Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EU Clear all filters
382cases from 28 jurisdictions
€7.66bnTotal of monetary amounts (325 cases with an amount)
€890mLargest single case: Google
€250,000Median per case with an amount

Click a bar to drill down one level.

Where?

by country
  1. EU level €3.8bn 50 % · 20 cases
  2. Ireland €895m 12 % · 10 cases
  3. France €823.9m 11 % · 25 cases
  4. Spain €563.1m 7 % · 10 cases
  5. Netherlands €463.6m 6 % · 18 cases
  6. Italy €462.4m 6 % · 26 cases
  7. Germany €204.8m 3 % · 39 cases
  8. Slovakia €142.7m 2 % · 17 cases
  9. Austria €86m 1 % · 16 cases
  10. Czechia €52.2m 1 % · 9 cases
  11. 18 more€163.4m

What for?

by area of law

All areas of law

  1. Competition law €2.73bn 36 % · 82 cases
  2. AI and digital regulation €2.5bn 33 % · 16 cases
  3. Data protection €2bn 26 % · 136 cases
  4. Consumer protection and online retail €204.2m 3 % · 33 cases
  5. Bribery and corruption €102.8m 1 % · 8 cases
  6. Money laundering and terrorist financing €101.3m 1 % · 34 cases
  7. Capital markets and financial supervision €16.7m 0 % · 36 cases
  8. Environment and sustainability €1m 0 % · 6 cases
  9. Health and safety and employment law €953,069 0 % · 7 cases
  10. Information security and cyber €464,702 0 % · 8 cases
  11. 4 more€490,550

Who?

by sector

All sectors

  1. Media and online platforms €1.96bn 26 % · 31 cases
  2. Telecoms, IT and software €1.58bn 21 % · 36 cases
  3. Retail and e-commerce €1.37bn 18 % · 44 cases
  4. Transport, logistics and shipping €819.9m 11 % · 20 cases
  5. Automotive €547m 7 % · 11 cases
  6. Chemicals and pharmaceuticals €488m 6 % · 5 cases
  7. Energy and utilities €271.3m 4 % · 23 cases
  8. Financial services and insurance €144.9m 2 % · 83 cases
  9. Construction and real estate €126m 2 % · 21 cases
  10. Manufacturing and mechanical engineering €99.5m 1 % · 9 cases
  11. 6 more€244.3m

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 202314€26.5m
Q1 202415€92.2m
Q2 202410€54.9m
Q3 202414€821.6m
Q4 202438€878.1m
Q1 202526€82.6m
Q2 202540€2.12bn
Q3 202535€509.4m
Q4 202554€857.8m
Q1 202645€257.6m
Q2 202644€398.5m
Q3 202647€1.56bn

382 cases

23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering EU levelPlatform obligations €890m

In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.

What organisations can take from it

Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Published
23 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Sep 2026 Plaček Pet Products s.r.o.Plaček Pet Products: 36.4 million CZK for minimum prices on pet food CzechiaCartels and collusion €1.49m

From January 2013 to March 2022, the distributor of premium pet food and pet supplies imposed minimum resale prices on its retailers and threatened sanctions if they were undercut. In a settlement procedure, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 36.438 million CZK; the company ended the conduct after the inspection and introduced a compliance programme.

What organisations can take from it

Never enforce recommended retail prices with supply stops or sanctions – sales teams need clear rules on this.

Relevance to training and awareness

Price requirements imposed on retailers in sales

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Verbot vertikaler Preisbindung (tschechisches Wettbewerbsgesetz, Art. 101 AEUV)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Termination immediately after the inspection, information of customers about free pricing, full cooperation, settlement and newly introduced compliance programme.
Published
24 Sep 2026

Original amount 36,438,000 CZK, converted at the ECB reference rate of 24 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Sep 2026 Audax Renovables, S.A. – Sucursal em PortugalPortugal: 22,000 EUR against Audax Renovables over missing gas reserves and hotline PortugalOther €22,000

On a total of 249 days, the Portuguese branch of the energy supplier failed to hold the mandatory natural gas security reserves, did not correctly show network charges on invoices, did not publish, or published late, mandatory information and its quality report, and failed to meet the standards for hotline waiting times. In a settlement procedure, the Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) set a fine of 44,000 EUR and reduced it to 22,000 EUR.

What organisations can take from it

Security of supply and service obligations in the energy sector are sanctioned individually – a compliance calendar for reserves and reports helps.

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Other
Legal basis
Regime Sancionatório do Setor Energético (RSSE), Art. 28, 29; Decreto-Lei n.º 62/2020, Art. 96; RRC; RQS
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Settlement (transação) with full admission, remediation of all infringements

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Sep 2026 Lesy České republiky, s.p. (Lesy ČR)Lesy ČR: 17.3 million CZK for export ban on wood chips CzechiaCartels and collusion €710,383

From July 2021 to July 2024, the state forestry company contractually prohibited a customer from actively and passively exporting wood chips and logging residues and secured the ban with a right of termination. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) considered this a restriction of competition by object under Czech and EU law and imposed 17.268 million CZK (first instance, not final).

What organisations can take from it

State-owned companies are also subject to competition law – have export and resale bans in framework agreements legally reviewed before signing.

Relevance to training and awareness

Anticompetitive clauses in supply contracts

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (Exportverbot, S0733/2025)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Voluntary termination immediately after proceedings were opened.
Published
17 Sep 2026

Original amount 17,268,000 CZK, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers SwedenOrganisational requirements €177,187

As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.

What organisations can take from it

Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.

Authority / court
Finansinspektionen (FI)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
No established damage to investors; remedial measures already taken during the investigation.
Published
16 Sep 2026

Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies EstoniaInternal controls Order

Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.

What organisations can take from it

Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
Action
Order
Status of proceedings
unknown
Sector
Financial services and insurance
Published
16 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker CzechiaOther €12,350

In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.

What organisations can take from it

External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.

Relevance to training and awareness

Conflicts of interest of external advisers in procurement procedures

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Other
Legal basis
Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Published
15 Sep 2026

Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection ItalyMarketing and consent €5.51m

For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).

What organisations can take from it

An objection to advertising must take effect immediately and reliably across all channels – including app messages.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record ItalyEmployee data €24,000

Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).

What organisations can take from it

Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.

Relevance to training and awareness

Purpose limitation when accessing patient records

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator ItalyVideo surveillance €8,000

Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.

What organisations can take from it

Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports MaltaMoney laundering and terrorist financing €97,622

The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.

What organisations can take from it

Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction
Published
4 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination MaltaCustomer due diligence €160,099

At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.

What organisations can take from it

A customer risk assessment belongs before business starts, not in a later remediation project.

Relevance to training and awareness

Risk-based customer profiles and source of funds

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Settlement with 40% reduction; remediation demonstrated
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Aug 2026 Flower bulb business failed to disclose hours of Polish seasonal workers – fine of around 95,600 EUR NetherlandsMinimum wage and undeclared work €95,588

A lily and tulip grower with an average of around 50 (at peak 75) employees, where Polish migrant workers are employed (anonymised in the judgment), was unable to produce sufficient records of hours worked and wages paid for 18 employees for September 2020 to February 2021. The Dutch Minister of Social Affairs and Employment (Minister van Sociale Zaken en Werkgelegenheid) imposed 118,000 EUR in 2024 (112,100 EUR after objection); the North Netherlands District Court (Rechtbank Noord-Nederland) reduced the fine to 95,587.50 EUR, partly because of measures taken and excessively long proceedings.

What organisations can take from it

Companies employing seasonal workers must be able to document hours and wage payments for each person without gaps – missing records are fined separately for each employee.

Authority / court
Rechtbank Noord-Nederland (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid / Nederlandse Arbeidsinspectie)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Art. 18b Abs. 2 Wet minimumloon en minimumvakantiebijslag (Wml)
Action
Fine
Status of proceedings
reduced
Sector
Food and agriculture
Employees
50 to 249
Mitigating circumstances
Reduction of 12.5 % for appropriate measures, 5 % for delay and 2,500 EUR for exceeding the reasonable length of proceedings.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking CzechiaCartels and collusion €11.7m

From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.

What organisations can take from it

Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.

Relevance to training and awareness

Coordination with cooperation partners on customers and tenders

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
intentional
Published
26 Aug 2026

Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants DenmarkAbuse of market power Order

In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.

What organisations can take from it

Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
Competition law · Abuse of market power
Legal basis
Konkurrenceloven; AEUV Art. 102
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Published
26 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records IrelandData breaches and data security €645,000

In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.

What organisations can take from it

Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.

Relevance to training and awareness

Physical security and retention of paper records

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
Action
Fine
Status of proceedings
final
Sector
Public sector
Employees
10,000 or more
Published
2 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Elizabeta Promet d.o.o., SolinCroatia: 10,000 EUR against Elizabeta Promet for deliveries without a written contract CroatiaAbuse of market power €10,000

As a buyer with significant bargaining power, the company from Solin purchased agricultural and food products from two suppliers without written contracts. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) considered this an unfair trading practice and, taking mitigating circumstances into account, imposed 10,000 EUR (date = publication).

What organisations can take from it

In food purchasing, the mere absence of written supply contracts is an infringement – a simple contract standard prevents this.

Relevance to training and awareness

Written form for supply contracts in food purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Several mitigating circumstances taken into account
Published
25 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Aug 2026 WH Media GmbHKommAustria penalises person responsible for W24 over advertising in news programme AustriaMisleading advertising and pricing €500

On 29 May 2024, the Vienna broadcaster W24 aired advertising in split screen within the programme ‘24 Stunden Wien’, did not adequately separate advertising from programming and, at around 50 minutes, significantly exceeded the permitted 12 minutes of advertising per hour. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) imposed fines totalling 500 EUR (plus 50 EUR in costs) on the body authorised to represent the company externally; the GmbH is jointly and severally liable under § 9 (7) VStG (Austrian Administrative Penal Act).

What organisations can take from it

Advertising time limits and the separation requirement also apply to small regional broadcasters – management is personally liable via § 9 VStG.

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 64 Abs. 2 Z 9 i. V. m. §§ 43 Abs. 2, 44 Abs. 1, 45 Abs. 1 AMD-G; § 9 VStG
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
negligent
Mitigating circumstances
No previous record, duration of proceedings, remorseful confession and remedial measures initiated.
Liability of senior managers
Fine imposed on the body responsible externally (§ 9 (1) VStG); the company is jointly and severally liable.
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect CzechiaCartels and collusion €11.5m

From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.

What organisations can take from it

Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.

Relevance to training and awareness

Coordination of terms and conditions among competitors

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
intentional
Published
17 Aug 2026

Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2026 Dante International S.A.; Extreme Digital-eMAG Kft. (Betreiber des eMAG-Webshops)eMAG: further 225 million HUF for unfulfilled commitments HungaryConsumer protection and online retail €620,091

In 2021, the operators of the online retailer eMAG had committed to a support programme for Hungarian businesses, but once again implemented it only partially and not with the prescribed content. In the follow-up review, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 225 million HUF; in total, the operators have already received fines of 710 million HUF.

What organisations can take from it

Commitments made binding by an authority require dedicated implementation and evidence controlling – otherwise the next fine follows.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Consumer protection and online retail
Legal basis
Nachprüfungsverfahren zu verbindlichen Zusagen (VJ/6/2025)
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Repeat case
yes
Mitigating circumstances
The companies acknowledged the failures and waived legal remedies.
Published
13 Aug 2026

Original amount 225,000,000 HUF, converted at the ECB reference rate of 13 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Aug 2026 „О-Рент“ ЕООД (sowie „Инжконсулт“ ЕООД und „Земекоп“ ЕООД)Construction machinery cartel: fine for O-Rent, compliance programme for all participants BulgariaCartels and collusion €2,403

The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found a cartel in public tenders for mining and construction machinery (price fixing and market sharing, Art. 15 ZZK – Bulgarian Protection of Competition Act, Art. 101 TFEU). Inzhkonsult and Zemekop, as a single undertaking, were exempted from the fine; O-Rent received a sanction of 2,403.07 EUR. All three companies must introduce a competition law compliance programme within 60 days and report on it.

What organisations can take from it

The authority now expressly requires compliance programmes – anyone bidding in tenders should have one before it is ordered.

Relevance to training and awareness

Competition law in tenders; compliance programme

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 15 Abs. 1 Nr. 1 und 2 ZZK; Art. 101 Abs. 1 lit. a und c AEUV
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Mitigating circumstances
Immunity from fines for two participants (leniency programme)
Published
20 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2026 Hair-Line Kft.Hair-Line: 68.5 million HUF for price and territorial restrictions on hairdressing supplies HungaryCartels and collusion €187,929

In 2018–2022, the distributor of professional hairdressing products (Alfaparf, Yellow) determined the prices at which its territorial representatives were allowed to sell to salons and retailers and restricted passive sales outside the territories. Under a settlement and with a commitment to a compliance programme, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 68.5 million HUF.

What organisations can take from it

Commercial agent systems with territorial protection must not restrict resale prices or passive sales either.

Relevance to training and awareness

Price and territorial restrictions in the distribution system

Missing or inadequate training played a role in the decision.

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Cartels and collusion
Legal basis
Ungarisches Wettbewerbsgesetz, Verbot wettbewerbsbeschränkender Vereinbarungen (VJ/17/2022)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Cooperation, acknowledgement in the settlement and commitment to a comprehensive compliance programme.
Published
7 Aug 2026

Original amount 68,500,000 HUF, converted at the ECB reference rate of 7 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AS Asphaltstraßensanierung GmbH, BITUNOVA GmbH, Kutter Spezialstraßenbau GmbH & Co. KG, Possehl Construction GmbH (inkl. VSI), Liesen…alles für den Bau GmbH, OAT GmbH/Otto Alte-Teigeler GmbHBundeskartellamt: 60.3 million EUR against DSK road repair cartel GermanyCartels and collusion €60.3m

From around 2010 to September 2019, six suppliers of thin cold-laid asphalt surface layers (Dünne Asphaltdeckschichten in Kaltbauweise, DSK) allocated customers – primarily public contracting authorities – and contracts among themselves nationwide and coordinated prices. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines of around 60.3 million EUR; all proceedings ended in settlements.

What organisations can take from it

Anyone who "shares out" public contracts regionally risks fines running into millions – calculations and bids must always be prepared independently.

Relevance to training and awareness

Customer allocation and bid rigging in public contracts

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB, Art. 101 AEUV
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Mitigating circumstances
Leniency bonus for Possehl/VSI, Bitunova, Kutter and AS; settlement
Published
6 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 „Чили Хилс Фудс“ ООД (Chili Hills Foods OOD)Chili Hills Foods: 20,022 EUR for false copying allegations against competitor BulgariaCompetition law €20,022

From May 2024, in social media videos (campaign ‘Създавай! Не копирай!’), the company falsely accused a competing family business for hot chillies of having stolen its business, ideas and concept, and promoted the clips partly through paid advertising. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) regarded this as unfair damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act), imposed 4% of 2025 net turnover (500,555 EUR), i.e. 20,022 EUR, and ordered immediate cessation. Appeals have been lodged against the decision.

What organisations can take from it

Allegations against competitors on social media are only permissible if based on verifiable facts – paid reach aggravates the sanction.

Relevance to training and awareness

Statements about competitors on social media

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
Action
Fine
Status of proceedings
under appeal
Sector
Food and agriculture
Published
19 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 Capwatt Retail Gás PT, S.A.Portugal: 12,000 EUR against Capwatt over gas reserves and dispute resolution notice PortugalOther €12,000

In several months of 2023 and 2024, the gas supplier did not hold the natural gas security reserves and did not name the competent alternative dispute resolution bodies in customer contracts. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) accepted the settlement proposal, set a fine of 24,000 EUR and reduced it to 12,000 EUR.

What organisations can take from it

Mandatory information in consumer contracts – for example on dispute resolution – belongs in a regularly reviewed contract template.

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Other
Legal basis
RSSE, Art. 29; Decreto-Lei n.º 62/2020, Art. 57, 96; Portaria n.º 59/2022; RRC Art. 22
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Culpability
negligent
Mitigating circumstances
Settlement with admission and remediation

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2026 AS "Latvijas valsts meži"7.86 million EUR against Latvijas valsts meži for breach of competitive neutrality LatviaCompetition law €7.86m

From 2020 to April 2026, on the basis of old long-term logging contracts, the state forestry group supplied six wood processors with guaranteed quantities of roundwood outside public auctions, while all others could only buy through auctions. In its first decision on the competitive neutrality of public undertakings, the Konkurences padome (Latvian Competition Council) imposed 7,859,606.89 EUR and required equal sales conditions for all qualified bidders.

What organisations can take from it

State-owned companies must allocate resources without discrimination – review historical special contracts regularly for competitive neutrality.

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law
Legal basis
Art. 14.1 Konkurences likums (Wettbewerbsneutralität)
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
13 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Aug 2026 Lime Technology S.r.l., EmTransit S.r.l. (Dott), Bird Rides Italy S.r.l.Rome: 2.675 million EUR against e-scooter and e-bike sharing providers over blocked free rides ItalyInformation duties in online retail €2.68m

The three sharing providers made it difficult for holders of a Metrebus annual pass to access the free-ride passes promised when the concessions were awarded, through inadequate organisation, cumbersome activation and long waiting times, which shortened the usable time; Bird also deactivated accounts without prior notice. The AGCM imposed fines totalling 2.675 million EUR in three proceedings (Lime 1.4 million, Dott 525,000, Bird 750,000 EUR).

What organisations can take from it

Promised benefits must also be redeemable in organisational terms – sluggish processing can itself be unfair.

Relevance to training and awareness

Customer service and redemption of promised services

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Codice del Consumo (pratiche commerciali scorrette), Verfahren PS13028, PS13029, PS13030
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
6 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 AvisAvis: maximum fine of 1 million EUR for handling fee on traffic fines SpainInformation duties in online retail €1m

The car rental company charged customers an "administration fee" of 33.88 to 45 EUR when a rental car incurred a traffic offence – even though naming the driver is a statutory obligation of the rental company. Spain's Ministry of Social Rights, Consumer Affairs and 2030 Agenda classified this as a very serious infringement and imposed the maximum fine of 1 million EUR; a court had already declared the clause void in 2020.

What organisations can take from it

No additional fee may be charged for fulfilling statutory obligations – least of all after a court has prohibited the clause.

Authority / court
Ministerio de Derechos Sociales, Consumo y Agenda 2030
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Artt. 82, 87.5 y 87.6 TRLGDCU (Real Decreto Legislativo 1/2007)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Repeat case
yes
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jul 2026 Österreichischer Rundfunk (ORF)KommAustria finds unlabelled product placement in ORF's ‘Sport aktuell’ AustriaMisleading advertising and pricing Order

In the programme ‘Sport aktuell’ on ORF 1 on 29 July 2025, a logo wall was visible as product placement without being labelled. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) found, with final effect, a violation of the ORF Act (ORF-Gesetz).

What organisations can take from it

Product placements must be identified and labelled by the editorial team – including logo walls in the background.

Relevance to training and awareness

Labelling of advertising and product placement

Authority / court
Kommunikationsbehörde Austria (KommAustria)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 16 Abs. 5 Z 4 ORF-G
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Published
29 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2026 TrenitaliaTrenitalia removes hurdles to refunds for delays following AGCM proceedings ItalyInformation duties in online retail Order

For refunds in the event of delays of 60 minutes or more or cancellations, Trenitalia required prior written confirmation from the call centre or ticket office. The AGCM accepted binding commitments: abolition of the confirmation requirement, strengthened refund channels, an information page on disruptions and an implementation report within three months; no infringement was found.

