Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUSweden Clear all filters
10cases from 1 jurisdiction
€15.9mTotal of monetary amounts (8 cases with an amount)
€12.9mLargest single case: Ikano Bank AB
€224,716Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20242€17,366
Q1 20250—
Q2 20251€6,801
Q3 20250—
Q4 20252€2.09m
Q1 20261€564,626
Q2 20262€12.9m
Q3 20262€337,240

10 cases

22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak SwedenData breaches and data security €160,053

The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.

What organisations can take from it

Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Published
22 Sep 2026

Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers SwedenOrganisational requirements €177,187

As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.

What organisations can take from it

Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.

Authority / court
Finansinspektionen (FI)
Area of law
Capital markets and financial supervision · Organisational requirements
Legal basis
Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
No established damage to investors; remedial measures already taken during the investigation.
Published
16 Sep 2026

Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence SwedenCustomer due diligence €12.9m

For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.

What organisations can take from it

The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.

Relevance to training and awareness

Enhanced due diligence for high-risk customers

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
under appeal
Sector
Financial services and insurance
Published
17 Jun 2026

Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis SwedenVideo surveillance Reprimand or warning

The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.

What organisations can take from it

Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.

Relevance to training and awareness

Use of cameras in vehicles

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 6 Abs. 1
Action
Reprimand or warning
Status of proceedings
final
Sector
Defence and security
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data SwedenData breaches and data security €564,626

The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).

What organisations can take from it

Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Mitigating circumstances
Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
Published
26 Jan 2026

Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Nov 2025 Avida Finans ABAvida Finans: 20 million SEK for loans to consumers unable to repay SwedenConsumer protection and online retail €1.82m

The Swedish financial supervisory authority Finansinspektionen (FI) examined consumer loans granted by the lender over four weeks in summer 2024 and found at least around 30 cases in which consumers without the ability to repay received loans. FI issued a remark and imposed 20 million SEK.

What organisations can take from it

Carry out credit checks consistently even under sales pressure and verify them internally through sample checks.

Relevance to training and awareness

Creditworthiness assessment in sales

Authority / court
Finansinspektionen (FI)
Area of law
Consumer protection and online retail
Legal basis
Konsumentkreditlagen (2010:1846), Kreditprüfung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
11 Nov 2025

Original amount 20,000,000 SEK, converted at the ECB reference rate of 11 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Oct 2025 Zimpler ABZimpler: 3 million SEK over anti-money laundering deficiencies at gambling-related payment service SwedenCustomer due diligence €272,245

Between July 2023 and April 2024, the payment service provider, a substantial part of whose business is linked to the gambling sector, had gaps in its general risk assessment (including a missing assessment of its currency exchange service), in its customer risk assessment and in customer due diligence. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 3 million SEK.

What organisations can take from it

Include every new product – even an ancillary service such as currency exchange – in the money laundering risk assessment before launch.

Relevance to training and awareness

Money laundering risks in the gambling environment

Authority / court
Finansinspektionen (FI)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Penningtvättslagen (2017:630)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
15 Oct 2025

Original amount 3,000,000 SEK, converted at the ECB reference rate of 15 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Jun 2025 Waxholms Ångfartygs AktiebolagWaxholmsbolaget: fine for processing a captain’s breathalyser test results SwedenEmployee data €6,801

The shipping company processed results of on-board breath alcohol tests that could be attributed to a complainant employed as a captain. The Swedish Authority for Privacy Protection (IMY) regarded this as processing without a legal basis and as unlawful processing of health data and imposed 75,000 SEK.

What organisations can take from it

Monitoring data such as alcohol test results are employees’ health data – access, storage and legal basis must be settled before such tests are introduced.

Relevance to training and awareness

Employee health data (alcohol tests)

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Employee data
Legal basis
DSGVO Art. 6, Art. 9
Action
Fine
Status of proceedings
unknown
Sector
Transport, logistics and shipping
Published
18 Jun 2025

Original amount 75,000 SEK, converted at the ECB reference rate of 18 Jun 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Dec 2024 Aktiebolaget Trav och GaloppATG: reprimand over misleadingly designed cookie banner SwedenCookies and tracking Reprimand or warning

Following a complaint – one of several complaints about cookie banners lodged with European data protection authorities – the Swedish Authority for Privacy Protection (IMY) found that the betting operator did not make withdrawing consent as easy as giving it and, through the misleading design of the banner (choice of colours, contrast, rejection only as a link), made informed, freely given consent more difficult. IMY issued a reprimand; ATG had since changed the banner.

What organisations can take from it

Rejecting must be as easy as accepting: colour, contrast and link placement in the cookie banner must not steer the decision.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Cookies and tracking
Legal basis
DSGVO Art. 6, Art. 7 Abs. 3
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Other

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

11 Dec 2024 Granit Bostad Beritsholm ABGranit Bostad Beritsholm: 200,000 SEK for round-the-clock video surveillance in a block of flats SwedenVideo surveillance €17,366

The landlord monitored a multi-family building in Malmö around the clock with cameras at entrances, lifts, flat doors, in the stairwell, the basement and the refuse room, without any legal basis for doing so; the signs did not name the controller. The Swedish Authority for Privacy Protection (IMY) imposed 200,000 SEK and ordered the landlord to stop the surveillance except in the garage and to supplement the signs.

What organisations can take from it

Video surveillance in residential buildings requires a balancing of interests for each individual area – problems such as vandalism do not justify blanket, permanent surveillance.

Authority / court
Integritetsskyddsmyndigheten (IMY)
Area of law
Data protection · Video surveillance
Legal basis
DSGVO Art. 6 Abs. 1, Art. 13
Action
Fine
Status of proceedings
unknown
Sector
Construction and real estate
Published
12 Dec 2024

Original amount 200,000 SEK, converted at the ECB reference rate of 11 Dec 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial