Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Prezes Urzędu Ochrony Danych Osobowych (UODO) 11 cases 73 % · €3.04m
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK) 4 cases 27 % · €34.2m
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
- Financial services and insurance 4 cases 27 % · €1.33m
- Retail and e-commerce 4 cases 27 % · €34.2m
- Media and online platforms 2 cases 13 % · €1.41m
- Construction and real estate 1 case 7 % · €1,135
- Healthcare 1 case 7 % · €2,669
- Food and agriculture 1 case 7 % · €55,102
- Public sector 1 case 7 % · €4,938
- Transport, logistics and shipping 1 case 7 % · €232,208
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €23,362 |
| Q1 2024 | 2 | €354,397 |
| Q2 2024 | 1 | €55,102 |
| Q3 2024 | 1 | €950,490 |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €13,604 |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €2,669 |
| Q4 2025 | 2 | €24.8m |
| Q1 2026 | 4 | €10.4m |
| Q2 2026 | 2 | €710,989 |
| Q3 2026 | 0 | — |
15 cases
26 Jun 2026 Neonet S.A.Neonet: 3 million PLN over false delivery and availability information on Allegro €709,854
On its Allegro account, the electronics retailer promised dispatch within 24 hours even for goods not in stock and did not inform customers in good time of delays or unavailability. UOKiK imposed a fine of 3,043,000 PLN; the decision is not final.
Link delivery and availability information to stock levels; in the event of delays, inform customers immediately.
Availability and delivery information on marketplaces
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Verletzung kollektiver Verbraucherinteressen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 26 Jun 2026
Original amount 3,043,000 PLN, converted at the ECB reference rate of 26 Jun 2026.
- Empty promises from Neonet – decision by the President of UOKiK Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified €1,135
Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.
Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.
Recognising misdirected mail as a data breach – including at service providers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.
- UODO, Decyzja DKN.5131.16.2025 vom 07.04.2026 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jan 2026 Zalando SEZalando: around 31 million PLN for missing 30-day lowest prices on discounts €7.34m
Zalando did not display the lowest price of the previous 30 days for discounts, manipulated reference prices to make reductions appear larger and did not present the mandatory information consistently at all stages of the purchasing process. Poland's Office of Competition and Consumer Protection (UOKiK) imposed a fine of 30,945,000 PLN; the decision is not final.
Discount information must be identical and correct on all pages of a shop – listing, product page, shopping basket.
Presentation of discounts in online shops
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 14 Jan 2026
Original amount 30,945,000 PLN, converted at the ECB reference rate of 14 Jan 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jan 2026 Whaleco Technology Limited (Temu)Temu: almost 6 million PLN over changing reference prices and discount labelling €1.4m
The operator of the Temu interface omitted the 30-day lowest price or stated it incorrectly, labelled promotions inconsistently and changed reference prices from day to day without the actual price changing. UOKiK imposed a fine of 5,910,900 PLN; the decision is not final.
Reference prices that shift daily without any real price change are a misleading staging of discounts.
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 14 Jan 2026
Original amount 5,910,900 PLN, converted at the ECB reference rate of 14 Jan 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent €232,208
The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.
Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Mitigating circumstances
- During the proceedings the function was made independent and placed directly under the management board.
- Published
- 26 Jan 2026
Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.
- Kara dla Poczty Polskiej za brak zapewnienia niezależności sprawowania funkcji IOD Press release of an authority
- Decyzja DKN.5131.4.2025 z 2 stycznia 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Dec 2025 Jeronimo Martins Polska (Biedronka)Biedronka: almost 105 million PLN over undisclosed conditions for "100 % back" €24.7m
The supermarket chain advertised promotions such as "Special Wednesday" with "100 % money back as a voucher", but did not state restrictions concerning product categories, minimum spend and use of the vouchers in radio, app and in-store advertising, only on the receipt, the website or in-store notices. UOKiK imposed a fine of 104,722,016 PLN; the decision is not final.
State the essential restrictions of a promotion in the advertising itself, not just on the receipt.
Complete promotion terms in advertising
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Verletzung kollektiver Verbraucherinteressen (irreführende Werbung durch Unterlassen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Culpability
- intentional
- Published
- 4 Dec 2025
Original amount 104,722,016 PLN, converted at the ECB reference rate of 4 Dec 2025.
- When a promotion fails to mention what is important – nearly PLN 105 million in fines for Biedronka Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified €4,938
In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.
Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.
Checking postal mailings; notifying data breaches involving identification numbers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.
- UODO, Decyzja DKN.5131.17.2024 vom 23.10.2025 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN €2,669
For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.
This also applies in small practices and companies: management cannot be its own data protection officer.
Role and independence of the data protection officer; release of patient records
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- An independent external data protection officer was appointed in July 2024.
- Published
- 29 Sep 2025
Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.
- Prezes firmy nie może być jednocześnie IOD. Kara dla spółki Specer Press release of an authority
- Decyzja DKN.5131.7.2025 z 12 września 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication €13,604
Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.
Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.
Protection of data subjects in press reports; encryption of storage media
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Media and online platforms
- Published
- 11 Mar 2025
Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.
- Kara dla Polskiego Radia Szczecin za brak procedur chroniących prawa bohaterów publikacji Press release of an authority
- WSA oddalił skargę na decyzję Prezesa UODO w sprawie kary dla Radia Szczecin Press release of an authority
- Decyzja DKN.5112.10.2024 z 6 marca 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing €950,490
In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.
Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.
Misdirected documents and notification of data subjects
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 9 Sep 2024
Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.
- Kara dla mBanku za niezawiadomienie osób poszkodowanych wyciekiem danych Press release of an authority
- Decyzja DKN.5131.1.2024 z 20 sierpnia 2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2024 Res-Gastro M. Gaweł Sp. k.UODO: 238,345 PLN against catering company after loss of an unencrypted USB stick €55,102
An employee of the catering company lost a USB stick containing unencrypted data on a colleague, including PESEL number, passport data and salary. The risk analysis had not provided for the mere loss of data carriers, encryption was left to employees with only an instruction video, and the effectiveness of the measures was not tested; the President of the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych, UODO) imposed 238,345 PLN (decision DKN.5131.29.2023, not final).
Encryption of portable data carriers must be technically enforced – a training video alone impermissibly shifts responsibility onto employees.
Handling portable data carriers and encryption
Missing or inadequate training played a role in the decision.
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 5 Abs. 2, Art. 24 Abs. 1, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Self-reporting of the incident and cooperation in the proceedings substantially reduced the fine.
- Published
- 17 May 2024
Original amount 238,345 PLN, converted at the ECB reference rate of 29 Apr 2024.
- Prawie 240 tys. zł kary dla firmy, której pracownik zgubił pendrive z danymi osobowymi Press release of an authority
- Decyzja DKN.5131.29.2023 z 29 kwietnia 2024 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported €336,066
A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.
Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.
Risk assessment and notification of data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
- Published
- 2 Apr 2024
Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.59.2022 vom 12.03.2024 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years €18,331
The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.
Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.
Recognising misdirected mail and reporting it internally
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 2 Apr 2024
Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.
- UODO: Troska o dane osób ważniejsza niż interes administratora (02.04.2024) Press release of an authority
- UODO, Decyzja DKN.5131.28.2023 vom 12.03.2024 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator €23,362
The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.
Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.
Avoiding misdirected e-mails; reporting data breaches
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- intentional
- Repeat case
- yes
- Published
- 23 Nov 2023
Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.
- UODO: Kolejna administracyjna kara pieniężna za niezgłoszenie naruszenia ochrony danych osobowych (23.11.2023) Press release of an authority
- UODO, Decyzja DKN.5131.55.2022 vom 18.10.2023 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link