What organisations can take from it

Additional formalities before statutory refunds act as a hurdle and lead to proceedings.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Codice del Consumo (impegni); EU-Fahrgastrechte im Eisenbahnverkehr
Action
Order
Status of proceedings
final
Sector
Transport, logistics and shipping
Mitigating circumstances
Binding commitments, no finding of an infringement.
Published
30 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Maxxis International GmbH, Best4Tires Berlin GmbH, Reifen Müller GmbH & Co. KGBundeskartellamt: 11.9 million EUR over resale price maintenance in tyre distribution (Maxxis/CST) GermanyCartels and collusion €11.9m

Maxxis guaranteed wholesalers fixed margins per tyre sold of the Maxxis and CST brands, monitored prices in particular on the Tyre24 platform and intervened when prices were too low. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines totalling 11.9 million EUR on three companies and one responsible individual.

What organisations can take from it

Margin guarantees and price controls vis-à-vis dealers constitute prohibited resale price maintenance – sales teams need clear rules for price discussions.

Relevance to training and awareness

Influencing resale prices and price monitoring on platforms

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB (vertikale Preisbindung)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Settlement with Maxxis and Reifen Müller
Liability of senior managers
Fine imposed on one responsible natural person (not named)
Published
21 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products EU levelPlatform obligations €550m

AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.

What organisations can take from it

The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay GermanyDisclosure and reporting obligations €240,000

Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.

What organisations can take from it

Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.

Relevance to training and awareness

Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative GermanyInformation duties in online retail Order

On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.

What organisations can take from it

Keep retention or pause offers off the confirmation page of the online cancellation process.

Relevance to training and awareness

Design of the cancellation process (cancellation button, retention offers)

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
§ 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
Action
Order
Status of proceedings
final
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jul 2026 CalPlus GmbH, Elektronik-Kontor Messtechnik GmbH, TVW Meßtechnik GmbHBundeskartellamt: 453,000 EUR against distributors of test and measuring equipment GermanyCartels and collusion €453,000

From 2016 to 2022, three distributors of test and measuring equipment coordinated discounts as essential price components and informed each other of customer contacts, usually with a request for "restraint". This was evidenced by more than 400 emails; the proceedings ended in settlements.

What organisations can take from it

Small distributors are liable too: merely asking a competitor to "hold back" with a customer is a prohibited customer allocation agreement.

Relevance to training and awareness

Email contacts with competitors about customers and discounts

Authority / court
Bundeskartellamt
Area of law
Competition law · Cartels and collusion
Legal basis
§ 1 GWB
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Mitigating circumstances
Settlement; cooperation by Elektronik-Kontor Messtechnik taken into account
Published
15 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment MaltaCustomer due diligence €80,907

The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.

What organisations can take from it

Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.

Relevance to training and awareness

Risk-based customer assessment in gambling

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps GermanyCustomer due diligence €210,000

Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.

What organisations can take from it

Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.

Relevance to training and awareness

Ongoing monitoring of business relationships and suspicious activity reporting

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time GermanyDisclosure and reporting obligations €187,500

The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.

What organisations can take from it

Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.

Relevance to training and awareness

Threshold monitoring and notification deadlines for shareholdings

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 33 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
22 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles SloveniaEmployee data Order

The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.

What organisations can take from it

Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.

Relevance to training and awareness

Consent and proportionality in employee monitoring

Authority / court
Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
Area of law
Data protection · Employee data
Legal basis
Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
7 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR LatviaCookies and tracking €1,000

In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.

What organisations can take from it

Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.

Relevance to training and awareness

Cookie banners and cooperation with the supervisory authority

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
intentional
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR EU levelOrganisational requirements €2.15m

The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.

What organisations can take from it

Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR LithuaniaDisclosure and reporting obligations €362,000

Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.

What organisations can take from it

Running daily fines make every delay expensive – supervisory orders need top-management priority.

Authority / court
Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Published
30 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options BelgiumOrganisational requirements €1m

In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.

What organisations can take from it

Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
Published
26 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jun 2026 Neonet S.A.Neonet: 3 million PLN over false delivery and availability information on Allegro PolandInformation duties in online retail €709,854

On its Allegro account, the electronics retailer promised dispatch within 24 hours even for goods not in stock and did not inform customers in good time of delays or unavailability. UOKiK imposed a fine of 3,043,000 PLN; the decision is not final.

What organisations can take from it

Link delivery and availability information to stock levels; in the event of delays, inform customers immediately.

Relevance to training and awareness

Availability and delivery information on marketplaces

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
26 Jun 2026

Original amount 3,043,000 PLN, converted at the ECB reference rate of 26 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition BulgariaCompetition law €52,097

On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.

What organisations can take from it

Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Published
2 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 TotalEnergiesParis Judicial Court: TotalEnergies must include Scope 3 emissions in vigilance plan FranceSupply chain due diligence Order

In an action brought by Notre Affaire à Tous, Sherpa, ZEA, France Nature Environnement and the City of Paris, the Paris Judicial Court (Tribunal judiciaire de Paris, 34th chamber) ruled that climate risks fall under the French duty of vigilance law and that Scope 3 emissions are part of the oil and gas group's activities. The vigilance plan without Scope 3 is incomplete, the court held; TotalEnergies must supplement it within six months, with provisional enforceability, and implementation will be reviewed by the court in January 2027.

What organisations can take from it

Risk analyses under due diligence laws must also cover the climate impact of the products sold (Scope 3).

Authority / court
Tribunal judiciaire de Paris (34. Kammer)
Area of law
Supply chain and human rights · Supply chain due diligence
Legal basis
Art. L.225-102-1 und L.225-102-2 Code de commerce (Loi n° 2017-399, devoir de vigilance); Art. 1252 Code civil
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Employees
10,000 or more
Published
25 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR AustriaMarketing and consent €13m

The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).

What organisations can take from it

Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.

Authority / court
Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
Action
Fine
Status of proceedings
reduced
Sector
Other
Culpability
negligent
Mitigating circumstances
Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Kaufland Hrvatska k.d.Croatia: 300,000 EUR against Kaufland for unfair practices towards suppliers CroatiaAbuse of market power €300,000

The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) found that Kaufland Hrvatska charged food suppliers fees for services not provided and for advertising not commissioned, and paid for perishable goods only after more than 30 days. For these unfair trading practices, and with repeat offending as an aggravating factor (final penalty already in 2020), it imposed 300,000 EUR (date = publication).

What organisations can take from it

Purchasing departments must know the payment deadlines and fee prohibitions of UTP law – repeat offences become significantly more expensive.

Relevance to training and awareness

Fair terms towards suppliers in purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 4, 11, 12 Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Repeat case
yes
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked DenmarkPlatform obligations Order

After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.

What organisations can take from it

Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Deghi S.p.A.Deghi: 2 million EUR for endlessly renewing countdown discounts ItalyMisleading advertising and pricing €2m

From January 2024 to December 2025, the online retailer advertised time-limited discounts with countdown timers which, once they had expired, restarted with a new timer on identical terms. The AGCM classified this artificial scarcity as a particularly insidious dark pattern and imposed a fine of 2 million EUR.

What organisations can take from it

A countdown must genuinely expire – an automatically restarting timer creates misleading scarcity.

Relevance to training and awareness

False urgency and countdown timers in online marketing

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Codice del Consumo (pratiche commerciali scorrette)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
25 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 VARTA AGVARTA: late ad hoc announcement and missing half-yearly financial report GermanyDisclosure and reporting obligations €620,000

BaFin imposed fines on the battery manufacturer because it had not disclosed inside information without delay and had not published the half-yearly financial report for the 2024 financial year.

What organisations can take from it

Ad hoc assessments and periodic disclosure require fixed responsibilities and deadline controls so that neither inside information nor mandatory reports are left pending.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR; § 115 Abs. 1 Satz 1 WpHG
Action
Fine
Status of proceedings
final
Sector
Manufacturing and mechanical engineering
Published
1 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies ItalyCustomer due diligence €40,000

Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.

What organisations can take from it

Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.

Relevance to training and awareness

Customer due diligence and suspicious transaction reports

Authority / court
Banca d'Italia
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Corrective measures initiated

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence SwedenCustomer due diligence €12.9m

For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.

What organisations can take from it

The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.

Relevance to training and awareness

Enhanced due diligence for high-risk customers

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Jun 2026

Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis SwedenVideo surveillance Reprimand or warning

The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.

What organisations can take from it

Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.

Relevance to training and awareness

Use of cameras in vehicles

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 6 Abs. 1
Action
Reprimand or warning
Status of proceedings
final
Sector
Defence and security
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit FinlandData subject rights and transparency €792,639

The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.

What organisations can take from it

Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.

Authority / court
Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. e DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Retail and e-commerce
Published
18 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage GreeceVideo surveillance €95,000

A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.

What organisations can take from it

Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.

Relevance to training and awareness

Handling video footage and access requests

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Video surveillance
Legal basis
Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function GermanyData breaches and data security Fine

In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.

What organisations can take from it

Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.

Authority / court
Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5, Art. 25 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Liability of senior managers
According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
Published
10 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report CyprusDisclosure and reporting obligations €16,500

The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.

What organisations can take from it

Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes
Published
7 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Portugal: 8.18 million EUR against three companies over advertising in TV recordings PortugalCartels and collusion €8.18m

With the support of a consultancy, the three largest pay-TV providers agreed from 2019 to May 2025 to introduce advertising as a condition for accessing recordings and to standardise the marketing of this advertising space. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,181,000 EUR on three companies; together with the fourth participant, already sanctioned earlier under a settlement, the fines add up to 13,351,000 EUR. Owing to ongoing court proceedings, the AdC did not publish the names in its announcement.

What organisations can take from it

Jointly coordinated ‘industry solutions’ at customers’ expense are cartels – even when a service provider takes on the coordination.

Relevance to training and awareness

Coordinated product changes among competitors

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º (Processo PRC/2020/4)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) GreeceData subject rights and transparency €110,000

Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.

What organisations can take from it

Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Jun 2026 VF Hellas Ενδυμάτων Ε.Π.Ε. (VF Hellas, Tochter der VF Corporation)Greece: 954,485 EUR against VF Hellas for banning price comparison and Google Ads GreeceCartels and collusion €954,485

The importer and wholesaler of the Vans, Eastpak and The North Face brands contractually prohibited its retailers from using price comparison portals and search engine advertising (in particular Google Ads). The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) regarded this as a hardcore restriction in online sales and, in a settlement procedure (Decision 913/2026), set a reduced fine of 954,485 EUR; date = press release.

