Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUCroatia Clear all filters
11cases from 1 jurisdiction
€13.8mTotal of monetary amounts
€5.47mLargest single case: EOS Matrix d.o.o.
€300,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€5.47m
Q1 20240—
Q2 20240—
Q3 20241€190,000
Q4 20242€1.26m
Q1 20250—
Q2 20250—
Q3 20252€421,000
Q4 20252€6m
Q1 20261€100,000
Q2 20261€300,000
Q3 20261€10,000

11 cases

5 Oct 2023 EOS Matrix d.o.o.Croatia: 5.47 million EUR against debt collection company EOS Matrix after data leak CroatiaData breaches and data security €5.47m

An anonymous tip-off accompanied by a USB stick proved that data of 181,641 debtors had leaked from the debt collection company’s records; there were no systems for detecting unusual data retrievals. In addition, EOS Matrix stored health data up to and including diagnoses, data of non-debtors and call recordings without a legal basis; the Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 5.47 million EUR.

What organisations can take from it

Employees’ free-text notes can turn into impermissible health data – clear recording rules and monitoring of data retrievals are mandatory.

Relevance to training and awareness

No recording of health data in call notes

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 2, Art. 6 Abs. 1, Art. 9 Abs. 2, Art. 12, 13, 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
5 Oct 2023

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Aug 2026 Elizabeta Promet d.o.o., SolinCroatia: 10,000 EUR against Elizabeta Promet for deliveries without a written contract CroatiaAbuse of market power €10,000

As a buyer with significant bargaining power, the company from Solin purchased agricultural and food products from two suppliers without written contracts. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) considered this an unfair trading practice and, taking mitigating circumstances into account, imposed 10,000 EUR (date = publication).

What organisations can take from it

In food purchasing, the mere absence of written supply contracts is an infringement – a simple contract standard prevents this.

Relevance to training and awareness

Written form for supply contracts in food purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Several mitigating circumstances taken into account
Published
25 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Kaufland Hrvatska k.d.Croatia: 300,000 EUR against Kaufland for unfair practices towards suppliers CroatiaAbuse of market power €300,000

The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) found that Kaufland Hrvatska charged food suppliers fees for services not provided and for advertising not commissioned, and paid for perishable goods only after more than 30 days. For these unfair trading practices, and with repeat offending as an aggravating factor (final penalty already in 2020), it imposed 300,000 EUR (date = publication).

What organisations can take from it

Purchasing departments must know the payment deadlines and fee prohibitions of UTP law – repeat offences become significantly more expensive.

Relevance to training and awareness

Fair terms towards suppliers in purchasing

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 4, 11, 12 Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Repeat case
yes
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files CroatiaData subject rights and transparency €100,000

An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.

Relevance to training and awareness

Data minimisation for ID copies, retention periods

Missing or inadequate training played a role in the decision.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
negligent
Mitigating circumstances
No damage to data subjects was found.
Published
19 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers CroatiaData subject rights and transparency €1.5m

The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).

What organisations can take from it

Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
18 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses CroatiaInternational data transfers €4.5m

The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.

What organisations can take from it

Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · International data transfers
Legal basis
Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
14 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords CroatiaData breaches and data security €320,000

The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).

What organisations can take from it

Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.

Relevance to training and awareness

Secure password storage in software development

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 31, Art. 32 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Energy and utilities
Published
22 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2025 Hrvatski ured za osiguranje (HUO)AZOP: 101,000 EUR against Croatian Insurance Bureau after leak of vehicle owner data CroatiaData breaches and data security €101,000

Following an anonymous tip-off about a USB stick containing data on more than one million vehicle owners (name, OIB, address, registration number, insurance data), the Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) found that the data originated from the database of the Insurance Bureau, which had not laid down appropriate protective measures or deletion periods. Because of its public tasks, the fine was capped at 101,000 EUR (date of publication; exact date of the decision not stated).

What organisations can take from it

Large registers need access controls, export logging and deletion periods so that bulk data does not end up unnoticed on USB sticks.

Relevance to training and awareness

Access control and deletion periods for register data

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 32 Abs. 2 und 4 DSGVO; Art. 44 kroatisches DSGVO-Durchführungsgesetz
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Cap due to public tasks (Art. 44 of the Implementing Act).
Published
2 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Hrvatski lovački savezCroatia: 89,935 EUR against hunting association for predatory pricing in hunter training CroatiaAbuse of market power €89,935

From 2022 to March 2024, the Croatian Hunting Association offered hunter training below cost and financed this from areas in which it holds a statutory monopoly in order to drive out competitors. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed 89,935.20 EUR and ordered separate cost accounting; the High Administrative Court dismissed the action on 17 December 2025.

What organisations can take from it

An organisation holding a monopoly in one market must not use the profits from it to undercut in neighbouring markets – separate cost accounting provides evidence.

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 13 Nr. 1 Zakon o zaštiti tržišnog natjecanja (ZZTN)
Action
Fine
Status of proceedings
final
Sector
Other
Published
10 Feb 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Dec 2024 Ericsson Nikola Tesla d.d., Kodeks d.o.o., Retel d.o.o., Vatel d.o.o., LUMISS d.o.o., Mitel Austria GmbHCroatia: 1.17 million EUR against Ericsson Nikola Tesla and five partners for customer allocation CroatiaCartels and collusion €1.17m

From 2010 to 2015, the suppliers of Ericsson/Aastra/Mitel telephone systems (PBX) allocated customers among themselves so as not to undercut each other. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) imposed a total of 1,170,968.24 EUR, of which 785,570.58 EUR on Ericsson Nikola Tesla; one leniency applicant (Steiner) was not penalised, and Kodeks received a reduction.

What organisations can take from it

Dealers of the same brand are also competitors – agreements on ‘own’ customers are a hardcore cartel.

Relevance to training and awareness

No agreements on customer or territorial allocation

Authority / court
Agencija za zaštitu tržišnog natjecanja (AZTN)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 8 Zakon o zaštiti tržišnog natjecanja (ZZTN)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Leniency programme for two participants
Published
5 Mar 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup CroatiaData breaches and data security €190,000

In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.

What organisations can take from it

Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.

Relevance to training and awareness

Notification of data breaches within 72 hours

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
13 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial