Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Finansinspektionen (FI) €15.1m 95 % · 4 cases
- Integritetsskyddsmyndigheten (IMY) €748,846 5 % · 6 cases
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 2 | €17,366 |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €6,801 |
| Q3 2025 | 0 | — |
| Q4 2025 | 2 | €2.09m |
| Q1 2026 | 1 | €564,626 |
| Q2 2026 | 2 | €12.9m |
| Q3 2026 | 2 | €337,240 |
10 cases
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers €177,187
As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.
Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- No established damage to investors; remedial measures already taken during the investigation.
- Published
- 16 Sep 2026
Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.
- FI ger AIFM Capital en anmärkning och en sanktionsavgift (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence €12.9m
For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.
The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.
Enhanced due diligence for high-risk customers
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 17 Jun 2026
Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.
- FI ger Ikano Bank en anmärkning och en sanktionsavgift (17.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis Reprimand or warning
The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.
Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.
Use of cameras in vehicles
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 6 Abs. 1
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Defence and security
- IMY – Tillsyn Securitas Sverige Aktiebolag Decision of an authority
- IMY – Beslut Securitas Sverige AB Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data €564,626
The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).
Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
- Published
- 26 Jan 2026
Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.
- IMY – Tillsyn Sportadmin i Skandinavien AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2025-7801 (26.01.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Nov 2025 Avida Finans ABAvida Finans: 20 million SEK for loans to consumers unable to repay €1.82m
The Swedish financial supervisory authority Finansinspektionen (FI) examined consumer loans granted by the lender over four weeks in summer 2024 and found at least around 30 cases in which consumers without the ability to repay received loans. FI issued a remark and imposed 20 million SEK.
Carry out credit checks consistently even under sales pressure and verify them internally through sample checks.
Creditworthiness assessment in sales
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Consumer protection and online retail
- Legal basis
- Konsumentkreditlagen (2010:1846), Kreditprüfung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Nov 2025
Original amount 20,000,000 SEK, converted at the ECB reference rate of 11 Nov 2025.
- Avida Finans får en anmärkning och en sanktionsavgift för bristande kreditprövningar (11.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Oct 2025 Zimpler ABZimpler: 3 million SEK over anti-money laundering deficiencies at gambling-related payment service €272,245
Between July 2023 and April 2024, the payment service provider, a substantial part of whose business is linked to the gambling sector, had gaps in its general risk assessment (including a missing assessment of its currency exchange service), in its customer risk assessment and in customer due diligence. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 3 million SEK.
Include every new product – even an ancillary service such as currency exchange – in the money laundering risk assessment before launch.
Money laundering risks in the gambling environment
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 15 Oct 2025
Original amount 3,000,000 SEK, converted at the ECB reference rate of 15 Oct 2025.
- Zimpler får en anmärkning och sanktionsavgift (15.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Jun 2025 Waxholms Ångfartygs AktiebolagWaxholmsbolaget: fine for processing a captain’s breathalyser test results €6,801
The shipping company processed results of on-board breath alcohol tests that could be attributed to a complainant employed as a captain. The Swedish Authority for Privacy Protection (IMY) regarded this as processing without a legal basis and as unlawful processing of health data and imposed 75,000 SEK.
Monitoring data such as alcohol test results are employees’ health data – access, storage and legal basis must be settled before such tests are introduced.
Employee health data (alcohol tests)
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 6, Art. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 18 Jun 2025
Original amount 75,000 SEK, converted at the ECB reference rate of 18 Jun 2025.
- IMY – Tillsyn Waxholms Ångfartygs AB (WÅAB) Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2024-1520 (18.06.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Dec 2024 Aktiebolaget Trav och GaloppATG: reprimand over misleadingly designed cookie banner Reprimand or warning
Following a complaint – one of several complaints about cookie banners lodged with European data protection authorities – the Swedish Authority for Privacy Protection (IMY) found that the betting operator did not make withdrawing consent as easy as giving it and, through the misleading design of the banner (choice of colours, contrast, rejection only as a link), made informed, freely given consent more difficult. IMY issued a reprimand; ATG had since changed the banner.
Rejecting must be as easy as accepting: colour, contrast and link placement in the cookie banner must not steer the decision.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- DSGVO Art. 6, Art. 7 Abs. 3
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Other
- IMY – Tillsyn Aktiebolaget Trav och Galopp Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2023-16453 (16.12.2024) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Dec 2024 Granit Bostad Beritsholm ABGranit Bostad Beritsholm: 200,000 SEK for round-the-clock video surveillance in a block of flats €17,366
The landlord monitored a multi-family building in Malmö around the clock with cameras at entrances, lifts, flat doors, in the stairwell, the basement and the refuse room, without any legal basis for doing so; the signs did not name the controller. The Swedish Authority for Privacy Protection (IMY) imposed 200,000 SEK and ordered the landlord to stop the surveillance except in the garage and to supplement the signs.
Video surveillance in residential buildings requires a balancing of interests for each individual area – problems such as vandalism do not justify blanket, permanent surveillance.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 6 Abs. 1, Art. 13
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Published
- 12 Dec 2024
Original amount 200,000 SEK, converted at the ECB reference rate of 11 Dec 2024.
- IMY – Tillsyn Granit Bostad Beritsholm AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2023-15373 (11.12.2024) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link