What organisations can take from it

Prohibiting retailers from using price comparison sites or search engine advertising is a hardcore restriction – distribution agreements should regularly undergo competition law review.

Relevance to training and awareness

Competition-law-compliant design of dealer agreements in online sales

Authority / court
Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 1 Gesetz 3959/2011; Art. 101 AEUV; Art. 4 lit. e VO (EU) 2022/720
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Settlement procedure (Diettheti Diaforon) with fine reduction
Published
3 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products EU levelPlatform obligations €200m

Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.

What organisations can take from it

Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
28 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2026 Soltec Power Holdings, SASoltec: incorrect 2023 annual figures reported to the market SpainDisclosure and reporting obligations €190,000

The manufacturer of solar tracking systems disseminated its results for 2023 by way of an "Otra Información Relevante" announcement containing inaccurate information. Spain's National Securities Market Commission (CNMV) imposed a fine of 190,000 EUR for a serious infringement; the company waived administrative appeals.

What organisations can take from it

Voluntary market announcements on results are also subject to MAR – figures must be reconciled before publication.

Authority / court
Comisión Nacional del Mercado de Valores (CNMV)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 297.1.e i. V. m. 297.2.d Ley 6/2023; Art. 17 i. V. m. Art. 7 MAR
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
3 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters HungaryData protection €140,706

On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.

What organisations can take from it

Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.

Relevance to training and awareness

Handling leaked personal data in newsrooms

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection
Legal basis
DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Culpability
intentional
Published
26 May 2026

Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients CyprusOrganisational requirements €100,000

For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.

What organisations can take from it

When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.

Relevance to training and awareness

Appropriateness assessment when selling complex products

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Aug 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff ItalyData breaches and data security €1.72m

Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.

What organisations can take from it

Staff in branches and partner shops must verify alleged support calls before granting access.

Relevance to training and awareness

Social engineering / fake IT support

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO (Integrität und Vertraulichkeit, Art. 32)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
16 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists FinlandMarket abuse and insider dealing €400,000

The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.

What organisations can take from it

Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.

Relevance to training and awareness

Insider lists and handling of inside information

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
Published
15 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency BelgiumData subject rights and transparency €86,000

The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.

What organisations can take from it

Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.

Relevance to training and awareness

Recording of customer calls

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
Action
Fine
Status of proceedings
under appeal
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls IrelandData breaches and data security €277,500

Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).

What organisations can take from it

Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.

Relevance to training and awareness

Identity verification by telephone (vishing)

Authority / court
Data Protection Commission (DPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
8 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 May 2026 HP TRONIC Zlín, spol. s r.o.HP TRONIC Zlín: 39 million CZK for price requirements imposed on electronics retailers CzechiaCartels and collusion €1.6m

For more than ten years from 2012, the distributor and retailer of consumer electronics and household appliances set minimum resale prices for its retail customers, monitored them and sanctioned deviations. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 38.971 million CZK; a leniency application, settlement and an improved compliance programme reduced the fine, and the company appealed against the amount.

What organisations can take from it

Reprimanding retailers over low prices risks high fines – an effective compliance programme can reduce them but is no substitute for ending the practice.

Relevance to training and awareness

Resale price maintenance in sales

Missing or inadequate training played a role in the decision.

Authority / court
Úřad pro ochranu hospodářské soutěže (ÚOHS)
Area of law
Competition law · Cartels and collusion
Legal basis
Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0551/2023)
Action
Fine
Status of proceedings
under appeal
Sector
Retail and e-commerce
Culpability
intentional
Mitigating circumstances
Leniency application, settlement and expansion of the internal compliance programme.
Published
6 May 2026

Original amount 38,971,000 CZK, converted at the ECB reference rate of 6 May 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary BelgiumOrganisational requirements €150,000

One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.

What organisations can take from it

Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.

Relevance to training and awareness

Care in master data maintenance / register reconciliation

Authority / court
Autorité des services et marchés financiers (FSMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Loi du 4 avril 2014 relative aux assurances, Art. 259
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes
Mitigating circumstances
IT adjustments to prevent recurrence.
Published
5 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection MaltaMarketing and consent €1,000

Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.

What organisations can take from it

An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.

Relevance to training and awareness

Passing marketing objections on to service providers (suppression lists)

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
yes
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late GermanyData processors Reprimand or warning

A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.

What organisations can take from it

Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.

Relevance to training and awareness

Reporting process for data breaches and management of service providers

Authority / court
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Area of law
Data protection · Data processors
Legal basis
Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Mitigating circumstances
BVG has announced measures against similar incidents.
Published
4 May 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Apr 2026 „Вазовски машиностроителни заводи“ ЕАД (VMZ)Arms manufacturer VMZ used a partner’s know-how for disposable grenade launchers – 50,855 EUR BulgariaCompetition law €50,855

On application by the client Armar, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that VMZ had used technical documentation on disposable grenade launchers that had been provided in confidence (trade secret) contrary to the confidentiality agreements and good commercial practice (Art. 37(1) ZZK – Bulgarian Protection of Competition Act). Sanction of 50,855.09 EUR and obligation to cease, with immediate enforceability. Appeals have been lodged against the decision.

What organisations can take from it

Design documents provided in confidence may only be used within the agreed scope – especially in sensitive industries.

Relevance to training and awareness

Handling confidential know-how of business partners

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 37 Abs. 1 ZZK (Geschäftsgeheimnisse)
Action
Fine
Status of proceedings
under appeal
Sector
Defence and security

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Apr 2026 Amica Chips S.p.A., Pata S.p.A., Preziosi Food S.p.A.Italy: 23.3 million EUR against Amica Chips, Pata and Preziosi Food over snack cartel ItalyCartels and collusion €23.3m

In a secret, continuing agreement, three manufacturers of salty snacks and crisps divided up among themselves the supply of private-label snacks to food retailers. Fines: Amica Chips 8,239,210 EUR, Pata 7,555,387 EUR, Preziosi Food 7,503,550 EUR; this was the first time Italy's competition authority (Autorità Garante della Concorrenza e del Mercato, AGCM) applied its settlement procedure.

What organisations can take from it

Retailers' tenders for private labels are competition – coordinated sham bids to retailers constitute a cartel.

Relevance to training and awareness

Sham bids in retailers' private-label tenders

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV; Art. 14-quater Gesetz 287/1990 (Settlement)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Leniency reduction for Pata and Amica Chips; 10 % settlement discount for all
Published
28 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratóriíLaboratory cartel: 14.6 million EUR and procurement bans against diagnostic laboratories SlovakiaCartels and collusion €14.6m

Four laboratories and their association coordinated negotiations on prices with health insurers, coordinated in tenders, exchanged sensitive information and allocated customers. At first instance, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 14,551,800 EUR and three-year procurement bans; Unilabs received a substantially reduced fine as leniency applicant and under a settlement.

What organisations can take from it

Common negotiating positions towards payers via an association are a cartel – association meetings need minutes and a review of the agenda.

Relevance to training and awareness

Information exchange among competitors and association work

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Unilabs: leniency reduction (50%) and settlement (a further 30%).
Published
12 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Synadis Bio, Greenweez (mit Carrefour SA), ITM Entreprises (mit Les Mousquetaires), Les Comptoirs de la BioFrance: 12.67 million EUR over allocation of distribution channels for organic food FranceCartels and collusion €12.7m

Through the association Synadis Bio, market participants ensured for more than seven years that organic brands were not sold simultaneously in specialist organic shops and in conventional supermarkets, in order to prevent price comparisons (decision 26-D-05). Fines: Synadis Bio 10 million EUR, Greenweez/Carrefour 1.85 million EUR, ITM 740,000 EUR, Les Comptoirs de la Bio 80,000 EUR.

What organisations can take from it

Association decisions that tie members to particular distribution channels amount to market sharing – even if they are justified as a quality or positioning policy.

Relevance to training and awareness

Association rules to foreclose distribution channels

Authority / court
Autorité de la concurrence
Area of law
Competition law · Cartels and collusion
Legal basis
Art. L.420-1 Code de commerce, Art. 101 Abs. 1 AEUV; Bußgeldbemessung nach Art. L.464-2 Code de commerce
Action
Fine
Status of proceedings
under appeal
Sector
Food and agriculture
Published
16 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment EstoniaData processors Order

The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.

What organisations can take from it

Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.

Relevance to training and awareness

Consent and transparency for health data; cooperation with the supervisory authority

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data processors
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles SloveniaEmployee data €6,000

A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.

What organisations can take from it

GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.

Relevance to training and awareness

GPS tracking and employee data protection

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Liability of senior managers
Additional fine of 600 EUR on the responsible person.
Published
15 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years DenmarkData protection Fine

The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.

What organisations can take from it

‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware SloveniaEmployee data €71,474

An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.

What organisations can take from it

Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.

Relevance to training and awareness

Permissible monitoring of employees and IT use

Authority / court
Informacijski pooblaščenec Republike Slovenije (IP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 und Art. 6 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional
Liability of senior managers
Additional fine of 4,000 EUR on the responsible person.
Published
9 Apr 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified PolandIncident reporting obligations €1,135

Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.

What organisations can take from it

Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.

Relevance to training and awareness

Recognising misdirected mail as a data breach – including at service providers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Construction and real estate

Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia NetherlandsInternational data transfers €100m

Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.

What organisations can take from it

Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR RomaniaData processors €125,083

In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).

What organisations can take from it

Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data processors
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
25 Mar 2026

Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions FinlandDisclosure and reporting obligations €70,000

Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.

What organisations can take from it

Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.

Relevance to training and awareness

Regulatory reporting

Authority / court
Finanssivalvonta (FIN-FSA)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Admission of the failures / cooperation.
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR LatviaData subject rights and transparency €1,500

A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.

What organisations can take from it

Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.

Relevance to training and awareness

Handling data subject requests and correspondence from authorities

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops MaltaCustomer due diligence €225,730

Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.

