Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) 7 cases 64 % · €4.03m
- Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) 3 cases 27 % · €1.56m
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA) 1 case 9 % · €110,000
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
- Retail and e-commerce 3 cases 27 % · €1.53m
- Energy and utilities 1 case 9 % · €110,000
- Financial services and insurance 1 case 9 % · €120,000
- Healthcare 1 case 9 % · €25,000
- Food and agriculture 1 case 9 % · €127,314
- Public sector 1 case 9 % · €10,000
- Other 1 case 9 % · €80,000
- Telecoms, IT and software 1 case 9 % · €700,000
- Transport, logistics and shipping 1 case 9 % · €3m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €3m |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €120,000 |
| Q2 2025 | 2 | €827,314 |
| Q3 2025 | 0 | — |
| Q4 2025 | 1 | €80,000 |
| Q1 2026 | 2 | €492,498 |
| Q2 2026 | 3 | €1.16m |
| Q3 2026 | 1 | €25,000 |
11 cases
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage €95,000
A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.
Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.
Handling video footage and access requests
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Απόφαση 10/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Jun 2026 VF Hellas Ενδυμάτων Ε.Π.Ε. (VF Hellas, Tochter der VF Corporation)Greece: 954,485 EUR against VF Hellas for banning price comparison and Google Ads €954,485
The importer and wholesaler of the Vans, Eastpak and The North Face brands contractually prohibited its retailers from using price comparison portals and search engine advertising (in particular Google Ads). The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) regarded this as a hardcore restriction in online sales and, in a settlement procedure (Decision 913/2026), set a reduced fine of 954,485 EUR; date = press release.
Prohibiting retailers from using price comparison sites or search engine advertising is a hardcore restriction – distribution agreements should regularly undergo competition law review.
Competition-law-compliant design of dealer agreements in online sales
- Authority / court
- Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 1 Gesetz 3959/2011; Art. 101 AEUV; Art. 4 lit. e VO (EU) 2022/720
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Settlement procedure (Diettheti Diaforon) with fine reduction
- Published
- 3 Jun 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2026 ΚΟΜΠΑ Μονοπρόσωπη Ε.Π.Ε. und HAPPY DOG Α.Ε. ΖωοτροφώνGreece: around 482,500 EUR against pet food importers for resale price maintenance €482,498
Two importers of dog and cat food monitored their retailers’ consumer prices on price comparison portals and asked them to adjust them to their price lists; the retailers complied. In a settlement procedure (Decision 901/2026), the Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) imposed 387,498 EUR on KOMPA and 95,000 EUR on Happy Dog; the case began with a tip-off via the authority’s anonymous whistleblowing platform.
Recommended prices must not be enforced through monitoring and calls to retailers – and authorities’ whistleblowing channels make such practices visible.
Prohibition of resale price maintenance in sales
- Authority / court
- Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 1 Gesetz 3959/2011; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Settlement procedure with reduced fines
- Published
- 6 Mar 2026
- Δελτίο Τύπου – Πρόστιμα σε επιχειρήσεις προμήθειας ζωοτροφών για ζώα συντροφιάς Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log €10,000
In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.
Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.
Confidential handling of employees’ health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Απόφαση 1/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier €80,000
Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).
Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.
Checking consent before telemarketing
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5, 6, 7, 29, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Απόφαση 44/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2025 Vodafone – Πάναφον Α.Ε.Ε.Τ.Greece: 700,000 EUR against Vodafone over prepaid numbers registered in other people’s names €700,000
Using a customer’s identity card, an unknown person registered at least 15 prepaid numbers in her name at a Vodafone partner shop. By Decision 27/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed on Vodafone 350,000 EUR (processing by a processor, Art. 28), 200,000 EUR (accuracy of data) and 150,000 EUR under the Greek ePrivacy law, and issued a reprimand requiring the company to secure the activation of new numbers technically within three months (for example by sending an SMS to the existing customer); the shop (Karampelas K. & Sia E.E., ‘DS Phone’) received 40,000 EUR.
Identity checks in branch and partner distribution are a data protection issue – providers are liable for weak processes of their distribution partners.
Identity verification when concluding contracts in partner distribution
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 28 Abs. 1 und 3 DSGVO; Art. 12 Gesetz 3471/2006
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Απόφαση 27/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 May 2025 Ατλάντα Αντιπροσωπείαι – Διανομαί Α.Ε.Greece: 127,314 EUR against breakfast cereal distributor Atlanta for resale price maintenance €127,314
From March to August 2021, the distribution partner for breakfast cereals set resale prices, which retailers and supermarket chains largely adopted. The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) accepted the settlement proposal and, by Decision 878/2025, imposed a reduced fine of 127,314 EUR; date = press release.
Even short periods of imposing prices on retailers carry fines – sales teams must know the line between recommendation and requirement.
Resale price maintenance towards retailers
- Authority / court
- Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 1 Gesetz 3959/2011; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Settlement procedure with fine reduction
- Published
- 2 May 2025
- Δελτίο Τύπου – Πρόστιμο σε επιχείρηση η οποία διακινεί δημητριακά πρωινού κατόπιν Διαδικασίας Διευθέτησης Διαφορών Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jan 2025 Εθνική Τράπεζα της Ελλάδος Α.Ε. (National Bank of Greece)Greece: 120,000 EUR against National Bank of Greece after misdirected payment via mobile number €120,000
An IRIS transfer made by mobile number via the bank’s app ended up with an uninvolved customer instead of the intended recipient because the number had been assigned incorrectly. By Decision 3/2025, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) imposed 100,000 EUR for inaccurate data, insufficient security, lack of data protection by design and failure to notify the data breach, as well as 20,000 EUR for breach of the right of access.
Even a single misdirected payment can be a notifiable data breach – customer complaints must be assessed internally as a possible incident.
Recognising and reporting data breaches
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. d und f, Art. 15, 25, 32, 33, 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Απόφαση 3/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Feb 2024 Ελληνικά Ταχυδρομεία Α.Ε. (ΕΛΤΑ, Hellenic Post)Greece: almost 3 million EUR against Hellenic Post after ransomware attack €3m
In a cyber attack in 2022, attackers obtained administrator access, disabled protective software, encrypted files and later published stolen data on the darknet. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the postal company had not implemented the necessary technical and organisational measures or its own security policy and, by Decision 10/2024, imposed 2,995,140 EUR.
A security policy on paper offers no protection – what is examined is whether it has actually been implemented.
Cyber defence, handling of administrator accounts
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Επιβολή προστίμου σε εταιρία για μη ορθή τήρηση τεχνικών και οργανωτικών μέτρων (Απόφαση 10/2024) Decision of an authority
- Απόφαση 10/2024 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link