Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet 3 cases 30 % · €34,834
- Konkurrencerådet (Danish Competition Council) 2 cases 20 % ·
- Dänisches Gericht auf Anzeige der Datatilsynet 1 case 10 % · €5,363
- Datatilsynet 1 case 10 % ·
- Københavns Byret (auf Anzeige der Datatilsynet) 1 case 10 % · €10,057
- Retten i Glostrup (auf Anzeige der Datatilsynet) 1 case 10 % · €46,909
- Vestre Landsret (auf Anzeige der Datatilsynet) 1 case 10 % · €200,986
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | €26,803 |
| Q3 2024 | 0 | — |
| Q4 2024 | 4 | €62,329 |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €200,986 |
| Q4 2025 | 0 | — |
| Q1 2026 | 1 | €8,031 |
| Q2 2026 | 2 | — |
| Q3 2026 | 1 | — |
10 cases
26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants Order
In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.
Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.
- Authority / court
- Konkurrencerådet (Danish Competition Council)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Konkurrenceloven; AEUV Art. 102
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 26 Aug 2026
- KFST – Wolt has abused its dominant position (26.08.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked Order
After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.
Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.
- Authority / court
- Konkurrencerådet (Danish Competition Council)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 24 Jun 2026
- KFST – The Competition Council rules against Meta (24.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years Fine
The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.
‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Mitigating circumstances
- Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.
- Datatilsynet – Gyldendal indstilles til bøde (Opdatering: afgjort 14. april 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Sep 2025 IDdesign A/SIDdesign: High Court raises GDPR fine to 1.5 million DKK – group turnover counts €200,986
The furniture retailer had stored data of around 385,000 customers in a legacy system without retention periods. The district court had imposed 100,000 DKK; following a referral to the CJEU on whether the fine is to be calculated on the basis of the turnover of the entire group, the High Court increased the fine to 1.5 million DKK.
Retention periods also apply to legacy systems in individual branches – and the group turnover counts when setting the fine.
- Authority / court
- Vestre Landsret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 83
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
Original amount 1,500,000 DKK, converted at the ECB reference rate of 2 Sep 2025.
- Datatilsynet – Møbelfirma indstillet til bøde (Opdatering zum Verfahrensausgang) Press release of an authority
- Domsdatabasen – Vestre Landsret SS-364/2021-VLR, Dom 02.09.2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Dec 2024 Danske Shoppingcentre P/SDanske Shoppingcentre: 350,000 DKK for camera above urinal in City2 shopping centre €46,909
Because of vandalism, the operator of the City2 shopping centre had installed cameras in toilet areas; one camera in the men’s toilets also captured the area in front of the urinal despite a black masking, and there were no signs. The court followed the Danish Data Protection Agency (Datatilsynet) and the public prosecutor and imposed 350,000 DKK for breach of the data minimisation principle.
Cameras have virtually no place in toilet and changing areas – masking parts of the image is no substitute for checking the location.
- Authority / court
- Retten i Glostrup (auf Anzeige der Datatilsynet)
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. c; databeskyttelsesloven § 41; tv-overvågningsloven
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
Original amount 350,000 DKK, converted at the ECB reference rate of 19 Dec 2024.
- Datatilsynet – Danske Shoppingcentre indstilles til bøde (mit Ausgang des Verfahrens) Press release of an authority
- Domsdatabasen – Retten i Glostrup SS-9747/2023-GLO, Dom 19.12.2024 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts Other
At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.
Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.
Offboarding, access rights and multi-factor authentication
- Authority / court
- Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 27 Nov 2024
- Datatilsynet anmelder Lyngby-Taarbæk Kommune til politiet Decision of an authority
- Datatilsynet: Bødesager (Lyngby-Taarbæk Kommune unter „Sager, der fortsat verserer“) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware €5,363
As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.
A backup only counts if restoration is tested regularly – including access to the keys.
- Authority / court
- Dänisches Gericht auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO; Auftragsverarbeitungsvertrag
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.
- Databehandler indstillet til bøde (Uptime-IT ApS) Press release of an authority
- Datatilsynet – Bødesager Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops €10,057
The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).
Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.
Encryption of mobile devices and phishing defence (multi-factor authentication)
- Authority / court
- Københavns Byret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Repeat case
- yes
Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.
- Datatilsynet – Kræftens Bekæmpelse indstillet til bøde (Opdatering zum Verfahrensausgang) Press release of an authority
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 Court decision
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 (Status: Endelig) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2024 Hvidovre KommuneHvidovre Kommune: 200,000 DKK after disclosing protected addresses of children to parents €26,803
Following a system change, both parents with custody gained access to letters from the municipal dental care service and automatically received letters containing, in some cases, protected addresses of the children – without any check as to whether the disclosure was permissible. The Danish Data Protection Agency (Datatilsynet) criticised the lack of change management; the municipality accepted a fine notice of 200,000 DKK.
Whenever access rights or automated mailing processes are changed, check in advance who will see which data afterwards.
Change management for IT systems holding sensitive data
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
Original amount 200,000 DKK, converted at the ECB reference rate of 27 May 2024.
- Datatilsynet – Hvidovre Kommune indstilles til bøde (Opdatering: afgjort 27. maj 2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link