What organisations can take from it

Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.

Relevance to training and awareness

Recognising structured deposits below the checking threshold

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
Action
Fine
Status of proceedings
under appeal
Sector
Other
Published
16 Apr 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis HungaryData subject rights and transparency €1,274

A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.

What organisations can take from it

Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.

Relevance to training and awareness

Access to health data and access requests

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
20 Mar 2026

Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Colas Rail Asia Sdn Bhd (Colas-Gruppe)Colas Rail Asia: CJIP of 29.7 million EUR over bribery in metro contracts in Malaysia FranceBribery of public officials €29.7m

The Malaysian subsidiary of Colas Rail paid large, undocumented sums via intermediaries in connection with public contracts for urban rail lines in Kuala Lumpur (Kelana Jaya extension, MRT2). Following an internal investigation, Colas Rail self-reported the matter in 2017; the CJIP (Convention judiciaire d'intérêt public, a French deferred prosecution agreement) provides for a public interest fine of 29,745,974 EUR and a three-year compliance programme monitored by the French Anti-Corruption Agency (AFA) (costs of up to 1.9 million EUR).

What organisations can take from it

Undocumented payments to intermediaries on foreign projects must be stopped early by the finance and compliance functions – self-reporting after an internal investigation is rewarded.

Relevance to training and awareness

Intermediaries and consultants in public tenders

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Employees
10,000 or more
Culpability
intentional
Mitigating circumstances
Self-report (criminal complaint filed by Colas Rail on 31 May 2017) following an internal forensic investigation.
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician FranceBribery of public officials €1.77m

In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.

What organisations can take from it

Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.

Relevance to training and awareness

Benefits to hospital physicians, integration of acquired companies

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
250 to 999
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Mar 2026 Trustpilot Group Plc, Trustpilot A/S, Trustpilot S.r.l.Trustpilot: 4 million EUR fine for inadequate verification of the authenticity of reviews ItalyFake reviews €4m

According to the AGCM, the review platform did not adequately check whether reviews – including those labelled as "verified" – were genuine, and allowed companies to invite specifically selected customers to leave reviews via paid services, which undermined the representativeness of the star ratings. In addition, information on how the platform works and on paid services was lacking; the authority also saw dark pattern elements in this.

What organisations can take from it

Anyone who advertises with verified reviews must actually carry out the verification and disclose the selective collection of reviews.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Consumer protection and online retail · Fake reviews
Legal basis
Artt. 20, 21, 22 e 23, comma 1, lett. bb-ter Codice del Consumo
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
23 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule PortugalCartels and collusion €4.52m

From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).

What organisations can take from it

An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.

Relevance to training and awareness

No-poach agreements in association rules

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
12 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements LuxembourgMarketing and consent overturned

In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.

What organisations can take from it

Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.

Authority / court
Cour administrative (Luxemburg); Verfahren der CNPD
Area of law
Data protection · Marketing and consent
Legal basis
Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
Action
Order
Status of proceedings
overturned
Sector
Retail and e-commerce
Employees
10,000 or more
Mitigating circumstances
Amazon had implemented the compliance order before the hearing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2026 Fleurette Properties LtdCommodities holding Fleurette: 25.8 million EUR strafbeschikking over bribery in Congo NetherlandsBribery of public officials €25.8m

According to the Dutch Public Prosecution Service (OM), the top holding company of a mining, oil and gold group, which was based in the Netherlands from 2010 to 2017, participated together with others in bribing public officials of the DR Congo in order to obtain licences for cobalt and copper mines. On 6 March 2026, the OM issued a strafbeschikking (prosecutorial penalty order) imposing a fine of 25.8 million EUR, which Fleurette accepted.

What organisations can take from it

In the commodities sector, licences and concessions are the main target for bribery – holding companies share liability for payments made by their subsidiaries.

Relevance to training and awareness

Award of licences in the commodities sector, payments to public officials

Authority / court
Openbaar Ministerie (OM); Ermittlungen FIOD Anti-Corruptie Centrum
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Buitenlandse ambtelijke omkoping (Wetboek van Strafrecht); OM-strafbeschikking
Action
Fine
Status of proceedings
final
Sector
Steel and metals
Culpability
intentional
Published
10 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2026 ΚΟΜΠΑ Μονοπρόσωπη Ε.Π.Ε. und HAPPY DOG Α.Ε. ΖωοτροφώνGreece: around 482,500 EUR against pet food importers for resale price maintenance GreeceCartels and collusion €482,498

Two importers of dog and cat food monitored their retailers’ consumer prices on price comparison portals and asked them to adjust them to their price lists; the retailers complied. In a settlement procedure (Decision 901/2026), the Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) imposed 387,498 EUR on KOMPA and 95,000 EUR on Happy Dog; the case began with a tip-off via the authority’s anonymous whistleblowing platform.

What organisations can take from it

Recommended prices must not be enforced through monitoring and calls to retailers – and authorities’ whistleblowing channels make such practices visible.

Relevance to training and awareness

Prohibition of resale price maintenance in sales

Authority / court
Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 1 Gesetz 3959/2011; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
Settlement procedure with reduced fines
Published
6 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 SIA "SS"Classifieds portal ss.lv blocked users of competitor – fine of 186,781 EUR LatviaAbuse of market power €186,781

From March 2020 to May 2021, the operator of ss.lv/ss.com (market share over 60%) deleted advertisements and blocked accounts of users – mainly car dealers and estate agents – who also advertised on the competing platform pp.lv; anyone wishing to register with an inbox.lv address additionally had to provide a different e-mail address. The Konkurences padome (Latvian Competition Council) considered this an abuse of a dominant position (Art. 102 TFEU), imposed 186,780.65 EUR and required objective criteria for dealing with customers.

What organisations can take from it

Market-leading platforms must not punish users for multi-homing – internal moderation rules need objective criteria.

Relevance to training and awareness

Competition law limits in dealing with competitors’ customers

Authority / court
Konkurences padome (Lettischer Wettbewerbsrat)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
18 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Mar 2026 Schaeffler AGSchaeffler: deviation of quarterly figures from market expectations disclosed too late GermanyDisclosure and reporting obligations €180,000

The automotive supplier's business figures for the first quarter of 2024 deviated significantly from market expectations; this inside information was not disclosed without delay by means of an ad hoc announcement. BaFin imposed a fine.

What organisations can take from it

Make a comparison of internal figures with the analyst consensus a fixed part of the quarterly process, so that significant deviations are immediately assessed for ad hoc disclosure obligations.

Relevance to training and awareness

Recognising inside information in deviations from market expectations (controlling/IR)

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR
Action
Fine
Status of proceedings
final
Sector
Automotive
Published
26 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register MaltaMoney laundering and terrorist financing €69,000

Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.

What organisations can take from it

Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.

Authority / court
Financial Intelligence Analysis Unit (FIAU)
Area of law
Money laundering and terrorist financing
Legal basis
Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The bank continuously attempted to upload reports
Published
6 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order DenmarkData subject rights and transparency €8,031

Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.

What organisations can take from it

Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.

Relevance to training and awareness

Handling access requests (Art. 15 GDPR)

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
Action
Fine
Status of proceedings
final
Sector
Other

Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy FinlandData subject rights and transparency €5,000

Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.

What organisations can take from it

Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.

Relevance to training and awareness

Right of access to call recordings

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15 Abs. 1 und 3
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
25 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 BVwG reduces FMA penalty against private bank over unclarified beneficial owners AustriaCustomer due diligence €356,000

From 2017 to 2020, an Austrian bank specialising in private and investment banking had not adequately examined the ownership and control structure of an offshore holding client despite the lack of evidence on shareholders, trust arrangements and beneficial owners. The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the infringement but reduced the additional penalty imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 17 December 2024 from 476,000 to 356,000 EUR (total penalty 436,000 EUR less FMA penalties already paid), because the FMA had taken the seriousness of the offence into account twice and the bank had cooperated, admitted its errors and terminated the client relationship; an appeal on points of law has been permitted.

What organisations can take from it

For offshore holdings with trustees, prove the beneficial owner with supporting documents – a self-declaration is not enough.

Relevance to training and awareness

Identifying beneficial owners in holding and trust structures

Authority / court
Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 17.12.2024
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 9 Abs. 1 erster Satz i. V. m. § 6 Abs. 1 Z 2 FM-GwG; § 35 Abs. 1 und 3 i. V. m. § 34 Abs. 1 Z 2 und Abs. 2 FM-GwG; § 22 Abs. 9 FMABG (Zusatzstrafe)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Culpability
negligent
Mitigating circumstances
Reduction by the court because the wrongfulness of the offence had been counted twice, cooperation, admission of the facts and of guilt, and termination of the client relationship

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR RomaniaData protection €1,999

The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.

What organisations can take from it

Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.

Relevance to training and awareness

Taking patient data when leaving; cooperation with the supervisory authority

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
20 Feb 2026

Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files CroatiaData subject rights and transparency €100,000

An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.

Relevance to training and awareness

Data minimisation for ID copies, retention periods

Missing or inadequate training played a role in the decision.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
negligent
Mitigating circumstances
No damage to data subjects was found.
Published
19 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Périphériques et Matériels de Contrôle SAS (Groupe Carrus)Betting terminal manufacturer PMC: CJIP over payments to the head of state-owned PMU Mali FranceBribery of public officials €499,150

From 2008 to 2011, the Paris-based supplier of betting and gaming terminals made unjustified payments of 78,972 EUR to the head of the majority state-owned Pari Mutuel Urbain Mali, with which it had a supply contract awarded without a tender. The case was triggered by a report from TRACFIN (the French financial intelligence unit). Public interest fine of 499,150 EUR (including 335,000 EUR already seized) and a three-year AFA compliance programme.

What organisations can take from it

Managers of state-controlled companies are also public officials – even small private payments to them create a risk of criminal liability for medium-sized companies.

Relevance to training and awareness

Payments to heads of state-owned companies abroad

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger und Geldwäsche
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Employees
50 to 249
Culpability
intentional
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR EU levelOrganisational requirements €1.37m

The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.

What organisations can take from it

Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.

