Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUCyprus Clear all filters
10cases from 1 jurisdiction
€525,500Total of monetary amounts (7 cases with an amount)
€225,000Largest single case: FXNET Limited
€70,000Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Cyprus Securities and Exchange Commission (CySEC) €511,500 97 % · 5 cases
  2. Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) €14,000 3 % · 5 cases

What for?

by area of law

All areas of law

  1. Capital markets and financial supervision €511,500 97 % · 5 cases
  2. Data protection €14,000 3 % · 5 cases

Who?

by sector

All sectors

  1. Financial services and insurance €505,000 96 % · 7 cases
  2. Other €20,500 4 % · 2 cases
  3. Energy and utilities — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20242€4,000
Q1 20254€235,000
Q2 20250—
Q3 20251€70,000
Q4 20251€100,000
Q1 20260—
Q2 20262€116,500
Q3 20260—

10 cases

8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report CyprusDisclosure and reporting obligations €16,500

The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.

What organisations can take from it

Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
Action
Fine
Status of proceedings
unknown
Sector
Other
Repeat case
yes
Published
7 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients CyprusOrganisational requirements €100,000

For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.

What organisations can take from it

When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.

Relevance to training and awareness

Appropriateness assessment when selling complex products

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
24 Aug 2026
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Wonderinterest Trading LtdCyprus: 100,000 EUR against Wonderinterest Trading over misleading client information CyprusOrganisational requirements €100,000

For 2022 to 2024, the Cyprus Securities and Exchange Commission (CySEC) found that the investment firm had no adequate compliance procedures, did not define target markets for its financial instruments, did not act in the best interests of clients and did not inform clients in a fair, clear and not misleading manner. It imposed fines of 50,000, 30,000 and 20,000 EUR; a judicial review of the decision has been recorded.

What organisations can take from it

Advertising statements by financial service providers must present risks in a balanced way – marketing belongs in the compliance approval process.

Relevance to training and awareness

Fair and not misleading marketing communications

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Sec. 17(2), 17(3)(c), 22(1), 25(1), 25(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 22, 44 Delegierte VO (EU) 2017/565
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Dec 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Sep 2025 Blacktower Financial Management (Cyprus) LtdCyprus: Blacktower Financial Management pays 70,000 EUR over conflicts of interest CyprusOrganisational requirements €70,000

For the period November 2020 to May 2025, the Cyprus Securities and Exchange Commission (CySEC) investigated the investment firm’s handling of conflicts of interest and its general conduct of business and information obligations towards clients. The proceedings ended with a settlement of 70,000 EUR, which the company has paid.

What organisations can take from it

Conflicts of interest must be identified, documented and managed vis-à-vis clients – adviser training is the basis for this.

Relevance to training and awareness

Recognising conflicts of interest in investment advice

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 24(1), 25(1) Gesetz über Wertpapierdienstleistungen 2017; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
17 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Mar 2025 FXNET LimitedCyprus: FXNET pays 225,000 EUR under settlement over organisational and CFD breaches CyprusOrganisational requirements €225,000

The investigation covering 2021 to 2022 concerned compliance organisation, product governance, record-keeping obligations, safeguarding of client funds, client information, suitability and appropriateness assessments and the CFD restrictions for retail investors. Following board resolutions of 17 and 31 March 2025, the Cyprus Securities and Exchange Commission (CySEC) concluded a settlement of 225,000 EUR, which has been paid.

What organisations can take from it

Safeguarding client funds and keeping proper records are basic duties of every investment firm – gaps quickly add up in a settlement.

Authority / court
Cyprus Securities and Exchange Commission (CySEC)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Art. 17, 22(1), 25, 26(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; Art. 37(4) CySEC-Gesetz
Action
Other
Status of proceedings
final
Sector
Financial services and insurance
Published
11 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Mar 2025 Αρχή Ηλεκτρισμού Κύπρου (Electricity Authority of Cyprus, EAC)Cyprus: reprimand for electricity supplier EAC over insecure app registration CyprusData breaches and data security Reprimand or warning

A customer denied having registered in the EAC Mobile App and having changed his billing address there; the supplier could not prove that the mobile number used for identification originated from the customer himself. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) found breaches of accountability and data security, issued a reprimand and ordered the delivery address to be clarified with the customer in writing.

What organisations can take from it

Self-registration in customer portals needs robust identity verification – otherwise invoices and data can be redirected.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24, Art. 32 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Energy and utilities

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Mar 2025 Οργανισμός Χρηματοδοτήσεως Στέγης (Housing Finance Corporation)Cyprus: 10,000 EUR against housing finance corporation for storing data too long CyprusData subject rights and transparency €10,000

The housing finance corporation retained data of a former customer in its loan system beyond the permissible retention period because deletion there is only possible manually, record by record. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 10,000 EUR and ordered erasure within 10 days as well as technical and organisational corrections within six months.

What organisations can take from it

Retention periods need technical support – a system without a deletion function turns every expired period into an infringement.

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. d und e, Art. 24 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Feb 2025 Trust International Insurance Company (Cyprus) LimitedCyprus: reprimand for Trust International Insurance – accident file given to insurance agent CyprusData breaches and data security Reprimand or warning

An insurance agent who was himself involved in an accident received, on request, the roadside assistance file from the insurer, including data of the other party to the accident, and subsequently contacted that person. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand because there was no legal basis for the disclosure and internal procedures did not cover this case, and ordered a procedure for data requests from agents and employees.

What organisations can take from it

Own agents or employees are also third parties when they request data in their own matters – this must be governed in the disclosure process.

Relevance to training and awareness

Disclosure of customer data to agents and colleagues in their own matters

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6 Abs. 1, Art. 32 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
The company implemented the order

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Dec 2024 Eurolife LtdCyprus: reprimand for insurer Eurolife – unsealed dismissal letter delivered to father CyprusEmployee data Reprimand or warning

A courier of the insurer delivered an employee’s dismissal letter unsealed to his parents’ home and, when the father refused to accept it, left it there, so that third parties could read its contents. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) issued a reprimand for breaches of lawfulness, confidentiality and accountability and ordered the delivery procedure for dismissal letters to be revised within one month.

What organisations can take from it

HR letters such as dismissals must be sealed and delivered only to the person concerned – couriers need clear instructions.

Relevance to training and awareness

Confidential delivery of HR correspondence

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a und f, Art. 6, Art. 24 Abs. 1 DSGVO
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Financial services and insurance

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Nov 2024 CMC Certus Management Consultants LtdCyprus: 4,000 EUR against visa service provider CMC Certus – client documents on Scribd CyprusInternational data transfers €4,000

Without informing them, the residence permit consultancy sent a client couple’s marriage certificate and proof of salary to a sister company in Georgia for translation; the documents subsequently appeared publicly on the Scribd platform. The Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection) imposed 2,000 EUR each for an impermissible transfer to a third country and for lack of security measures, as well as a reprimand for insufficient cooperation.

What organisations can take from it

Translation by a group company in a third country is also a data transfer – requiring safeguards, information and confidentiality rules.

Relevance to training and awareness

Passing client documents on to translators and group companies

Authority / court
Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Commissioner for Personal Data Protection)
Area of law
Data protection · International data transfers
Legal basis
Art. 5 Abs. 1 lit. f, Art. 31, Art. 44 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial