Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Europäische Kommission 14 cases 70 % · €3.79bn
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA) 3 cases 15 % · €5.72m
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23 1 case 5 % ·
- Gerichtshof der Europäischen Union, Rs. C-340/21 1 case 5 % ·
- Gerichtshof der Europäischen Union, Rs. C-413/23 P 1 case 5 % ·
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
- Retail and e-commerce 4 cases 20 % · €1.08bn
- Media and online platforms 4 cases 20 % · €320m
- Financial services and insurance 3 cases 15 % · €5.72m
- Telecoms, IT and software 3 cases 15 % · €1.39bn
- Automotive 2 cases 10 % · €530m
- Chemicals and pharmaceuticals 2 cases 10 % · €476m
- Public sector 2 cases 10 % ·
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 2 | €13.4m |
| Q1 2024 | 1 | €2.2m |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €462.6m |
| Q1 2025 | 1 | — |
| Q2 2025 | 5 | €1.49bn |
| Q3 2025 | 1 | — |
| Q4 2025 | 4 | €192m |
| Q1 2026 | 1 | €1.37m |
| Q2 2026 | 2 | €202.1m |
| Q3 2026 | 2 | €1.44bn |
20 cases
23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering €890m
In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.
Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Jul 2026
- Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
- IP/26/1670: Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products €550m
AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.
The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
- Published
- 20 Jul 2026
- Commission fines AliExpress €550 million for breaching the Digital Services Act Press release of an authority
- IP/26/1654: Commission fines AliExpress €550 million for breaching the Digital Services Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR €2.15m
The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.
Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – Moody's Deutschland GmbH (ESMA43-857238790-2075) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products €200m
Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.
Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 28 May 2026
- Commission fines Temu €200 million for breaching the Digital Services Act Press release of an authority
- IP/26/1178 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR €1.37m
The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.
Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – REGIS-TR S.A. (ESMA43-857238790-1634) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Exide, FET (inkl. Elettra), Rombat, EUROBAT (Clarios Kronzeuge)EU: 72 million EUR against starter battery manufacturers and the association EUROBAT €72m
From 2005 to 2017, the manufacturers of automotive starter batteries agreed, with the help of the association EUROBAT, to publish jointly calculated lead surcharges (EUROBAT premiums) and to use them in price negotiations with carmakers. Fines: Exide 30 million EUR, Rombat 20.218 million EUR, Elettra 15.594 million EUR, FET 6.11 million EUR, EUROBAT 125,000 EUR; Clarios escaped a fine as leniency applicant.
Suppliers may pass on raw material surcharges individually, but must never fix them in an industry-wide coordinated manner via association indices.
Joint raw material surcharges among competitors via association indices
- Authority / court
- Europäische Kommission
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV, Art. 53 EWR-Abkommen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Mitigating circumstances
- Leniency programme (Clarios 100 %, FET 50 %, Rombat 30 %); reduction for inability to pay for one company; payment in instalments
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository €120m
First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.
Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 5 Dec 2025
- Commission fines X €120 million under the Digital Services Act Press release of an authority
- IP/25/2934 (Druckfassung) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository Order
Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.
Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
- Action
- Order
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB —
The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.
Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-413/23 P
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Verordnung (EU) 2018/1725 (Informationspflicht)
- Status of proceedings
- under appeal
- Sector
- Public sector
- Published
- 4 Sep 2025
- Press Release No 107/25: Judgment of the Court in Case C-413/23 P EDPS v SRB Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2025 AliExpressAliExpress: DSA commitments on illegal products and trader transparency made binding Order
The European Commission declared binding commitments by AliExpress relating, among other things, to the detection of illegal products such as medicines and food supplements (including via hidden links and affiliate programmes), the notice and complaint system, the transparency of advertising and recommender systems, the traceability of traders and data access for researchers; an independent monitoring trustee oversees implementation. In parallel, it made a preliminary finding of a breach of the obligation to carry out a risk assessment.
Marketplaces must systematically detect illegal products – including where they are offered via detours such as affiliate links.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Art. 71 Digital Services Act (Verordnung (EU) 2022/2065)
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jun 2025 Delivery Hero SE, Glovoapp23 SAEU: 329 million EUR against Delivery Hero and Glovo – first labour market cartel €329m
From July 2018 to July 2022, Delivery Hero and Glovo agreed a mutual no-poach arrangement, exchanged commercially sensitive information and allocated national markets; this was facilitated by Delivery Hero's minority stake in Glovo. Fines: Delivery Hero 223.285 million EUR, Glovo 105.732 million EUR (settlement procedure, 10 % reduction).
No-poach clauses and information flows from stakes in competitors are high-risk under competition law and must be shielded by clean-team rules.
No-poach agreements and information exchange via minority stakes
- Authority / court
- Europäische Kommission
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV, Art. 53 EWR-Abkommen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Mitigating circumstances
- Settlement procedure (10 % reduction)
- Kommission verhängt Geldbußen in Höhe von 329 Mio. EUR gegen Delivery Hero und Glovo (IP/25/1356) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Apr 2025 AppleDMA: 500 million EUR against Apple over anti-steering in the App Store €500m
In one of the first non-compliance decisions under the Digital Markets Act (DMA), the European Commission found that Apple prevents app developers from informing customers free of charge about cheaper offers outside the App Store and steering them there. In addition to a fine of 500 million EUR, the removal of the restrictions within 60 days was ordered, failing which periodic penalty payments may be imposed.
Gatekeepers must allow business users to communicate freely with their customers; technical or commercial hurdles are treated as circumvention.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Apr 2025
- Commission finds Apple and Meta in breach of the Digital Markets Act Press release of an authority
- IP/25/1085 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Apr 2025 MetaDMA: 200 million EUR against Meta over ‘consent or pay’ model €200m
Between March and November 2024, Meta offered users of Facebook and Instagram only the choice between consenting to the combination of their data for personalised advertising and a paid subscription. The European Commission saw this as a breach of the obligation under the Digital Markets Act (DMA) to offer an equivalent, less data-intensive alternative, and imposed 200 million EUR.
A binary ‘consent or pay’ is not sufficient where the law requires an equivalent option involving less data processing.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Einwilligung zur Datenzusammenführung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 23 Apr 2025
- Commission finds Apple and Meta in breach of the Digital Markets Act Press release of an authority
- IP/25/1085 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2025 BMW, Ford, Honda, Hyundai/Kia, Jaguar Land Rover, Mazda, Mitsubishi, Opel/GM, Renault/Nissan, Stellantis, Suzuki, Toyota, Volkswagen, Volvo, ACEA (Mercedes-Benz Kronzeuge)EU: 458 million EUR against carmakers and ACEA over end-of-life vehicle recycling cartel €457.9m
The Commission imposed fines of around 458 million EUR on 15 carmakers and the association ACEA. From 2002 to 2017, they had agreed not to pay dismantlers for recycling end-of-life vehicles and not to advertise recycling rates or recycled content; ACEA organised the meetings. Mercedes-Benz received full immunity as leniency applicant, and all parties reached a settlement (10 % reduction).
Agreements on purchasing terms or on refraining from advertising claims are also cartels – association meetings require antitrust supervision.
Agreements in association bodies; refraining from purchasing or advertising can also be a cartel
- Authority / court
- Europäische Kommission
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV, Art. 53 EWR-Abkommen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Employees
- 10,000 or more
- Mitigating circumstances
- Leniency programme (Mercedes-Benz 100 %, Stellantis/Opel 50 %, Mitsubishi 30 %, Ford 20 %), 10 % settlement reduction, lesser involvement of Honda, Mazda, Mitsubishi, Suzuki
- Commission fines car manufacturers and association €458 million over end-of-life vehicles recycling cartel (IP/25/881) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Mar 2025 AppleApple: Commission sets out specific interoperability obligations for iOS by DMA decision Order
In two specification decisions under the Digital Markets Act, the European Commission set out which interoperability measures Apple must take: access for manufacturers of connected devices to nine iOS features (such as notifications on smartwatches, peer-to-peer Wi-Fi, NFC, pairing) and a more transparent and faster procedure for developers’ interoperability requests.
Gatekeepers must actively open interfaces – anyone handling third-party requests sluggishly risks detailed regulatory requirements.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Digital Markets Act (Verordnung (EU) 2022/1925): Interoperabilitätspflicht, Spezifizierungsbeschlüsse
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Oct 2024 Teva Pharmaceutical Industries (Teva-Gruppe)EU: 462.6 million EUR against Teva for patent misuse and disparaging a competing medicine €462.6m
Teva abused its dominant position for the MS medicine Copaxone: it artificially extended patent protection by filing staggered divisional applications with the EPO and strategically withdrawing them, and spread misleading statements about an authorised competing product among physicians and decision-makers. Seven Member States were affected over periods of four to nine years.
Communications by sales representatives and medical affairs about competing products must be substantiated and objective; patent strategies of dominant companies require competition law review.
Disparaging statements about competing products to healthcare professionals
- Authority / court
- Europäische Kommission
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 102 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Chemicals and pharmaceuticals
- Employees
- 10,000 or more
- Commission fines Teva €462.6 million over misuse of the patent system and disparagement (IP/24/5581) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2024 Scope Ratings GmbHScope Ratings: conflicts of interest not identified and disclosed – 2.2 million EUR €2.2m
The Berlin-based credit rating agency lacked adequate procedures, internal controls and organisational arrangements to deal with conflicts of interest, did not disclose a potential conflict and concealed ancillary services it had provided to a rated entity. ESMA found negligent infringements and imposed fines of 2,197,500 EUR.
Systematically record and disclose ancillary services for customers whom you are at the same time rating or auditing.
Identifying and disclosing conflicts of interest
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Anhang III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Published
- 22 Mar 2024
- Decision of the Board of Supervisors – Scope Ratings GmbH (ESMA43-1868696574-770) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Dec 2023 Natsionalna agentsia za prihodite (NAP, bulgarische Steuerbehörde)CJEU: after hacker attack, Bulgaria's tax authority must prove adequate security —
Following a cyber attack in 2019, data on millions of people from the IT system of the Bulgarian tax authority (Natsionalna agentsia za prihodite, NAP) was published on the internet. The Court of Justice of the European Union (Case C-340/21) ruled that the controller must prove the adequacy of its protective measures, can be liable even for attacks by third parties, and that the mere fear of misuse of data can constitute non-material damage.
After an attack, the company bears the burden of proving adequate security – documenting the measures protects against liability.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-340/21
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 24, Art. 32, Art. 82
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 14 Dec 2023
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Oct 2023 Alkaloids of Australia, Alkaloids Corporation, Boehringer, Linnea, Transo-Pharm (C2 PHARMA Kronzeuge)EU: 13.4 million EUR against pharmaceutical ingredient cartel (SNBB for Buscopan) €13.4m
From 2005 to 2019, six manufacturers and traders of the active ingredient SNBB (the base substance for Buscopan and generics) fixed minimum prices, allocated quotas and exchanged sensitive information. This was the first cartel concerning an active pharmaceutical ingredient that the Commission has sanctioned; C2 PHARMA received full immunity, and all parties reached a settlement.
Even small niche markets for active ingredients are in the spotlight – contacts with competitors about prices or volumes are off-limits.
Price and quota agreements in the trade in active ingredients
- Authority / court
- Europäische Kommission
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV, Art. 53 EWR-Abkommen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Chemicals and pharmaceuticals
- Mitigating circumstances
- Leniency programme (C2 PHARMA 100 %, Transo-Pharm 50 %, Linnea 30 %), 10 % settlement reduction
- Commission fines pharma companies €13,4 million in antitrust cartel settlement (IP/23/5104) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link