Authority / court
Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Culpability
negligent
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Feb 2026 BVwG upholds 588,000 EUR FMA penalty against major bank over incorrect risk classification AustriaCustomer due diligence €588,000

The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) dismissed the appeal of a listed major Austrian bank and upheld the fine of 588,000 EUR (plus 58,800 EUR in procedural costs) imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 19 November 2024. From 2017 to 2020, the bank had not adequately risk-classified three business relationships and had disregarded sector risks such as gambling and precious metals trading as well as cash intensity; an appeal on points of law has been permitted.

What organisations can take from it

Customers from gambling or precious metals trading with a high share of cash belong in a higher risk class – otherwise the enhanced obligations are missing.

Relevance to training and awareness

Risk classification of cash-intensive high-risk sectors

Authority / court
Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 19.11.2024
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
§ 6 Abs. 5 i. V. m. § 34 Abs. 1 Z 2 und § 35 Abs. 1–3 FM-GwG
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 ELKOND HHK, VUKI, Prysmian, NKT, KABEX u. a. (Kabelkartell, 9 Unternehmen und ein Verband)Cable cartel: PMÚ imposes record fines of 97.4 million EUR SlovakiaCartels and collusion €97.4m

Manufacturers and suppliers of copper and aluminium cables coordinated a common calculation of the metal surcharge, which makes up a significant part of the final price; an industry association acted as facilitator. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a total of 97,434,800 EUR, the highest amount in a single proceeding; two leniency applicants were not fined (not final). Addressees: ELKOND HHK, a.s.; VUKI a.s.; Prysmian Kablo s.r.o.; Prysmian Kabely, s.r.o.; Kablo Vrchlabí s.r.o.; NKT s.r.o.; PRECON s.r.o.; Tele–Fonika Kabely CZ s.r.o.; KABELOVNA KABEX a. s.; Asociace výrobců kabelů a vodičů ČR a SR (leniency applicants without a fine: ICS Industrial Cables Slovakia, PRAKAB).

What organisations can take from it

A coordinated calculation formula for price components is also price fixing – association work needs competition law support.

Relevance to training and awareness

Price coordination via associations and surcharge formulas

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
Action
Fine
Status of proceedings
unknown
Sector
Manufacturing and mechanical engineering
Culpability
intentional
Published
11 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 DPG Media nv; Mediahuis nv; PPP Belgium bv; bpost nv (Kronzeuge)Press concession: 11.9 million EUR for collusion in newspaper delivery tender BelgiumCartels and collusion €11.9m

So that bpost would obtain the state concession for newspaper delivery for 2023–2027, its competitor PPP refrained from submitting a bid and in return received additional delivery volumes from DPG Media and Mediahuis (bid rigging). In a settlement procedure, the Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (Belgian Competition Authority, BMA) imposed 3,786,574 EUR (DPG Media), 7,788,423 EUR (Mediahuis) and 323,486 EUR (PPP); bpost, as leniency applicant, received full immunity, and two bpost employees involved were fined a total of 6,300 EUR.

What organisations can take from it

Agreements on who participates in a tender are hardcore cartels – individuals are also liable, and leniency applicants benefit.

Relevance to training and awareness

Collusion in public tenders

Authority / court
Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (BMA)
Area of law
Competition law · Cartels and collusion
Legal basis
Code de droit économique Art. IV.1; AEUV Art. 101
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Leniency programme (immunity for bpost; reductions of 50% and 40% for DPG Media and Mediahuis respectively) and 10% settlement reduction.
Liability of senior managers
First-ever fines against two natural persons (employed by bpost), totalling 6,300 EUR.
Published
13 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Feb 2026 UAB „Manado“, MB „Parts ready“Manado and Parts ready: cartel in Vilnius public transport spare parts tender LithuaniaCartels and collusion €41,080

In two tenders by ‘Vilniaus viešasis transportas’ for vehicle spare parts (May–October 2025), the dealers coordinated bids and prices, wrote the bids for each other and sent them from the same computer. The contracting entity reported the suspicion. Following acknowledgement (minus 15%), fines of 17,950 EUR (Manado) and 23,130 EUR (Parts ready). Source: archived copy of the press release.

What organisations can take from it

Even jointly prepared bids by small dealers are a cartel – and contracting entities increasingly recognise such patterns.

Relevance to training and awareness

Competition law in tenders

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Cartels and collusion
Legal basis
Konkurencijos įstatymas (verbotene Vereinbarungen)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Acknowledgement of the infringement (15% reduction)
Published
12 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Feb 2026 Strukton Civiel Projecten B.V. und Strukton International B.V. (Strukton-Gruppe)Construction group Strukton pays 10 million EUR out-of-court settlement over bribery on the Riyadh Metro NetherlandsBribery of public officials €10m

To secure a share in the Riyadh Metro project, around 31 million USD was paid between 2013 and 2021 to an agent representing a high-ranking member of the Saudi royal family; the agent payments were understated to the export credit insurer Atradius. Strukton accepted a transaction (out-of-court settlement) of 10 million EUR.

What organisations can take from it

Commissions to agents with ties to ruling families carry the highest risk – and false statements to export credit insurers constitute a second offence.

Relevance to training and awareness

Agent commissions and false statements to export credit insurers

Authority / court
Openbaar Ministerie (OM)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Buitenlandse ambtelijke omkoping und valsheid in geschrift (Wetboek van Strafrecht); Transactie nach Art. 74 Sr
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Culpability
intentional
Mitigating circumstances
Cooperation from mid-2023; compliance programme in place since 2017; the employees involved are no longer with the company.
Liability of senior managers
The Dutch Public Prosecution Service (OM) is considering prosecuting several natural persons involved (not named).
Published
30 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 RASEMA s.r.o.; M – D – J, spol. s.r.o.; SIMA plus Krompachy, s.r.o.; BarCom spol. s.r.o.Photovoltaic tender: 1.1 million EUR – the contracting entity was also a cartel member SlovakiaCartels and collusion €1.1m

In a tender for industrial photovoltaic installations that was to be financed from EU Structural Funds, three bidders coordinated their bids so that a pre-selected bidder would win; the contracting entity BarCom acted as facilitator. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a total of 1,098,200 EUR and three-year procurement bans on all four; the EU funding was refused because of the indications of competition infringements, and the collusion was proven by e-mails secured during the inspection.

What organisations can take from it

A contracting entity that determines the winner of a funded tender in advance is itself liable under competition law and additionally risks losing the funding.

Relevance to training and awareness

Collusion in funded procurement

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Culpability
intentional
Published
11 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list PortugalCartels and collusion €8,200

Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).

What organisations can take from it

Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.

Relevance to training and awareness

No price recommendations by professional associations

Authority / court
Autoridade da Concorrência (AdC)
Area of law
Competition law · Cartels and collusion
Legal basis
Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jan 2026 CCV Group B.V.Netherlands: payment institution CCV without integrity risk analysis – 406,125 EUR fine NetherlandsInternal controls €406,125

Until March 2018, the payment institution had no systematic integrity risk analysis (SIRA) and therefore no systematic identification and analysis of integrity risks for its gatekeeper function. The Dutch central bank (De Nederlandsche Bank, DNB) imposed the fine in 2020; following objection and appeal proceedings, it was fixed at the reduced amount of 406,125 EUR by the decision of 28 January 2026 and was published in July 2026.

What organisations can take from it

Without a documented integrity risk analysis, any money laundering prevention lacks its foundation – and that alone is subject to fines.

Authority / court
De Nederlandsche Bank (DNB)
Area of law
Money laundering and terrorist financing · Internal controls
Legal basis
Art. 3:10 Wet op het financieel toezicht (Wft); Art. 10 Besluit prudentiële regels Wft (Bpr)
Action
Fine
Status of proceedings
reduced
Sector
Financial services and insurance
Mitigating circumstances
Fine reduced in the objection and appeal proceedings
Published
21 Jul 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data SwedenData breaches and data security €564,626

The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).

What organisations can take from it

Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
Published
26 Jan 2026

Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack FranceData breaches and data security €5m

In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.

What organisations can take from it

Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.

Relevance to training and awareness

Social engineering and account takeover

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
29 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jan 2026 Logistics business: fines for minimum wage, reporting and foreign employment violations GermanyMinimum wage and undeclared work €13,731

Between June and December 2023, a logistics and transport business withheld a total of around 2,000 EUR in minimum wages from several employees, breached reporting and immediate notification obligations, and in July/August 2023 employed a foreign national without a residence permit. The fines: 5,231 EUR (minimum wage), 750 EUR each (reporting obligations) and 7,000 EUR (unauthorised employment of foreign nationals), totalling 13,731 EUR (date = publication).

What organisations can take from it

Even small wage arrears are penalised individually alongside reporting and residence violations – HR processes for new hires need a fixed checklist.

Relevance to training and awareness

Immediate notification and checking of work permits when hiring

Authority / court
Hauptzollamt Karlsruhe (Finanzkontrolle Schwarzarbeit)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
§ 21 Abs. 1 Nr. 11 MiLoG; § 111 Abs. 1 Nr. 2 SGB IV; § 404 Abs. 2 Nr. 3 SGB III
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
22 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2026 PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs)Pharmaceutical cartel uncovered thanks to whistleblower: 7.8 million EUR against PHOENIX and TRANSMEDIC SlovakiaCartels and collusion €7.8m

The two companies colluded in tenders of the General Health Insurance Company for the supply of medicines (2017–2020). For the first time, a cartel was uncovered on the basis of information from a whistleblower; the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 7,595,200 EUR and a one-year procurement ban on PHOENIX and 201,800 EUR and a three-year procurement ban on TRANSMEDIC (first instance).

What organisations can take from it

Whistleblowers receive a reward in Slovakia – internal reporting channels should be faster than the route to the authority.

Relevance to training and awareness

Bid rigging in public tenders; whistleblowing channels

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
PHOENIX: settlement with a 30% fine reduction and a shortened procurement ban.
Published
24 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2026 Cardif Lux Vie S.A.Cardif Lux Vie: 615,000 EUR over deficiencies in money laundering questionnaires and customer files LuxembourgCustomer due diligence €615,000

An on-site inspection in 2023 revealed that the life insurer in some cases did not handle the mandatory money laundering risk assessment questionnaires in compliance with the rules, that the employees responsible lacked sufficiently precise instructions and that customer files contained many incorrect answers. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 615,000 EUR.

What organisations can take from it

Risk questionnaires are only as good as the guidance given to those who complete them – clear work instructions and training are part of this.

Relevance to training and awareness

Money laundering risk assessment by employees

Authority / court
Commissariat aux Assurances (CAA)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 8-4, 8-5; Règlement CAA 20/03
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Close cooperation with the CAA during and after the inspection; remediation plan for all deficiencies submitted promptly.
Published
1 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants AustriaData subject rights and transparency €25,500

The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).

What organisations can take from it

Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.

Relevance to training and awareness

Recording of telephone calls and applicant data

Authority / court
Datenschutzbehörde
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
Action
Fine
Status of proceedings
under appeal
Sector
Other
Employees
Under 50
Mitigating circumstances
No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR RomaniaEmployee data €14,997

An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.

Relevance to training and awareness

Handling employees’ health data, e-mail distribution lists

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
19 Jan 2026

Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2026 Zalando SEZalando: around 31 million PLN for missing 30-day lowest prices on discounts PolandMisleading advertising and pricing €7.34m

Zalando did not display the lowest price of the previous 30 days for discounts, manipulated reference prices to make reductions appear larger and did not present the mandatory information consistently at all stages of the purchasing process. Poland's Office of Competition and Consumer Protection (UOKiK) imposed a fine of 30,945,000 PLN; the decision is not final.

What organisations can take from it

Discount information must be identical and correct on all pages of a shop – listing, product page, shopping basket.

Relevance to training and awareness

Presentation of discounts in online shops

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
14 Jan 2026

Original amount 30,945,000 PLN, converted at the ECB reference rate of 14 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2026 Whaleco Technology Limited (Temu)Temu: almost 6 million PLN over changing reference prices and discount labelling PolandMisleading advertising and pricing €1.4m

The operator of the Temu interface omitted the 30-day lowest price or stated it incorrectly, labelled promotions inconsistently and changed reference prices from day to day without the actual price changing. UOKiK imposed a fine of 5,910,900 PLN; the decision is not final.

What organisations can take from it

Reference prices that shift daily without any real price change are a misleading staging of discounts.

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
14 Jan 2026

Original amount 5,910,900 PLN, converted at the ECB reference rate of 14 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jan 2026 Bulgarian construction subcontractor: 232,500 EUR for paying below the minimum wage GermanyMinimum wage and undeclared work €232,500

A Bulgarian construction company that worked as a subcontractor for a German firm on a major construction site in the district of Tuttlingen between January and May 2023 paid below the minimum wage, recorded only the duration of working time rather than its start and end, and did not register the posting. The decisions issued in September 2025, final since the end of 2025, amount to 232,500 EUR – of which 215,000 EUR is disgorgement of the economic benefit and 17,500 EUR is imposed on the managing director (date = publication; exact date of the decision not specified).

What organisations can take from it

General contractors should actively check the minimum wage, working time records and posting notifications of their foreign subcontractors – the economic benefit is disgorged in full.

Authority / court
Hauptzollamt Singen (Finanzkontrolle Schwarzarbeit)
Area of law
Health and safety and employment law · Minimum wage and undeclared work
Legal basis
Mindestlohngesetz; Arbeitnehmer-Entsendegesetz (Aufzeichnungs- und Meldepflichten)
Action
Fine
Status of proceedings
final
Sector
Construction and real estate
Liability of senior managers
Separate fine of 17,500 EUR against the managing director.
Published
9 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts FranceData breaches and data security €42m

Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.

What organisations can take from it

Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
Published
14 Jan 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log GreeceEmployee data €10,000

In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.

What organisations can take from it

Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.

Relevance to training and awareness

Confidential handling of employees’ health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jan 2026 Portugal: 16,000 EUR against filling station operator for forwarding complaints late PortugalConsumer protection and online retail €16,000

A filling station operator (medium-sized company, name not published) did not send the originals of eight sheets from the statutory complaints book to the authority on time. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) imposed 16,000 EUR for eight negligent administrative offences; the Competition, Regulation and Supervision Court upheld the fine in full on 14 July 2026.

What organisations can take from it

Even formal obligations such as forwarding complaints book sheets are sanctioned per case – branch staff must know the procedure.

Relevance to training and awareness

Timely forwarding of customer complaints from the complaints book

Authority / court
Entidade Reguladora dos Serviços Energéticos (ERSE)
Area of law
Consumer protection and online retail
Legal basis
Decreto-Lei n.º 156/2005 (Livro de Reclamações); Regime Jurídico das Contraordenações Económicas, Art. 18, 19
Action
Fine
Status of proceedings
final
Sector
Energy and utilities
Employees
50 to 249
Culpability
negligent
Mitigating circumstances
No previous record, no economic advantage

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent PolandData protection €232,208

The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.

What organisations can take from it

Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Repeat case
yes
Mitigating circumstances
During the proceedings the function was made independent and placed directly under the management board.
Published
26 Jan 2026

Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 C2MAC Group, Fonderie De Riccardis, Zanardi Fonderie u. a. (Gießereikartell, 12 Unternehmen und Assofond)Italy: 70 million EUR against 16 foundries and the association Assofond over price index cartel ItalyCartels and collusion €70m

From 2004 to June 2024, foundries coordinated their pricing strategies via the association Assofond: they exchanged sensitive information and developed joint indexation mechanisms ("Assofond indicators") in order to push through price increases including margins. The AGCM imposed fines of 70 million EUR (maximum around 600 million EUR), taking the crisis in the sector into account as a mitigating factor. Addressees: C2MAC Group, Fonderia Corrà, Fonderie De Riccardis, Fonderie Guido Glisenti/Lead Time, Pilenga Baldassarre/E.F. Group, Fonderie Mora Gavardo/Camozzi Group, Zanardi Fonderie, VDP Fonderia, Fonderie Ariotti, Ironcastings, Fonderia Zardo, ZML Industries/Cividale, Assofond.

What organisations can take from it

Joint price indices within an association are only permissible if they do not enable coordination of margins or prices – metalworking companies should have their association activities accompanied by competition law advice.

Relevance to training and awareness

Association indices and price adjustment clauses as a coordination tool

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Steel and metals
Mitigating circumstances
The severe crisis in the foundry sector was taken into account in setting the fines
Published
31 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier GreeceMarketing and consent €80,000

Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).

What organisations can take from it

Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.

Relevance to training and awareness

Checking consent before telemarketing

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5, 6, 7, 29, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2025 Ryanair DAC, Ryanair Holdings plcItaly: 255.8 million EUR against Ryanair for obstructing travel agencies ItalyAbuse of market power €255.8m

From April 2023 until at least April 2025, Ryanair obstructed travel agencies from buying Ryanair flights in combination with other services, for example through facial recognition procedures, account deletions, blocking of means of payment and restrictive partner agreements. The AGCM considered this to be an abuse of a dominant position and imposed fines of 255,761,692 EUR on a joint and several basis.

What organisations can take from it

Dominant providers must not use technical barriers to force sales partners and resellers out of the market.

Authority / court
Autorità Garante della Concorrenza e del Mercato (AGCM)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Published
23 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR FranceEmployee data €15m

In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.

What organisations can take from it

Store employee performance metrics only for as long and in as much detail as their specific purpose requires.

Authority / court
Conseil d'État
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
reduced
Sector
Transport, logistics and shipping
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws FranceData processors €1.7m

As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.

What organisations can take from it

Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat SpainData processors €500,000

An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.

What organisations can take from it

Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.

Relevance to training and awareness

Diligence in customer service / misdirected messages

Authority / court
Agencia Española de Protección de Datos (AEPD)
Area of law
Data protection · Data processors
Legal basis
Art. 25 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Snowball.xyz-Gruppe (Snowball.xyz, Šviesa, Tavo mokykla, Ateities pamoka) und AL holdingas-Gruppe (AL holdingas, Ugdymo sprendimai, UNT nuoma)E-register providers shared the market – 3.6 million EUR in cartel fines LithuaniaCartels and collusion €3.63m

In August 2020, the operators of the electronic class registers ‘Tamo’ and ‘Eduka’ agreed to stop competing: one group kept the class register business, the other took over the digital learning content. Following acknowledgement of the infringement, the fines were reduced by 15%: 2,714,940 EUR jointly and severally for the Snowball.xyz group and 913,340 EUR for the AL holdingas group (Art. 101 TFEU). The decision can be appealed. Source: archived copy of the press release.

What organisations can take from it

Agreements between competitors on ‘who does what’ are cartels – even when dressed up as portfolio streamlining.

Relevance to training and awareness

Market sharing among competitors

Authority / court
Konkurencijos taryba (Litauischer Wettbewerbsrat)
Area of law
Competition law · Cartels and collusion
Legal basis
Konkurencijos įstatymas; Art. 101 AEUV
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Acknowledgement of the infringement (15% reduction)
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style ItalyEmployee data €120,000

At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.

What organisations can take from it

Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.

Relevance to training and awareness

Employee monitoring through telematics

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
Action
Fine
Status of proceedings
final
Sector
Food and agriculture
Mitigating circumstances
Small number of data subjects (five employees), immediate suspension of the processing.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Bravogroup Holding Vagyonkezelő Kft.Bravogroup: 32.6 million HUF for unnotified stake in Xiaomi distributor HungaryMerger control €84,042

In February 2023, the IT holding company acquired a 50% stake with negative sole control in the Xiaomi distributor Mystical Hungary Zrt., but only approached the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) after 582 days and notified the concentration thereafter. Following voluntary disclosure, acknowledgement and waiver of legal remedies, the authority imposed a significantly reduced 32.6 million HUF.

What organisations can take from it

Blocking rights (negative control) can also trigger a notification requirement – review stakes under merger control law before signing.

Relevance to training and awareness

Merger control for minority stakes with veto rights

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Merger control
Legal basis
Ungarisches Wettbewerbsgesetz, Vollzugsverbot (VJ/20/2025)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Voluntary disclosure, acknowledgement and waiver of legal remedies.
Published
18 Dec 2025

Original amount 32,600,000 HUF, converted at the ECB reference rate of 18 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Dec 2025 Asparagus farm without reliable working time records: Raad van State upholds 11,250 EUR NetherlandsWorking time €11,250

In May/June 2022, the working time records of an asparagus business (anonymised in the judgment) deviated structurally from the hours actually worked; among other things, Sunday work went unrecorded, so compliance with working and rest times could not be checked. The Administrative Jurisdiction Division of the Dutch Council of State (Raad van State, Afdeling bestuursrechtspraak) upheld the fine of 11,250 EUR, imposed in 2023 without prior warning, including the increase factor of 1.5.

What organisations can take from it

Working time records that do not reflect actual hours are treated as missing – businesses are then sanctioned without prior warning.

Relevance to training and awareness

Correct recording of working and rest times

Authority / court
Raad van State, Afdeling bestuursrechtspraak (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid)
Area of law
Health and safety and employment law · Working time
Legal basis
Art. 4:3 Abs. 1 Arbeidstijdenwet
Action
Fine
Status of proceedings
final
Sector
Food and agriculture

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Dec 2025 Hardeck Möbel GmbH & Co. KGFurniture retailer Hardeck: 379,503 EUR fine for breach of AML due diligence obligations GermanyCustomer due diligence €379,504

The Arnsberg regional government (Bezirksregierung Arnsberg), as anti-money laundering supervisor for the non-financial sector, imposed a fine of 379,503.50 EUR, final since 16 December 2025, on the furniture retailer as a dealer in goods for breach of due diligence obligations under the German Money Laundering Act (Geldwäschegesetz, GwG). Karl-Ernst Hardeck is named as the person responsible for the company.

What organisations can take from it

Furniture retailers, as dealers in goods, are also obliged entities under the GwG – breaches of due diligence obligations can trigger six-figure fines.

Relevance to training and awareness

Identification for cash payments in the trade in goods

Authority / court
Bezirksregierung Arnsberg (Geldwäscheaufsicht Nichtfinanzsektor)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Geldwäschegesetz (Sorgfaltspflichten); Bekanntmachung nach § 57 GwG
Action
Fine
Status of proceedings
final
Sector
Retail and e-commerce
Liability of senior managers
The announcement names Karl-Ernst Hardeck as the person responsible for the infringement

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Exide, FET (inkl. Elettra), Rombat, EUROBAT (Clarios Kronzeuge)EU: 72 million EUR against starter battery manufacturers and the association EUROBAT EU levelCartels and collusion €72m

From 2005 to 2017, the manufacturers of automotive starter batteries agreed, with the help of the association EUROBAT, to publish jointly calculated lead surcharges (EUROBAT premiums) and to use them in price negotiations with carmakers. Fines: Exide 30 million EUR, Rombat 20.218 million EUR, Elettra 15.594 million EUR, FET 6.11 million EUR, EUROBAT 125,000 EUR; Clarios escaped a fine as leniency applicant.

What organisations can take from it

Suppliers may pass on raw material surcharges individually, but must never fix them in an industry-wide coordinated manner via association indices.

Relevance to training and awareness

Joint raw material surcharges among competitors via association indices

Authority / court
Europäische Kommission
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 101 AEUV, Art. 53 EWR-Abkommen
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Mitigating circumstances
Leniency programme (Clarios 100 %, FET 50 %, Rombat 30 %); reduction for inability to pay for one company; payment in instalments

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack NetherlandsData breaches and data security €175,000

In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.

What organisations can take from it

Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.

Authority / court
Autoriteit Persoonsgegevens (AP)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector
Culpability
negligent
Mitigating circumstances
Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Dec 2025 „ЗП Либра“ ООДZP Libra: 44,205 leva for poaching customers using competitor’s trade secrets BulgariaCompetition law €22,602

With the help of an employee of its competitor I&G Insurance Brokers who later moved to ZP Libra, the broker unfairly concluded a brokerage agreement to the detriment of the competitor and used the competitor’s trade secrets to poach customers. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) imposed 29,470 leva (1% of 2024 turnover, Art. 36(1) ZZK – Bulgarian Protection of Competition Act) and 14,735 leva (0.5%, Art. 37(1) ZZK); fines totalling 1,000 leva were also imposed on the employee.

What organisations can take from it

When hiring employees from competitors, make sure they do not bring customer lists or secrets with them – otherwise both the company and the individual are liable.

Relevance to training and awareness

Taking customer data and trade secrets when changing employer

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 36 Abs. 1, Art. 37 Abs. 1 ZZK
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Fines on the employee involved (1,000 leva in total)
Published
16 Dec 2025

Original amount 44,205 BGN, converted at the ECB reference rate of 11 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Dec 2025 Invest in OÜLender Invest in OÜ pays 16,000 EUR for failing to submit annual accounts EstoniaDisclosure and reporting obligations €16,000

The lender did not submit its 2024 annual report, together with the audit report, the resolution on the appropriation of profits and the minutes of the shareholders’ meeting, to the financial supervisory authority on time. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed a fine of 16,000 EUR; the maximum is 1 million EUR or 10% of annual turnover. Date = publication.

What organisations can take from it

Even small supervised lenders need a reliable deadline calendar for mandatory supervisory reports.

Authority / court
Finantsinspektsioon (Estnische Finanzaufsicht)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 56 Abs. 3, § 96 Abs. 2 KAVS (Gesetz über Kreditgeber und -vermittler)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
10 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository EU levelPlatform obligations €120m

First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.

What organisations can take from it

Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
5 Dec 2025
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 Volvo Hungária Kereskedelmi és Szolgáltató Kft.; Seres Gépipari Kereskedelmi Kft.; GIF Modul Kft.; Interteher Kft.; Eurotrade Kft.; He Hans Eibinger Kft. (MUT Kft. ohne Buße nach Entschädigung)Refuse vehicle cartel: over 1.5 billion HUF, of which 270 million for obstructing the inspection HungaryCartels and collusion €4.06m

In 2014–2015, chassis and body manufacturers allocated contracts and submitted cover bids in tenders for refuse collection and sewer cleaning vehicles. The Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed cartel fines of 1,278.4 million HUF (of which 972.9 million on Volvo Hungária) and, in addition, a record procedural fine of 270 million HUF on Volvo Hungária for obstructing access to data secured during the inspection.

What organisations can take from it

Regular meetings on ‘capacity planning’ with competitors are cartel evidence – and obstructing an inspection costs extra.

Relevance to training and awareness

Bid rigging and conduct during inspections

Authority / court
Gazdasági Versenyhivatal (GVH)
Area of law
Competition law · Cartels and collusion
Legal basis
Ungarisches Wettbewerbsgesetz, Art. 101 AEUV (Submissionsabsprachen, Verfahrensbuße; VJ/30/2018)
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Culpability
intentional
Mitigating circumstances
Admissions and leniency applications by most participants; MUT paid 116 million HUF in compensation to contracting authorities.
Published
5 Dec 2025

Original amount 1,548,400,000 HUF, converted at the ECB reference rate of 5 Dec 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository EU levelPlatform obligations Order

Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.

What organisations can take from it

Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.

Authority / court
Europäische Kommission
Area of law
AI and digital regulation · Platform obligations
Legal basis
Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
Action
Order
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Dec 2025 Jeronimo Martins Polska (Biedronka)Biedronka: almost 105 million PLN over undisclosed conditions for "100 % back" PolandMisleading advertising and pricing €24.7m

The supermarket chain advertised promotions such as "Special Wednesday" with "100 % money back as a voucher", but did not state restrictions concerning product categories, minimum spend and use of the vouchers in radio, app and in-store advertising, only on the receipt, the website or in-store notices. UOKiK imposed a fine of 104,722,016 PLN; the decision is not final.

What organisations can take from it

State the essential restrictions of a promotion in the advertising itself, not just on the receipt.

Relevance to training and awareness

Complete promotion terms in advertising

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Verletzung kollektiver Verbraucherinteressen (irreführende Werbung durch Unterlassen)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Culpability
intentional
Published
4 Dec 2025

Original amount 104,722,016 PLN, converted at the ECB reference rate of 4 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts EU levelData subject rights and transparency —

On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.

What organisations can take from it

Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.

Authority / court
Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
Status of proceedings
unknown
Sector
Media and online platforms
Published
2 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Dec 2025 SUROVINA d.o.o.; SALOMON d.o.o.; RECIKEL d.o.o.; DINOS d.o.o.Packaging waste: AVK finds market sharing by four waste management companies SloveniaCartels and collusion Order

In the reopened proceedings, the Javna agencija Republike Slovenije za varstvo konkurence (Slovenian Competition Protection Agency, AVK) found that the companies had shared the market for take-back schemes for packaging waste and agreed to stop providing their services to a competitor (now Interzero). The authority ordered immediate termination; the decision is not final, and an earlier decision from 2019 in the same matter is partly final.

What organisations can take from it

An agreement to stop supplying a common competitor is a cartel – even in regulated waste management markets.

Relevance to training and awareness

Boycott and market-sharing agreements

Authority / court
Javna agencija Republike Slovenije za varstvo konkurence (AVK)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 6 ZPOmK-1, Art. 101 AEUV (3062-5/2017)
Action
Order
Status of proceedings
unknown
Sector
Energy and utilities
Published
16 Apr 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ FranceCookies and tracking €1.5m

When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.

What organisations can take from it

Cookie settings must apply across all domains of a service – including when users move to affiliated sites.

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Cookies and tracking
Legal basis
Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Corrections during the proceedings, cooperation.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis BelgiumMarketing and consent €5,000

The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.

What organisations can take from it

Data brokers must be able to prove for every record on which legal basis it was collected and resold.

Authority / court
Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
Area of law
Data protection · Marketing and consent
Legal basis
DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
Action
Fine
Status of proceedings
reduced
Sector
Telecoms, IT and software

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Load 20 more of 222

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial