centre or ticket office. The AGCM accepted binding commitments: abolition of the confirmation requirement, strengthened refund channels, an information page on disruptions and an implementation report within three months; no infringement was found.

What organisations can take from it

Additional formalities before statutory refunds act as a hurdle and lead to proceedings.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Codice del Consumo (impegni); EU-Fahrgastrechte im Eisenbahnverkehr
Action
Order
Status of proceedings
final
Sector
Transport, logistics and shipping
Mitigating circumstances
Binding commitments, no finding of an infringement.
Published
30 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Maxxis International GmbH, Best4Tires Berlin GmbH, Reifen Müller GmbH & Co. KGBundeskartellamt: 11.9 million EUR over resale price maintenance in tyre distribution (Maxxis/CST) GermanyCartels and collusion €11.9m

Maxxis guaranteed wholesalers fixed margins per tyre sold of the Maxxis and CST brands, monitored prices in particular on the Tyre24 platform and intervened when prices were too low. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines totalling 11.9 million EUR on three companies and one responsible individual.

What organisations can take from it

Margin guarantees and price controls vis-à-vis dealers constitute prohibited resale price maintenance – sales teams need clear rules for price discussions.

Relevance to training and awareness

Influencing resale prices and price monitoring on platforms

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB (vertikale Preisbindung)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Settlement with Maxxis and Reifen Müller
Liability of senior managers
Fine imposed on one responsible natural person (not named)
Published
21 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products EU levelPlatform obligations €550m

AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.

What organisations can take from it

The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay GermanyDisclosure and reporting obligations €240,000

Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.

What organisations can take from it

Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.

Relevance to training and awareness

Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative GermanyInformation duties in online retail Order

On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.

What organisations can take from it

Keep retention or pause offers off the confirmation page of the online cancellation process.

Relevance to training and awareness

Design of the cancellation process (cancellation button, retention offers)

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
Action
Order
Status of proceedings
final
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2026 CalPlus GmbH, Elektronik-Kontor Messtechnik GmbH, TVW Meßtechnik GmbHBundeskartellamt: 453,000 EUR against distributors of test and measuring equipment GermanyCartels and collusion €453,000

From 2016 to 2022, three distributors of test and measuring equipment coordinated discounts as essential price components and informed each other of customer contacts, usually with a request for "restraint". This was evidenced by more than 400 emails; the proceedings ended in settlements.

What organisations can take from it

Small distributors are liable too: merely asking a competitor to "hold back" with a customer is a prohibited customer allocation agreement.

Relevance to training and awareness

Email contacts with competitors about customers and discounts

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Mitigating circumstances
Settlement; cooperation by Elektronik-Kontor Messtechnik taken into account
Published
15 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment MaltaCustomer due diligence €80,907

The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.

What organisations can take from it

Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.

Relevance to training and awareness

Risk-based customer assessment in gambling

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps GermanyCustomer due diligence €210,000

Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.

What organisations can take from it

Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.

Relevance to training and awareness

Ongoing monitoring of business relationships and suspicious activity reporting

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time GermanyDisclosure and reporting obligations €187,500

The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.

What organisations can take from it

Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.

Relevance to training and awareness

Threshold monitoring and notification deadlines for shareholdings

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 33 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
22 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles SloveniaEmployee data Order

The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.

What organisations can take from it

Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.

Relevance to training and awareness

Consent and proportionality in employee monitoring

Authority / court
Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
Area of law
Data protection · Employee data
Legal basis
Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
7 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR LatviaCookies and tracking €1,000

In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.

What organisations can take from it

Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.

Relevance to training and awareness

Cookie banners and cooperation with the supervisory authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR EU levelOrganisational requirements €2.15m

The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.

What organisations can take from it

Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR LithuaniaDisclosure and reporting obligations €362,000

Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.

What organisations can take from it

Running daily fines make every delay expensive – supervisory orders need top-management priority.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Published
30 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options BelgiumOrganisational requirements €1m

In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.

What organisations can take from it

Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Neonet S.A.Neonet: 3 million PLN over false delivery and availability information on Allegro PolandInformation duties in online retail €709,854

On its Allegro account, the electronics retailer promised dispatch within 24 hours even for goods not in stock and did not inform customers in good time of delays or unavailability. UOKiK imposed a fine of 3,043,000 PLN; the decision is not final.

What organisations can take from it

Link delivery and availability information to stock levels; in the event of delays, inform customers immediately.

Relevance to training and awareness

Availability and delivery information on marketplaces

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
26 Jun 2026

Original amount 3,043,000 PLN, converted at the ECB reference rate of 26 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition BulgariaCompetition law €52,097

On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.

What organisations can take from it

Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Published
2 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 TotalEnergiesParis Judicial Court: TotalEnergies must include Scope 3 emissions in vigilance plan FranceSupply chain due diligence Order

In an action brought by Notre Affaire à Tous, Sherpa, ZEA, France Nature Environnement and the City of Paris, the Paris Judicial Court (Tribunal judiciaire de Paris, 34th chamber) ruled that climate risks fall under the French duty of vigilance law and that Scope 3 emissions are part of the oil and gas group's activities. The vigilance plan without Scope 3 is incomplete, the court held; TotalEnergies must supplement it within six months, with provisional enforceability, and implementation will be reviewed by the court in January 2027.

What organisations can take from it

Risk analyses under due diligence laws must also cover the climate impact of the products sold (Scope 3).

Authority / court
Tribunal judiciaire de Paris (34. Kammer)
Area of law
Supply chain and human rights · Supply chain due diligence
Legal basis
Art. L.225-102-1 und L.225-102-2 Code de commerce (Loi n° 2017-399, devoir de vigilance); Art. 1252 Code civil
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Employees
10,000 or more
Published
25 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Kaufland Hrvatska k.d.Croatia: 300,000 EUR against Kaufland for unfair practices towards suppliers CroatiaAbuse of market power €300,000

The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) found that Kaufland Hrvatska charged food suppliers fees for services not provided and for advertising not commissioned, and paid for perishable goods only after more than 30 days. For these unfair trading practices, and with repeat offending as an aggravating factor (final penalty already in 2020), it imposed 300,000 EUR (date = publication).

What organisations can take from it

Purchasing departments must know the payment deadlines and fee prohibitions of UTP law – repeat offences become significantly more expensive.

Relevance to training and awareness

Fair terms towards suppliers in purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 4, 11, 12 Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Repeat case
yes
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked DenmarkPlatform obligations Order

After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.

What organisations can take from it

Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Deghi S.p.A.Deghi: 2 million EUR for endlessly renewing countdown discounts ItalyMisleading advertising and pricing €2m

From January 2024 to December 2025, the online retailer advertised time-limited discounts with countdown timers which, once they had expired, restarted with a new timer on identical terms. The AGCM classified this artificial scarcity as a particularly insidious dark pattern and imposed a fine of 2 million EUR.

What organisations can take from it

A countdown must genuinely expire – an automatically restarting timer creates misleading scarcity.

Relevance to training and awareness

False urgency and countdown timers in online marketing

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Codice del Consumo (pratiche commerciali scorrette)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
25 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 VARTA AGVARTA: late ad hoc announcement and missing half-yearly financial report GermanyDisclosure and reporting obligations €620,000

BaFin imposed fines on the battery manufacturer because it had not disclosed inside information without delay and had not published the half-yearly financial report for the 2024 financial year.

What organisations can take from it

Ad hoc assessments and periodic disclosure require fixed responsibilities and deadline controls so that neither inside information nor mandatory reports are left pending.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR; § 115 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Published
1 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies ItalyCustomer due diligence €40,000

Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.

What organisations can take from it

Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.

Relevance to training and awareness

Customer due diligence and suspicious transaction reports

Authority / court
Banca d'Italia
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Corrective measures initiated

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence SwedenCustomer due diligence €12.9m

For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.

What organisations can take from it

The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.

Relevance to training and awareness

Enhanced due diligence for high-risk customers

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Jun 2026

Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis SwedenVideo surveillance Reprimand or warning

The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.

What organisations can take from it

Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.

Relevance to training and awareness

Use of cameras in vehicles

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 6 Abs. 1
Action
Reprimand or warning
Status of proceedings
final
Sector
Defence and security
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit FinlandData subject rights and transparency €792,639

The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.

What organisations can take from it

Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.

Authority / court
Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
18 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage GreeceVideo surveillance €95,000

A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.

What organisations can take from it

Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.

Relevance to training and awareness

Handling video footage and access requests

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function GermanyData breaches and data security Fine

In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.

What organisations can take from it

Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.

Authority / court
Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5, Art. 25 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
Published
10 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report CyprusDisclosure and reporting obligations €16,500

The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.

What organisations can take from it

Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes
Published
7 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Portugal: 8.18 million EUR against three companies over advertising in TV recordings PortugalCartels and collusion €8.18m

With the support of a consultancy, the three largest pay-TV providers agreed from 2019 to May 2025 to introduce advertising as a condition for accessing recordings and to standardise the marketing of this advertising space. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,181,000 EUR on three companies; together with the fourth participant, already sanctioned earlier under a settlement, the fines add up to 13,351,000 EUR. Owing to ongoing court proceedings, the AdC did not publish the names in its announcement.

What organisations can take from it

Jointly coordinated ‘industry solutions’ at customers’ expense are cartels – even when a service provider takes on the coordination.

Relevance to training and awareness

Coordinated product changes among competitors

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º (Processo PRC/2020/4)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) GreeceData subject rights and transparency €110,000

Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.

What organisations can take from it

Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2026 VF Hellas Ενδυμάτων Ε.Π.Ε. (VF Hellas, Tochter der VF Corporation)Greece: 954,485 EUR against VF Hellas for banning price comparison and Google Ads GreeceCartels and collusion €954,485

The importer and wholesaler of the Vans, Eastpak and The North Face brands contractually prohibited its retailers from using price comparison portals and search engine advertising (in particular Google Ads). The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) regarded this as a hardcore restriction in online sales and, in a settlement procedure (Decision 913/2026), set a reduced fine of 954,485 EUR; date = press release.

What organisations can take from it

Prohibiting retailers from using price comparison sites or search engine advertising is a hardcore restriction – distribution agreements should regularly undergo competition law review.

Relevance to training and awareness

Competition-law-compliant design of dealer agreements in online sales

Authority / court
Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 1 Gesetz 3959/2011; Art. 101 AEUV; Art. 4 lit. e VO (EU) 2022/720
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Settlement procedure (Diettheti Diaforon) with fine reduction
Published
3 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products EU levelPlatform obligations €200m

Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.

What organisations can take from it

Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
28 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2026 Soltec Power Holdings, SASoltec: incorrect 2023 annual figures reported to the market SpainDisclosure and reporting obligations €190,000

The manufacturer of solar tracking systems disseminated its results for 2023 by way of an "Otra Información Relevante" announcement containing inaccurate information. Spain's National Securities Market Commission (CNMV) imposed a fine of 190,000 EUR for a serious infringement; the company waived administrative appeals.

What organisations can take from it

Voluntary market announcements on results are also subject to MAR – figures must be reconciled before publication.

Authority / court
Comisión Nacional del Mercado de Valores (CNMV)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 297.1.e i. V. m. 297.2.d Ley 6/2023; Art. 17 i. V. m. Art. 7 MAR
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters HungaryData protection €140,706

On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.

What organisations can take from it

Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.

Relevance to training and awareness

Handling leaked personal data in newsrooms

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection
Legal basis
DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
intentional
Published
26 May 2026

Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients CyprusOrganisational requirements €100,000

For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.

What organisations can take from it

When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.

Relevance to training and awareness

Appropriateness assessment when selling complex products

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Aug 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff ItalyData breaches and data security €1.72m

Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.

What organisations can take from it

Staff in branches and partner shops must verify alleged support calls before granting access.

Relevance to training and awareness

Social engineering / fake IT support

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO (Integrität und Vertraulichkeit, Art. 32)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists FinlandMarket abuse and insider dealing €400,000

The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.

What organisations can take from it

Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.

Relevance to training and awareness

Insider lists and handling of inside information

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
Published
15 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency BelgiumData subject rights and transparency €86,000

The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.

What organisations can take from it

Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.

Relevance to training and awareness

Recording of customer calls

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 May 2026 HP TRONIC Zlín, spol. s r.o.HP TRONIC Zlín: 39 million CZK for price requirements imposed on electronics retailers CzechiaCartels and collusion €1.6m

For more than ten years from 2012, the distributor and retailer of consumer electronics and household appliances set minimum resale prices for its retail customers, monitored them and sanctioned deviations. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 38.971 million CZK; a leniency application, settlement and an improved compliance programme reduced the fine, and the company appealed against the amount.

What organisations can take from it

Reprimanding retailers over low prices risks high fines – an effective compliance programme can reduce them but is no substitute for ending the practice.

Relevance to training and awareness

Resale price maintenance in sales

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0551/2023)
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Leniency application, settlement and expansion of the internal compliance programme.
Published
6 May 2026

Original amount 38,971,000 CZK, converted at the ECB reference rate of 6 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary BelgiumOrganisational requirements €150,000

One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.

What organisations can take from it

Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.

Relevance to training and awareness

Care in master data maintenance / register reconciliation

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 4 avril 2014 relative aux assurances, Art. 259
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
IT adjustments to prevent recurrence.
Published
5 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection MaltaMarketing and consent €1,000

Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.

What organisations can take from it

An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.

Relevance to training and awareness

Passing marketing objections on to service providers (suppression lists)

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Load 20 more of 302

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial