Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Data Protection Commission (DPC) 6 cases 60 % · €873.5m
- Central Bank of Ireland 2 cases 20 % · €21.5m
- Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht) 2 cases 20 % ·
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €91m |
| Q4 2024 | 2 | €251m |
| Q1 2025 | 0 | — |
| Q2 2025 | 2 | €530.6m |
| Q3 2025 | 1 | €36,273 |
| Q4 2025 | 2 | €21.5m |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €277,500 |
| Q3 2026 | 1 | €645,000 |
10 cases
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Nov 2025 Coinbase Europe LimitedIreland: 21.5 million EUR against Coinbase Europe – 30 million transactions unchecked €21.5m
In a settlement of 5 November 2025, the Central Bank of Ireland imposed a reprimand and 21,464,734 EUR (after a 30% discount on 30,663,906 EUR) for breaches of transaction monitoring obligations between April 2021 and March 2025: because of configuration errors in the monitoring system, more than 30 million transactions worth over 176 billion EUR – around 31% of all transactions – were not properly monitored over a period of twelve months. The subsequent review took almost three years and led to 2,708 suspicious transaction reports; the High Court confirmed the sanction on 12 January 2026, and it is the Central Bank's first enforcement action in the crypto sector.
Test monitoring rules regularly for complete coverage – a silent configuration error can go undetected for years.
- Authority / court
- Central Bank of Ireland
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Published
- 6 Nov 2025
- Enforcement Action against Coinbase Europe Limited Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Oct 2025 WhatsApp Ireland Limited (Dienst „Channels“) und PinterestWhatsApp (Channels) and Pinterest: designated as ‘exposed to terrorist content’ Order
After both hosting services had received at least two final removal orders from EU authorities within twelve months, Coimisiún na Meán (Ireland’s media and online safety regulator) designated them as exposed to terrorist content under the TCO Regulation. They must take specific protective measures and report on them within three months; the regulator assesses their effectiveness.
Repeated removal orders trigger additional, monitored prevention obligations for platforms – content moderation must be prepared for this.
- Authority / court
- Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Coimisiún na Meán: Further determinations made under Terrorist Content Online Regulation (TCOR) (17.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2025 Swilly Mulroy Credit Union LimitedIreland: small credit union accepted cash from non-members without checks €36,273
Between 2014 and 2021, the credit union solicited cash from persons without an account and accepted 2,329 cash deposits totalling 8.75 million EUR without the required anti-money laundering checks; the board had known about the risk since 2015, and there was no self-reporting. The Central Bank of Ireland imposed a reprimand and 36,273 EUR (after a 30% discount on 51,819 EUR).
Even small cooperative banks must identify cash from non-customers – and would do better to self-report known risks.
Identification for cash deposits by non-customers
- Authority / court
- Central Bank of Ireland
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Criminal Justice (Money Laundering and Terrorist Financing) Act 2010; Credit Union Act 1997
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Liability of senior managers
- The board had known about the risks since 2015 without taking remedial action
- Published
- 2 Jul 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2025 Department of Social Protection (DSP)DPC: 550,000 EUR against Irish social protection ministry over facial matching without legal basis €550,000
For registration for the Public Services Card, the ministry created biometric facial templates of a large part of the population without a sufficiently clear legal basis, with deficient information and an incomplete data protection impact assessment. Ireland's Data Protection Commission (DPC) issued a reprimand, imposed 550,000 EUR and ordered the biometric processing to be stopped within nine months if no valid legal basis is found.
Biometric procedures require a precise statutory basis and a complete impact assessment before they are rolled out widely.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und e, Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 Abs. 7 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Mitigating circumstances
- No deficiencies were found in the technical and organisational security measures.
- Published
- 12 Jun 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 May 2025 TikTok Technology LimitedDPC: 530 million EUR against TikTok over data access from China €530m
TikTok allowed employees in China to access European users' data remotely without assessing and demonstrating that standard contractual clauses and supplementary measures ensured an equivalent level of protection against access by Chinese authorities; it also informed users inadequately. Ireland's Data Protection Commission (DPC) imposed 530 million EUR and ordered that the transfers be brought into compliance or suspended within six months.
Even mere remote access from a third country is a transfer – without a documented transfer impact assessment, fines and a suspension order loom.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 46 Abs. 1, Art. 13 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 2 May 2025
- Irish Data Protection Commission fines TikTok €530 million and orders corrective measures Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2024 Meta Platforms Ireland LimitedIreland: 251 million EUR against Meta over data breach and deficient notification €251m
In 2018, attackers exploited a flaw in the ‘View As’ feature and gained access to around 29 million accounts, of which around 3 million were in the EEA. Ireland's Data Protection Commission (DPC) imposed 8 million EUR (Art. 33(3)) and 3 million EUR (Art. 33(5)) for incomplete notification and documentation, as well as 130 million EUR and 110 million EUR for infringements of data protection by design (Art. 25(1) and (2)).
Make data breach notifications complete, and document every breach internally in a traceable manner.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 33 Abs. 3 und 5, Art. 25 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 17 Dec 2024
- Irish Data Protection Commission fines Meta €251 Million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2024 TikTok, X und Meta (Instagram)TikTok, X and Instagram: Irish regulator requires measures against terrorist content Order
Coimisiún na Meán (Ireland’s media and online safety regulator) determined that the services of TikTok, X and Meta (Instagram) are exposed to terrorist content after they had received at least two final removal orders from EU authorities within twelve months. The providers must take specific measures against the dissemination of terrorist content and report on them.
Platforms should record removal orders centrally – from the second within twelve months, additional obligations monitored by the regulator loom.
- Authority / court
- Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Coimisiún na Meán: Determination made under Terrorist Content Online Regulation (TCOR) (13.11.2024) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Sep 2024 Meta Platforms Ireland LimitedIreland: 91 million EUR against Meta over plaintext passwords €91m
Meta stored users' passwords unencrypted in plaintext in internal systems and reported this to Ireland's Data Protection Commission (DPC) in March 2019. The DPC found infringements of the security obligations (Art. 5(1)(f), Art. 32(1)) and of the notification and documentation obligations (Art. 33(1) and (5)), and additionally issued a reprimand.
Never store or log passwords in plaintext – not even in internal systems.
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 und 5
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- According to the DPC, the passwords were not disclosed to external third parties.
- Published
- 27 Sep 2024
- Irish Data Protection Commission fines Meta Ireland €91 million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link