Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUDenmark Clear all filters
10cases from 1 jurisdiction
€298,149Total of monetary amounts (6 cases with an amount)
€200,986Largest single case: IDdesign A/S
€18,430Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Vestre Landsret (auf Anzeige der Datatilsynet) €200,986 67 % · 1 case
  2. Retten i Glostrup (auf Anzeige der Datatilsynet) €46,909 16 % · 1 case
  3. Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet €34,834 12 % · 3 cases
  4. Københavns Byret (auf Anzeige der Datatilsynet) €10,057 3 % · 1 case
  5. Dänisches Gericht auf Anzeige der Datatilsynet €5,363 2 % · 1 case
  6. Konkurrencerådet (Danish Competition Council) — 0 % · 2 cases
  7. Datatilsynet — 0 % · 1 case

What for?

by area of law

All areas of law

  1. Data protection €298,149 100 % · 8 cases
  2. Competition law — 0 % · 1 case
  3. AI and digital regulation — 0 % · 1 case

Who?

by sector

All sectors

  1. Retail and e-commerce €200,986 67 % · 1 case
  2. Construction and real estate €46,909 16 % · 1 case
  3. Public sector €26,803 9 % · 2 cases
  4. Healthcare €10,057 3 % · 1 case
  5. Other €8,031 3 % · 1 case
  6. Telecoms, IT and software €5,363 2 % · 1 case
  7. Media and online platforms — 0 % · 3 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€26,803
Q3 20240—
Q4 20244€62,329
Q1 20250—
Q2 20250—
Q3 20251€200,986
Q4 20250—
Q1 20261€8,031
Q2 20262—
Q3 20261—

10 cases

26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants DenmarkAbuse of market power Order

In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.

What organisations can take from it

Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
Competition law · Abuse of market power
Legal basis
Konkurrenceloven; AEUV Art. 102
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Published
26 Aug 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked DenmarkPlatform obligations Order

After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.

What organisations can take from it

Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.

Authority / court
Konkurrencerådet (Danish Competition Council)
Area of law
AI and digital regulation · Platform obligations
Legal basis
Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
Action
Order
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
24 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years DenmarkData protection Fine

The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.

What organisations can take from it

‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Mitigating circumstances
Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order DenmarkData subject rights and transparency €8,031

Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.

What organisations can take from it

Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.

Relevance to training and awareness

Handling access requests (Art. 15 GDPR)

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
Action
Fine
Status of proceedings
final
Sector
Other

Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Sep 2025 IDdesign A/SIDdesign: High Court raises GDPR fine to 1.5 million DKK – group turnover counts DenmarkData protection €200,986

The furniture retailer had stored data of around 385,000 customers in a legacy system without retention periods. The district court had imposed 100,000 DKK; following a referral to the CJEU on whether the fine is to be calculated on the basis of the turnover of the entire group, the High Court increased the fine to 1.5 million DKK.

What organisations can take from it

Retention periods also apply to legacy systems in individual branches – and the group turnover counts when setting the fine.

Authority / court
Vestre Landsret (auf Anzeige der Datatilsynet)
Area of law
Data protection
Legal basis
DSGVO Art. 5 Abs. 1 lit. e, Art. 83
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce

Original amount 1,500,000 DKK, converted at the ECB reference rate of 2 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Dec 2024 Danske Shoppingcentre P/SDanske Shoppingcentre: 350,000 DKK for camera above urinal in City2 shopping centre DenmarkVideo surveillance €46,909

Because of vandalism, the operator of the City2 shopping centre had installed cameras in toilet areas; one camera in the men’s toilets also captured the area in front of the urinal despite a black masking, and there were no signs. The court followed the Danish Data Protection Agency (Datatilsynet) and the public prosecutor and imposed 350,000 DKK for breach of the data minimisation principle.

What organisations can take from it

Cameras have virtually no place in toilet and changing areas – masking parts of the image is no substitute for checking the location.

Authority / court
Retten i Glostrup (auf Anzeige der Datatilsynet)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 5 Abs. 1 lit. c; databeskyttelsesloven § 41; tv-overvågningsloven
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate

Original amount 350,000 DKK, converted at the ECB reference rate of 19 Dec 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2024 Lyngby-Taarbæk KommuneLyngby-Taarbæk: police report with proposed fine over missing MFA and legacy accounts DenmarkData breaches and data security Other

At least 1,000 former employees retained access after leaving to the KMD Nexus specialist system containing data on around 30,000 citizens; one former employee viewed 1,022 citizen records. In addition, an unauthorised person used an employee's login credentials for Office services containing information on around 5,000 people – both systems had been accessible from the internet for years without multi-factor authentication. The Danish data protection authority (Datatilsynet) reported the municipality to the police and proposed a fine of 350,000 to 400,000 DKK; the case is still pending before the courts, and no fine has been imposed so far.

What organisations can take from it

Revoke access immediately when employees leave, and protect remote access with multi-factor authentication.

Relevance to training and awareness

Offboarding, access rights and multi-factor authentication

Authority / court
Datatilsynet
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, Art. 32
Action
Other
Status of proceedings
unknown
Sector
Public sector
Published
27 Nov 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2024 Uptime-IT ApSDenmark: 40,000 DKK against IT service provider with unusable backups after ransomware DenmarkData processors €5,363

As processor for a chiropractic practice, the IT service provider had encrypted backups without securing the key; after a ransomware attack in 2020, patient data including health information and CPR numbers could not be restored. The Danish data protection authority (Datatilsynet) reported the company to the police and proposed 50,000 DKK; the court sentenced it to a fine of 40,000 DKK on 12 November 2024.

What organisations can take from it

A backup only counts if restoration is tested regularly – including access to the keys.

Authority / court
Dänisches Gericht auf Anzeige der Datatilsynet
Area of law
Data protection · Data processors
Legal basis
Art. 32 DSGVO; Auftragsverarbeitungsvertrag
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software

Original amount 40,000 DKK, converted at the ECB reference rate of 12 Nov 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops DenmarkData breaches and data security €10,057

The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).

What organisations can take from it

Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.

Relevance to training and awareness

Encryption of mobile devices and phishing defence (multi-factor authentication)

Authority / court
Københavns Byret (auf Anzeige der Datatilsynet)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
Action
Fine
Status of proceedings
final
Sector
Healthcare
Repeat case
yes

Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2024 Hvidovre KommuneHvidovre Kommune: 200,000 DKK after disclosing protected addresses of children to parents DenmarkData breaches and data security €26,803

Following a system change, both parents with custody gained access to letters from the municipal dental care service and automatically received letters containing, in some cases, protected addresses of the children – without any check as to whether the disclosure was permissible. The Danish Data Protection Agency (Datatilsynet) criticised the lack of change management; the municipality accepted a fine notice of 200,000 DKK.

What organisations can take from it

Whenever access rights or automated mailing processes are changed, check in advance who will see which data afterwards.

Relevance to training and awareness

Change management for IT systems holding sensitive data

Authority / court
Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32
Action
Fine
Status of proceedings
final
Sector
Public sector

Original amount 200,000 DKK, converted at the ECB reference rate of 27 May 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial