Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUPoland Clear all filters
15cases from 1 jurisdiction
€37.2mTotal of monetary amounts
€24.7mLargest single case: Jeronimo Martins Polska (Biedronka)
€232,208Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€23,362
Q1 20242€354,397
Q2 20241€55,102
Q3 20241€950,490
Q4 20240—
Q1 20251€13,604
Q2 20250—
Q3 20251€2,669
Q4 20252€24.8m
Q1 20264€10.4m
Q2 20262€710,989
Q3 20260—

15 cases

26 Jun 2026 Neonet S.A.Neonet: 3 million PLN over false delivery and availability information on Allegro PolandInformation duties in online retail €709,854

On its Allegro account, the electronics retailer promised dispatch within 24 hours even for goods not in stock and did not inform customers in good time of delays or unavailability. UOKiK imposed a fine of 3,043,000 PLN; the decision is not final.

What organisations can take from it

Link delivery and availability information to stock levels; in the event of delays, inform customers immediately.

Relevance to training and awareness

Availability and delivery information on marketplaces

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
26 Jun 2026

Original amount 3,043,000 PLN, converted at the ECB reference rate of 26 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified PolandIncident reporting obligations €1,135

Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.

What organisations can take from it

Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.

Relevance to training and awareness

Recognising misdirected mail as a data breach – including at service providers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Construction and real estate

Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis PolandData subject rights and transparency €1.4m

Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.

What organisations can take from it

Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.

Relevance to training and awareness

Copying identity documents and data minimisation

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
Action
Fine
Status of proceedings
final
Sector
Media and online platforms
Published
16 Mar 2026

Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2026 Zalando SEZalando: around 31 million PLN for missing 30-day lowest prices on discounts PolandMisleading advertising and pricing €7.34m

Zalando did not display the lowest price of the previous 30 days for discounts, manipulated reference prices to make reductions appear larger and did not present the mandatory information consistently at all stages of the purchasing process. Poland's Office of Competition and Consumer Protection (UOKiK) imposed a fine of 30,945,000 PLN; the decision is not final.

What organisations can take from it

Discount information must be identical and correct on all pages of a shop – listing, product page, shopping basket.

Relevance to training and awareness

Presentation of discounts in online shops

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
14 Jan 2026

Original amount 30,945,000 PLN, converted at the ECB reference rate of 14 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Jan 2026 Whaleco Technology Limited (Temu)Temu: almost 6 million PLN over changing reference prices and discount labelling PolandMisleading advertising and pricing €1.4m

The operator of the Temu interface omitted the 30-day lowest price or stated it incorrectly, labelled promotions inconsistently and changed reference prices from day to day without the actual price changing. UOKiK imposed a fine of 5,910,900 PLN; the decision is not final.

What organisations can take from it

Reference prices that shift daily without any real price change are a misleading staging of discounts.

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
14 Jan 2026

Original amount 5,910,900 PLN, converted at the ECB reference rate of 14 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent PolandData protection €232,208

The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.

What organisations can take from it

Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Employees
10,000 or more
Repeat case
yes
Mitigating circumstances
During the proceedings the function was made independent and placed directly under the management board.
Published
26 Jan 2026

Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

4 Dec 2025 Jeronimo Martins Polska (Biedronka)Biedronka: almost 105 million PLN over undisclosed conditions for "100 % back" PolandMisleading advertising and pricing €24.7m

The supermarket chain advertised promotions such as "Special Wednesday" with "100 % money back as a voucher", but did not state restrictions concerning product categories, minimum spend and use of the vouchers in radio, app and in-store advertising, only on the receipt, the website or in-store notices. UOKiK imposed a fine of 104,722,016 PLN; the decision is not final.

What organisations can take from it

State the essential restrictions of a promotion in the advertising itself, not just on the receipt.

Relevance to training and awareness

Complete promotion terms in advertising

Authority / court
Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Verletzung kollektiver Verbraucherinteressen (irreführende Werbung durch Unterlassen)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Culpability
intentional
Published
4 Dec 2025

Original amount 104,722,016 PLN, converted at the ECB reference rate of 4 Dec 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified PolandIncident reporting obligations €4,938

In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.

What organisations can take from it

Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.

Relevance to training and awareness

Checking postal mailings; notifying data breaches involving identification numbers

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Public sector

Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN PolandData protection €2,669

For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.

What organisations can take from it

This also applies in small practices and companies: management cannot be its own data protection officer.

Relevance to training and awareness

Role and independence of the data protection officer; release of patient records

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
An independent external data protection officer was appointed in July 2024.
Published
29 Sep 2025

Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Mar 2025 Polskie Radio – Regionalna Rozgłośnia w Szczecinie „Radio Szczecin” S.A.Polskie Radio Szczecin: 56,824 PLN for lack of data protection review before publication PolandData breaches and data security €13,604

Following a report through which a minor victim became identifiable, an inspection found that the broadcaster had no risk analysis for editorial work, no rules for checking personal data before publication and no encryption of mobile storage media. Poland’s data protection authority (UODO) imposed 56,824 PLN; the Warsaw Administrative Court dismissed the action on 18 March 2026.

What organisations can take from it

Newsrooms need a data protection review before publication – the media privilege does not replace technical and organisational measures.

Relevance to training and awareness

Protection of data subjects in press reports; encryption of storage media

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO (DKN.5112.10.2024)
Action
Fine
Status of proceedings
under appeal
Sector
Media and online platforms
Published
11 Mar 2025

Original amount 56,824 PLN, converted at the ECB reference rate of 6 Mar 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Aug 2024 mBank S.A.mBank: 4.05 million PLN for failing to inform customers after misdirected mailing PolandData breaches and data security €950,490

In 2022, an employee of a processor accidentally sent customer documents containing PESEL numbers, identity document, income and credit data to another financial institution; the envelope was returned opened. Despite a notice from the authority, the bank did not notify the data subjects because the recipient was ‘trustworthy’; Poland’s data protection authority (UODO) imposed 4,053,173 PLN and ordered the notification.

What organisations can take from it

Whether data subjects must be informed depends on the risk to them – not on how trustworthy the wrong recipient appears.

Relevance to training and awareness

Misdirected documents and notification of data subjects

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 34 Abs. 1 und 2 DSGVO (DKN.5131.1.2024)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
9 Sep 2024

Original amount 4,053,173 PLN, converted at the ECB reference rate of 20 Aug 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Apr 2024 Res-Gastro M. Gaweł Sp. k.UODO: 238,345 PLN against catering company after loss of an unencrypted USB stick PolandData breaches and data security €55,102

An employee of the catering company lost a USB stick containing unencrypted data on a colleague, including PESEL number, passport data and salary. The risk analysis had not provided for the mere loss of data carriers, encryption was left to employees with only an instruction video, and the effectiveness of the measures was not tested; the President of the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych, UODO) imposed 238,345 PLN (decision DKN.5131.29.2023, not final).

What organisations can take from it

Encryption of portable data carriers must be technically enforced – a training video alone impermissibly shifts responsibility onto employees.

Relevance to training and awareness

Handling portable data carriers and encryption

Missing or inadequate training played a role in the decision.

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 5 Abs. 2, Art. 24 Abs. 1, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Mitigating circumstances
Self-reporting of the incident and cooperation in the proceedings substantially reduced the fine.
Published
17 May 2024

Original amount 238,345 PLN, converted at the ECB reference rate of 29 Apr 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Santander Bank Polska S.A.Santander Bank Polska: 1.44 million PLN – stolen customer documents not reported PolandIncident reporting obligations €336,066

A courier consignment containing bank documents (including PESEL numbers, account numbers, login credentials) was stolen and discarded on a housing estate; the supervisory authority learned of it from the media. The bank had informed neither the authority nor the data subjects because it rated the risk as low – it had already been sanctioned in 2022 for failing to notify data subjects.

What organisations can take from it

Assess the risk of a data breach from the data subjects’ perspective – failing to notify the loss of sensitive documents risks a higher penalty than the breach itself.

Relevance to training and awareness

Risk assessment and notification of data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1, Art. 34 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Employees
10,000 or more
Repeat case
yes
Published
2 Apr 2024

Original amount 1,440,549 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Mar 2024 Toyota Bank Polska S.A.Toyota Bank Polska: 78,575 PLN – misdirected mailing reported only after 1.5 years PolandIncident reporting obligations €18,331

The bank sent a customer’s contract data to the wrong recipient and only reported the breach one and a half years later, when the supervisory authority made enquiries following a complaint. Given the risk of identity theft, the authority considered that there had been an obligation to notify within 72 hours.

What organisations can take from it

Even a single misdirected mailing containing identity data is notifiable – misdirected mail cases need a documented risk assessment.

Relevance to training and awareness

Recognising misdirected mail and reporting it internally

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
2 Apr 2024

Original amount 78,575.4 PLN, converted at the ECB reference rate of 12 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Oct 2023 Link4 Towarzystwo Ubezpieczeń S.A.Link4: 103,752 PLN – misdirected e-mail not reported after using a risk calculator PolandIncident reporting obligations €23,362

The insurer sent a claims settlement confirmation containing name, address, vehicle and claim data by e-mail to an unauthorised person. After an assessment using an online calculator, it rated the risk as low and did not notify; the supervisory authority found that the notification obligation had been breached and treated, among other things, intent and lack of cooperation as aggravating factors.

What organisations can take from it

Risk assessment tools do not replace judgement – anyone sending out information covered by insurance secrecy should notify if in doubt.

Relevance to training and awareness

Avoiding misdirected e-mails; reporting data breaches

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Art. 33 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Culpability
intentional
Repeat case
yes
Published
23 Nov 2023

Original amount 103,752 PLN, converted at the ECB reference rate of 18 Oct 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial