Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by country- EU level €3.8bn 50 % · 20 cases
- Ireland €895m 12 % · 10 cases
- France €823.9m 11 % · 25 cases
- Spain €563.1m 7 % · 10 cases
- Netherlands €463.6m 6 % · 18 cases
- Italy €462.4m 6 % · 26 cases
- Germany €204.8m 3 % · 39 cases
- Slovakia €142.7m 2 % · 17 cases
- Austria €86m 1 % · 16 cases
- Czechia €52.2m 1 % · 9 cases
- 18 more€163.4m
What for?
by area of lawAll areas of law
- Competition law €2.73bn 36 % · 82 cases
- AI and digital regulation €2.5bn 33 % · 16 cases
- Data protection €2bn 26 % · 136 cases
- Consumer protection and online retail €204.2m 3 % · 33 cases
- Bribery and corruption €102.8m 1 % · 8 cases
- Money laundering and terrorist financing €101.3m 1 % · 34 cases
- Capital markets and financial supervision €16.7m 0 % · 36 cases
- Environment and sustainability €1m 0 % · 6 cases
- Health and safety and employment law €953,069 0 % · 7 cases
- Information security and cyber €464,702 0 % · 8 cases
- 4 more€490,550
Who?
by sectorAll sectors
- Media and online platforms €1.96bn 26 % · 31 cases
- Telecoms, IT and software €1.58bn 21 % · 36 cases
- Retail and e-commerce €1.37bn 18 % · 44 cases
- Transport, logistics and shipping €819.9m 11 % · 20 cases
- Automotive €547m 7 % · 11 cases
- Chemicals and pharmaceuticals €488m 6 % · 5 cases
- Energy and utilities €271.3m 4 % · 23 cases
- Financial services and insurance €144.9m 2 % · 83 cases
- Construction and real estate €126m 2 % · 21 cases
- Manufacturing and mechanical engineering €99.5m 1 % · 9 cases
- 6 more€244.3m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 14 | €26.5m |
| Q1 2024 | 15 | €92.2m |
| Q2 2024 | 10 | €54.9m |
| Q3 2024 | 14 | €821.6m |
| Q4 2024 | 38 | €878.1m |
| Q1 2025 | 26 | €82.6m |
| Q2 2025 | 40 | €2.12bn |
| Q3 2025 | 35 | €509.4m |
| Q4 2025 | 54 | €857.8m |
| Q1 2026 | 45 | €257.6m |
| Q2 2026 | 44 | €398.5m |
| Q3 2026 | 47 | €1.56bn |
382 cases
24 Sep 2026 Plaček Pet Products s.r.o.Plaček Pet Products: 36.4 million CZK for minimum prices on pet food €1.49m
From January 2013 to March 2022, the distributor of premium pet food and pet supplies imposed minimum resale prices on its retailers and threatened sanctions if they were undercut. In a settlement procedure, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 36.438 million CZK; the company ended the conduct after the inspection and introduced a compliance programme.
Never enforce recommended retail prices with supply stops or sanctions – sales teams need clear rules on this.
Price requirements imposed on retailers in sales
Missing or inadequate training played a role in the decision.
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Verbot vertikaler Preisbindung (tschechisches Wettbewerbsgesetz, Art. 101 AEUV)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Mitigating circumstances
- Termination immediately after the inspection, information of customers about free pricing, full cooperation, settlement and newly introduced compliance programme.
- Published
- 24 Sep 2026
Original amount 36,438,000 CZK, converted at the ECB reference rate of 24 Sep 2026.
- Distributor krmiv pro domácí zvířata dostal pokutu 36 milionů korun za diktování cen maloobchodníkům Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2026 Miljödata i Karlskrona AktiebolagIMY: 1.8 million SEK against HR software provider Miljödata after data leak €160,053
The provider of web-based systems for sickness reporting, rehabilitation and occupational safety incidents was hacked in August 2025; the stolen personal data appeared on the dark web shortly afterwards. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) found that, despite the high need for protection, there were no adequate security measures and no automatic real-time monitoring for attacks, assessed this as negligent and imposed 1,800,000 SEK.
Service providers hosting the health and personnel data of many employers need real-time attack detection, not just perimeter protection.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Published
- 22 Sep 2026
Original amount 1,800,000 SEK, converted at the ECB reference rate of 22 Sep 2026.
- IMY Tillsyn: Miljödata i Karlskrona AB Press release of an authority
- Beslut efter tillsyn enligt dataskyddsförordningen – Miljödata i Karlskrona Aktiebolag (IMY-2025-21177) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2026 Audax Renovables, S.A. – Sucursal em PortugalPortugal: 22,000 EUR against Audax Renovables over missing gas reserves and hotline €22,000
On a total of 249 days, the Portuguese branch of the energy supplier failed to hold the mandatory natural gas security reserves, did not correctly show network charges on invoices, did not publish, or published late, mandatory information and its quality report, and failed to meet the standards for hotline waiting times. In a settlement procedure, the Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) set a fine of 44,000 EUR and reduced it to 22,000 EUR.
Security of supply and service obligations in the energy sector are sanctioned individually – a compliance calendar for reserves and reports helps.
- Authority / court
- Entidade Reguladora dos Serviços Energéticos (ERSE)
- Area of law
- Other
- Legal basis
- Regime Sancionatório do Setor Energético (RSSE), Art. 28, 29; Decreto-Lei n.º 62/2020, Art. 96; RRC; RQS
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- Settlement (transação) with full admission, remediation of all infringements
- ERSE – Decisões sancionatórias: Processos n.º 47/2024 e 62/2025 – Audax Renovables, S.A. – Sucursal em Portugal Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Sep 2026 Lesy České republiky, s.p. (Lesy ČR)Lesy ČR: 17.3 million CZK for export ban on wood chips €710,383
From July 2021 to July 2024, the state forestry company contractually prohibited a customer from actively and passively exporting wood chips and logging residues and secured the ban with a right of termination. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) considered this a restriction of competition by object under Czech and EU law and imposed 17.268 million CZK (first instance, not final).
State-owned companies are also subject to competition law – have export and resale bans in framework agreements legally reviewed before signing.
Anticompetitive clauses in supply contracts
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (Exportverbot, S0733/2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Voluntary termination immediately after proceedings were opened.
- Published
- 17 Sep 2026
Original amount 17,268,000 CZK, converted at the ECB reference rate of 17 Sep 2026.
- Lesy ČR banned wood-chip exports and were imposed a fine of more than CZK 17 million Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 AIFM Capital ABAIFM Capital: 2 million SEK for inadequate selection and oversight of fund managers €177,187
As a so-called fund hotel, the company had its funds managed by other firms, but examined these delegation agreements only insufficiently, did not take the related decisions properly and did not monitor the funds’ returns in relation to risk closely enough. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 2 million SEK; no damage to investors was established.
Outsourcing tasks does not outsource responsibility: document the selection of service providers, the decisions taken and ongoing oversight.
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Schwedisches Fondsrecht – Regeln zur Delegation der Fondsverwaltung und deren Überwachung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- No established damage to investors; remedial measures already taken during the investigation.
- Published
- 16 Sep 2026
Original amount 2,000,000 SEK, converted at the ECB reference rate of 16 Sep 2026.
- FI ger AIFM Capital en anmärkning och en sanktionsavgift (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2026 Wallester ASFinancial supervisor orders Wallester to remedy governance and AML deficiencies Order
Following an on-site inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) issued an order requiring the payment institution Wallester to remedy, by 31 December, deficiencies in governance and control functions (separation of the lines of defence, internal rules), in safeguarding customer funds and in the staffing of its anti-money laundering and counter-terrorist financing function. Date = publication of the press release.
Fast-growing payment service providers must let their compliance, AML and internal audit functions grow with them in terms of staffing and organisation.
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Aufsichtsrechtliche Anordnung (ettekirjutus) der Finantsinspektsioon
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 16 Sep 2026
- Finantsinspektsioon tegi Wallester AS-ile ettekirjutuse (16.09.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Sep 2026 Ministerstvo životního prostředí (Umweltministerium der Tschechischen Republik)Ministry of the Environment: 300,000 CZK over unresolved conflict of interest of an insurance broker €12,350
In an insurance tender in 2024 worth around 200 million CZK, the ministry had parts of the tender documents drawn up by a broker who could later receive commissions from the winning insurer. As the contracting authority took no measures against the conflict of interest, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed a final fine of 300,000 CZK.
External advisers who help draft tender documents must not benefit from the outcome – examine and document conflicts of interest before the tender.
Conflicts of interest of external advisers in procurement procedures
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Other
- Legal basis
- Gesetz über die Vergabe öffentlicher Aufträge (Pflicht zur Vermeidung von Interessenkonflikten)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Published
- 15 Sep 2026
Original amount 300,000 CZK, converted at the ECB reference rate of 15 Sep 2026.
- ÚOHS uložil pokutu 300 tisíc korun resortu životního prostředí kvůli neošetření možného střetu zájmů Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia)Garante: 5.5 million EUR against BBVA Italia over advertising despite objection €5.51m
For seven months (October 2025 to May 2026), the bank continued to send a customer advertising via its app, although he had objected several times. The Italian data protection authority (Garante per la protezione dei dati personali) also found deficient systems for implementing objections and inaccurate information about the processing, and imposed 5,508,000 EUR (Provvedimento No. 613).
An objection to advertising must take effect immediately and reliably across all channels – including app messages.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 12, 21, 24 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Provvedimento n. 613 del 3 settembre 2026 (BBVA Italia) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2026 ASIS – Azienda Speciale per la gestione degli Impianti Sportivi (Trento)Garante: 8,000 EUR for cameras in swimming pool changing rooms of a Trentino sports operator €8,000
Since 2007, the municipal sports facilities operator had had cameras in the changing rooms of a swimming pool that recorded the locker area. The Italian data protection authority (Garante per la protezione dei dati personali) found no sound legal basis, incomplete notices and a 72-hour retention period not justified by a necessity assessment, and imposed 8,000 EUR (Provvedimento No. 619); the cameras were removed during the proceedings.
Changing rooms and comparably intimate areas are off limits for video surveillance – even when theft prevention is the motive.
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 lit. c und e DSGVO; Art. 2-ter Codice privacy
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante – Provvedimento n. 619 del 3 settembre 2026 [10294255] (ASIS Trento) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Aug 2026 EM@NEY P.L.C.Malta: EM@NEY pays 97,622 EUR under settlement for late bank account register reports €97,622
The financial institution did not deliver on time the data due every seven days to the Centralised Bank Account Register (CBAR). The Financial Intelligence Analysis Unit (FIAU) set a fine of 162,704 EUR, which was reduced by 40% to 97,622 EUR under a settlement pursuant to its 2026 settlement policy.
Recurring mandatory reports need deadline monitoring with escalation – otherwise individual omissions add up to six-figure sums.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8, 9 CBAR Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction
- Published
- 4 Sep 2026
- Settlement Agreement Publication Notice – EM@NEY P.L.C. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 MiFinity Malta LimitedMalta: MiFinity pays 160,099 EUR following anti-money laundering examination €160,099
At the payment institution, the customer risk assessment had only been introduced after business had started, some customers remained unassessed, and customer profiles were based on transaction thresholds rather than on risk. The Financial Intelligence Analysis Unit (FIAU) set a fine of 266,833 EUR and a follow-up directive; under a settlement, the fine was reduced by 40% to 160,099 EUR.
A customer risk assessment belongs before business starts, not in a later remediation project.
Risk-based customer profiles and source of funds
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 2(1), 5(5)(a)(ii), 7(1)(c), 7(2)(a), 21, 22 PMLFTR
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Settlement with 40% reduction; remediation demonstrated
- Published
- 2 Sep 2026
- Settlement Agreement Publication Notice – MiFinity Malta Limited Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Aug 2026 Flower bulb business failed to disclose hours of Polish seasonal workers – fine of around 95,600 EUR €95,588
A lily and tulip grower with an average of around 50 (at peak 75) employees, where Polish migrant workers are employed (anonymised in the judgment), was unable to produce sufficient records of hours worked and wages paid for 18 employees for September 2020 to February 2021. The Dutch Minister of Social Affairs and Employment (Minister van Sociale Zaken en Werkgelegenheid) imposed 118,000 EUR in 2024 (112,100 EUR after objection); the North Netherlands District Court (Rechtbank Noord-Nederland) reduced the fine to 95,587.50 EUR, partly because of measures taken and excessively long proceedings.
Companies employing seasonal workers must be able to document hours and wage payments for each person without gaps – missing records are fined separately for each employee.
- Authority / court
- Rechtbank Noord-Nederland (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid / Nederlandse Arbeidsinspectie)
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- Art. 18b Abs. 2 Wet minimumloon en minimumvakantiebijslag (Wml)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Food and agriculture
- Employees
- 50 to 249
- Mitigating circumstances
- Reduction of 12.5 % for appropriate measures, 5 % for delay and 2,500 EUR for exceeding the reasonable length of proceedings.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Aug 2026 O2 Czech Republic a.s.; SHERLOG Technology, a.s.O2 Czech Republic and SHERLOG: 280 million CZK for customer allocation in vehicle tracking €11.7m
From December 2012 to June 2022, the two companies allocated customers for vehicle tracking and electronic logbook services between themselves and coordinated bids, including in public tenders. At first instance, the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) fined O2 262.32 million CZK and SHERLOG 18.357 million CZK and imposed a six-month ban on public contracts; for O2, the fine was increased instead of a procurement ban.
Do not let sales cooperation with competitors turn into customer allocation – e-mail arrangements about individual tenders are the typical evidence.
Coordination with cooperation partners on customers and tenders
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0255/2023)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- intentional
- Published
- 26 Aug 2026
Original amount 280,677,000 CZK, converted at the ECB reference rate of 26 Aug 2026.
- Fines exceeding CZK 280 million imposed on O2 Czech Republic and SHERLOG Technology for cartel agreement Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Aug 2026 Wolt DenmarkWolt: Competition Council finds abuse of dominant position vis-à-vis restaurants Order
In 2022–2024, the delivery service used a standard clause to prohibit restaurants from being cheaper on their own channels than on Wolt, while at the same time being able to grant discounts without consultation and to compensate customers up to 400 DKK at the restaurants’ expense. The Konkurrencerådet (Danish Competition Council) ordered the practice to cease, required Wolt to inform all restaurants and intends to enforce a fine through the courts.
Platforms with a high market share should have parity clauses and unilateral cost shifting in standard terms reviewed under competition law.
- Authority / court
- Konkurrencerådet (Danish Competition Council)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Konkurrenceloven; AEUV Art. 102
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 26 Aug 2026
- KFST – Wolt has abused its dominant position (26.08.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Health Service Executive (HSE)Irish health service HSE: 645,000 EUR for neglected paper patient records €645,000
In 2023, intruders gained access to two former psychiatric hospitals and posted videos of the patient records stored there online. An inspection of twelve sites found records with mould, water and animal damage in unsuitable rooms, up to and including shipping containers. Ireland's Data Protection Commission (DPC) imposed a fine of 645,000 EUR, issued a reprimand and ordered audits and the relocation of records.
Data protection also applies to paper archives in disused buildings – retention requires an inventory, erasure periods and physical security.
Physical security and retention of paper records
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e und f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 2 Sep 2026
- Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Press release of an authority
- EDPB – DPC announces Final Decision following Inquiry into the HSE Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Aug 2026 Elizabeta Promet d.o.o., SolinCroatia: 10,000 EUR against Elizabeta Promet for deliveries without a written contract €10,000
As a buyer with significant bargaining power, the company from Solin purchased agricultural and food products from two suppliers without written contracts. The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) considered this an unfair trading practice and, taking mitigating circumstances into account, imposed 10,000 EUR (date = publication).
In food purchasing, the mere absence of written supply contracts is an infringement – a simple contract standard prevents this.
Written form for supply contracts in food purchasing
- Authority / court
- Agencija za zaštitu tržišnog natjecanja (AZTN)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Several mitigating circumstances taken into account
- Published
- 25 Aug 2026
- Provedba ZNTP-a: AZTN kaznio ELIZABETU PROMET d.o.o., Solin s 10.000,00 eura zbog nametanja nepoštenih trgovačkih praksi Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Aug 2026 WH Media GmbHKommAustria penalises person responsible for W24 over advertising in news programme €500
On 29 May 2024, the Vienna broadcaster W24 aired advertising in split screen within the programme ‘24 Stunden Wien’, did not adequately separate advertising from programming and, at around 50 minutes, significantly exceeded the permitted 12 minutes of advertising per hour. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) imposed fines totalling 500 EUR (plus 50 EUR in costs) on the body authorised to represent the company externally; the GmbH is jointly and severally liable under § 9 (7) VStG (Austrian Administrative Penal Act).
Advertising time limits and the separation requirement also apply to small regional broadcasters – management is personally liable via § 9 VStG.
- Authority / court
- Kommunikationsbehörde Austria (KommAustria)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 64 Abs. 2 Z 9 i. V. m. §§ 43 Abs. 2, 44 Abs. 1, 45 Abs. 1 AMD-G; § 9 VStG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- negligent
- Mitigating circumstances
- No previous record, duration of proceedings, remorseful confession and remedial measures initiated.
- Liability of senior managers
- Fine imposed on the body responsible externally (§ 9 (1) VStG); the company is jointly and severally liable.
- Published
- 19 Aug 2026
- KommAustria, Straferkenntnis KOA 05.910 / 2025-0.418.178-6-A (W24) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Aug 2026 Pluxee Česká republika a.s.; Edenred CZ s.r.o.; Up Česká republika s.r.o.Meal voucher cartel: 279 million CZK against Pluxee, Edenred and Up upheld with final effect €11.5m
From 2004 to 2018, the three issuers of paper meal vouchers coordinated with retail chains how many vouchers would be accepted per purchase. The President of the Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) dismissed the appeals against the recalculation of the fines: Pluxee 132.271 million, Edenred 101.94 million and Up 44.941 million CZK, a total of 279.152 million CZK.
Coordinating seemingly technical conditions such as acceptance limits is also a cartel – industry discussions need clear boundaries.
Coordination of terms and conditions among competitors
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (R0112/2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- intentional
- Published
- 17 Aug 2026
Original amount 279,152,000 CZK, converted at the ECB reference rate of 17 Aug 2026.
- Chairman of the Czech Competition Authority Definitively Confirms Fines for Meal Voucher Issuers’ Cartel Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Aug 2026 Dante International S.A.; Extreme Digital-eMAG Kft. (Betreiber des eMAG-Webshops)eMAG: further 225 million HUF for unfulfilled commitments €620,091
In 2021, the operators of the online retailer eMAG had committed to a support programme for Hungarian businesses, but once again implemented it only partially and not with the prescribed content. In the follow-up review, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 225 million HUF; in total, the operators have already received fines of 710 million HUF.
Commitments made binding by an authority require dedicated implementation and evidence controlling – otherwise the next fine follows.
- Authority / court
- Gazdasági Versenyhivatal (GVH)
- Area of law
- Consumer protection and online retail
- Legal basis
- Nachprüfungsverfahren zu verbindlichen Zusagen (VJ/6/2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Repeat case
- yes
- Mitigating circumstances
- The companies acknowledged the failures and waived legal remedies.
- Published
- 13 Aug 2026
Original amount 225,000,000 HUF, converted at the ECB reference rate of 13 Aug 2026.
- Újabb 225 milliós GVH-bírságot kapott az eMAG, mert megint hiányosan teljesítette a saját vállalásait Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Aug 2026 „О-Рент“ ЕООД (sowie „Инжконсулт“ ЕООД und „Земекоп“ ЕООД)Construction machinery cartel: fine for O-Rent, compliance programme for all participants €2,403
The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found a cartel in public tenders for mining and construction machinery (price fixing and market sharing, Art. 15 ZZK – Bulgarian Protection of Competition Act, Art. 101 TFEU). Inzhkonsult and Zemekop, as a single undertaking, were exempted from the fine; O-Rent received a sanction of 2,403.07 EUR. All three companies must introduce a competition law compliance programme within 60 days and report on it.
The authority now expressly requires compliance programmes – anyone bidding in tenders should have one before it is ordered.
Competition law in tenders; compliance programme
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 15 Abs. 1 Nr. 1 und 2 ZZK; Art. 101 Abs. 1 lit. a und c AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Mitigating circumstances
- Immunity from fines for two participants (leniency programme)
- Published
- 20 Aug 2026
- КЗК Публичен електронен регистър – Производство (Решение № 797 от 13.08.2026; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Aug 2026 Hair-Line Kft.Hair-Line: 68.5 million HUF for price and territorial restrictions on hairdressing supplies €187,929
In 2018–2022, the distributor of professional hairdressing products (Alfaparf, Yellow) determined the prices at which its territorial representatives were allowed to sell to salons and retailers and restricted passive sales outside the territories. Under a settlement and with a commitment to a compliance programme, the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed 68.5 million HUF.
Commercial agent systems with territorial protection must not restrict resale prices or passive sales either.
Price and territorial restrictions in the distribution system
Missing or inadequate training played a role in the decision.
- Authority / court
- Gazdasági Versenyhivatal (GVH)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Ungarisches Wettbewerbsgesetz, Verbot wettbewerbsbeschränkender Vereinbarungen (VJ/17/2022)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Mitigating circumstances
- Cooperation, acknowledgement in the settlement and commitment to a comprehensive compliance programme.
- Published
- 7 Aug 2026
Original amount 68,500,000 HUF, converted at the ECB reference rate of 7 Aug 2026.
- Korlátozta a versenyt az egyik ismert hazai fodrászcikk forgalmazó, komoly GVH-bírság lett a vége Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AS Asphaltstraßensanierung GmbH, BITUNOVA GmbH, Kutter Spezialstraßenbau GmbH & Co. KG, Possehl Construction GmbH (inkl. VSI), Liesen…alles für den Bau GmbH, OAT GmbH/Otto Alte-Teigeler GmbHBundeskartellamt: 60.3 million EUR against DSK road repair cartel €60.3m
From around 2010 to September 2019, six suppliers of thin cold-laid asphalt surface layers (Dünne Asphaltdeckschichten in Kaltbauweise, DSK) allocated customers – primarily public contracting authorities – and contracts among themselves nationwide and coordinated prices. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines of around 60.3 million EUR; all proceedings ended in settlements.
Anyone who "shares out" public contracts regionally risks fines running into millions – calculations and bids must always be prepared independently.
Customer allocation and bid rigging in public contracts
- Authority / court
- Bundeskartellamt
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- § 1 GWB, Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
- Mitigating circumstances
- Leniency bonus for Possehl/VSI, Bitunova, Kutter and AS; settlement
- Published
- 6 Aug 2026
- Bußgelder wegen Kartellabsprachen im Bereich Straßenreparatur mit DSK Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 „Чили Хилс Фудс“ ООД (Chili Hills Foods OOD)Chili Hills Foods: 20,022 EUR for false copying allegations against competitor €20,022
From May 2024, in social media videos (campaign ‘Създавай! Не копирай!’), the company falsely accused a competing family business for hot chillies of having stolen its business, ideas and concept, and promoted the clips partly through paid advertising. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) regarded this as unfair damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act), imposed 4% of 2025 net turnover (500,555 EUR), i.e. 20,022 EUR, and ordered immediate cessation. Appeals have been lodged against the decision.
Allegations against competitors on social media are only permissible if based on verifiable facts – paid reach aggravates the sanction.
Statements about competitors on social media
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Food and agriculture
- Published
- 19 Aug 2026
- КЗК Публичен електронен регистър – Производство (Решение № 743 от 06.08.2026; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 Capwatt Retail Gás PT, S.A.Portugal: 12,000 EUR against Capwatt over gas reserves and dispute resolution notice €12,000
In several months of 2023 and 2024, the gas supplier did not hold the natural gas security reserves and did not name the competent alternative dispute resolution bodies in customer contracts. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) accepted the settlement proposal, set a fine of 24,000 EUR and reduced it to 12,000 EUR.
Mandatory information in consumer contracts – for example on dispute resolution – belongs in a regularly reviewed contract template.
- Authority / court
- Entidade Reguladora dos Serviços Energéticos (ERSE)
- Area of law
- Other
- Legal basis
- RSSE, Art. 29; Decreto-Lei n.º 62/2020, Art. 57, 96; Portaria n.º 59/2022; RRC Art. 22
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Culpability
- negligent
- Mitigating circumstances
- Settlement with admission and remediation
- ERSE – Decisões sancionatórias: Processo n.º 50/2024 – Capwatt Retail Gás PT, S.A. Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Aug 2026 AS "Latvijas valsts meži"7.86 million EUR against Latvijas valsts meži for breach of competitive neutrality €7.86m
From 2020 to April 2026, on the basis of old long-term logging contracts, the state forestry group supplied six wood processors with guaranteed quantities of roundwood outside public auctions, while all others could only buy through auctions. In its first decision on the competitive neutrality of public undertakings, the Konkurences padome (Latvian Competition Council) imposed 7,859,606.89 EUR and required equal sales conditions for all qualified bidders.
State-owned companies must allocate resources without discrimination – review historical special contracts regularly for competitive neutrality.
- Authority / court
- Konkurences padome (Lettischer Wettbewerbsrat)
- Area of law
- Competition law
- Legal basis
- Art. 14.1 Konkurences likums (Wettbewerbsneutralität)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 13 Aug 2026
- Konkurences padome konstatē konkurences neitralitātes pārkāpumu AS „Latvijas valsts meži“ darbībā (13.08.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Aug 2026 Lime Technology S.r.l., EmTransit S.r.l. (Dott), Bird Rides Italy S.r.l.Rome: 2.675 million EUR against e-scooter and e-bike sharing providers over blocked free rides €2.68m
The three sharing providers made it difficult for holders of a Metrebus annual pass to access the free-ride passes promised when the concessions were awarded, through inadequate organisation, cumbersome activation and long waiting times, which shortened the usable time; Bird also deactivated accounts without prior notice. The AGCM imposed fines totalling 2.675 million EUR in three proceedings (Lime 1.4 million, Dott 525,000, Bird 750,000 EUR).
Promised benefits must also be redeemable in organisational terms – sluggish processing can itself be unfair.
Customer service and redemption of promised services
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Codice del Consumo (pratiche commerciali scorrette), Verfahren PS13028, PS13029, PS13030
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 6 Aug 2026
- PS13028-PS13029-PS13030 - Roma, sanzioni per 2,675 milioni di euro a operatori monopattini elettrici ed e-bike in sharing Press release of an authority
- AGCM Provvedimento PS13028 (Lime Technology S.r.l.) Decision of an authority
- AGCM Provvedimento PS13029 (EmTransit S.r.l. – Dott) Decision of an authority
- AGCM Provvedimento PS13030 (Bird Rides Italy S.r.l.) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jul 2026 AvisAvis: maximum fine of 1 million EUR for handling fee on traffic fines €1m
The car rental company charged customers an "administration fee" of 33.88 to 45 EUR when a rental car incurred a traffic offence – even though naming the driver is a statutory obligation of the rental company. Spain's Ministry of Social Rights, Consumer Affairs and 2030 Agenda classified this as a very serious infringement and imposed the maximum fine of 1 million EUR; a court had already declared the clause void in 2020.
No additional fee may be charged for fulfilling statutory obligations – least of all after a court has prohibited the clause.
- Authority / court
- Ministerio de Derechos Sociales, Consumo y Agenda 2030
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Artt. 82, 87.5 y 87.6 TRLGDCU (Real Decreto Legislativo 1/2007)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Repeat case
- yes
- Published
- 29 Jul 2026
- Consumo sanciona con un millón de euros a la empresa de alquiler de coches Avis por prácticas abusivas Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jul 2026 Österreichischer Rundfunk (ORF)KommAustria finds unlabelled product placement in ORF's ‘Sport aktuell’ Order
In the programme ‘Sport aktuell’ on ORF 1 on 29 July 2025, a logo wall was visible as product placement without being labelled. The Austrian Communications Authority (Kommunikationsbehörde Austria, KommAustria) found, with final effect, a violation of the ORF Act (ORF-Gesetz).
Product placements must be identified and labelled by the editorial team – including logo walls in the background.
Labelling of advertising and product placement
- Authority / court
- Kommunikationsbehörde Austria (KommAustria)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 16 Abs. 5 Z 4 ORF-G
- Action
- Order
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 29 Jul 2026
- KommAustria, Entscheidung 2025-0.606.040-3-A (ORF, Sport aktuell) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Jul 2026 TrenitaliaTrenitalia removes hurdles to refunds for delays following AGCM proceedings Order
For refunds in the event of delays of 60 minutes or more or cancellations, Trenitalia required prior written confirmation from the call centre or ticket office. The AGCM accepted binding commitments: abolition of the confirmation requirement, strengthened refund channels, an information page on disruptions and an implementation report within three months; no infringement was found.
Additional formalities before statutory refunds act as a hurdle and lead to proceedings.
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Codice del Consumo (impegni); EU-Fahrgastrechte im Eisenbahnverkehr
- Action
- Order
- Status of proceedings
- final
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- Binding commitments, no finding of an infringement.
- Published
- 30 Jul 2026
- PS13019 - Trenitalia, accolti impegni su ostacoli ai rimborsi per ritardi prolungati e cancellazioni treni Press release of an authority
- AGCM Provvedimento PS13019 (Trenitalia), Annahme der Zusagen, adunanza del 28 luglio 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2026 GoogleDMA: 890 million EUR against Google over self-preferencing and Play steering €890m
In two decisions, the European Commission found that Google favours its own services in search (460 million EUR) and prevents app developers on Google Play from steering customers to alternative offers (430 million EUR). Google was ordered to bring the infringements to an end.
Platforms' ranking rules and fee models must be demonstrably non-discriminatory and designed in compliance with the Digital Markets Act (DMA).
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/1925 (DMA), Selbstbevorzugungsverbot und Anti-Steering-Pflicht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 23 Jul 2026
- Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
- IP/26/1670: Commission fines Google €890 million for breaches of the Digital Markets Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Maxxis International GmbH, Best4Tires Berlin GmbH, Reifen Müller GmbH & Co. KGBundeskartellamt: 11.9 million EUR over resale price maintenance in tyre distribution (Maxxis/CST) €11.9m
Maxxis guaranteed wholesalers fixed margins per tyre sold of the Maxxis and CST brands, monitored prices in particular on the Tyre24 platform and intervened when prices were too low. Germany's Federal Cartel Office (Bundeskartellamt) imposed fines totalling 11.9 million EUR on three companies and one responsible individual.
Margin guarantees and price controls vis-à-vis dealers constitute prohibited resale price maintenance – sales teams need clear rules for price discussions.
Influencing resale prices and price monitoring on platforms
- Authority / court
- Bundeskartellamt
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- § 1 GWB (vertikale Preisbindung)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Mitigating circumstances
- Settlement with Maxxis and Reifen Müller
- Liability of senior managers
- Fine imposed on one responsible natural person (not named)
- Published
- 21 Jul 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jul 2026 AliExpressDSA: 550 million EUR against AliExpress over illegal and unsafe products €550m
AliExpress did not diligently assess the risks posed by illegal, unsafe and counterfeit products (including insufficient moderation capacity, recommender and advertising systems) and did not take effective countermeasures (including deficient enforcement of sanctions against traders, product checks that could be circumvented). The European Commission imposed 550 million EUR under the Digital Services Act (DSA) and required an action plan by 20 October 2026.
The size of a marketplace does not justify gaps: moderation capacity and sanctions against traders must match the actual risk.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Risikobewertung und Risikominderung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Novelty of the Digital Services Act (taken into account by the Commission when setting the fine)
- Published
- 20 Jul 2026
- Commission fines AliExpress €550 million for breaching the Digital Services Act Press release of an authority
- IP/26/1654: Commission fines AliExpress €550 million for breaching the Digital Services Act Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay €240,000
Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.
Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.
Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Published
- 20 Jul 2026
- TeamViewer SE: BaFin setzt Geldbuße fest Decision of an authority
- Bekanntmachung der BaFin zur TeamViewer SE (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jul 2026 BGH: online cancellation page must not offer a "pause contract" alternative Order
On the confirmation page of its online cancellation process, a gym operator displayed a highlighted notice with the button "Pause contract via self-service"; in addition, the confirmation button was labelled "Find contract", which the defendant had already acknowledged. In an action brought by the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband), the BGH ruled that the confirmation page may only contain the information required for the cancellation and the confirmation button, set aside the judgment of the Higher Regional Court of Düsseldorf (OLG Düsseldorf) dismissing the action to that extent and ordered the operator to cease and desist.
Keep retention or pause offers off the confirmation page of the online cancellation process.
Design of the cancellation process (cancellation button, retention offers)
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 200/25
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- § 312k Abs. 1 Satz 1, Abs. 2 BGB (Kündigungsbutton)
- Action
- Order
- Status of proceedings
- final
- Sector
- Other
- Published
- 16 Jul 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jul 2026 CalPlus GmbH, Elektronik-Kontor Messtechnik GmbH, TVW Meßtechnik GmbHBundeskartellamt: 453,000 EUR against distributors of test and measuring equipment €453,000
From 2016 to 2022, three distributors of test and measuring equipment coordinated discounts as essential price components and informed each other of customer contacts, usually with a request for "restraint". This was evidenced by more than 400 emails; the proceedings ended in settlements.
Small distributors are liable too: merely asking a competitor to "hold back" with a customer is a prohibited customer allocation agreement.
Email contacts with competitors about customers and discounts
- Authority / court
- Bundeskartellamt
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- § 1 GWB
- Action
- Fine
- Status of proceedings
- final
- Sector
- Manufacturing and mechanical engineering
- Mitigating circumstances
- Settlement; cooperation by Elektronik-Kontor Messtechnik taken into account
- Published
- 15 Jul 2026
- Bundeskartellamt verhängt Bußgelder wegen Preisabsprachen beim Vertrieb von Prüf- und Messgeräten Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jul 2026 Goldwin LtdMalta: 80,907 EUR against online casino Goldwin for missing customer risk assessment €80,907
The 2022 examination revealed that for more than two years the remote gaming operator had had no proper customer risk assessment for almost its entire player base; the assessments submitted had been prepared specifically for the examination. In addition, once players reached the deposit threshold of 2,000 EUR, it did not check in good time whether they were politically exposed persons. The Financial Intelligence Analysis Unit (FIAU) imposed 80,907 EUR; the fine was still open to appeal at the time of publication.
Supervisory authorities see through risk assessments prepared only for the examination – they must be applied in day-to-day business.
Risk-based customer assessment in gambling
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Reg. 5(5)(a)(ii), 11(5), 21 PMLFTR; FIAU Implementing Procedures Part I und II (Remote Gaming)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 16 Jul 2026
- Administrative Measure Publication Notice – Goldwin Ltd Decision of an authority
- Publication of AML/CFT Administrative Penalties and Measures – FIAU Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2026 Volksbank Düsseldorf Neuss eGBaFin: 210,000 EUR against Volksbank Düsseldorf Neuss over monitoring and reporting gaps €210,000
Germany's Federal Financial Supervisory Authority (BaFin) imposed fines totalling 210,000 EUR on the cooperative bank: business relationships were not monitored on an ongoing basis or with enhanced scrutiny, additional information was not obtained and suspicious activity reports were not filed or were filed late. The function of the money laundering reporting officer had been outsourced to an external service provider with several clients.
Institutions that outsource the anti-money laundering function remain responsible themselves for ongoing monitoring and timely suspicious activity reports.
Ongoing monitoring of business relationships and suspicious activity reporting
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 56 Abs. 1 S. 1 Nr. 20, 36, 38 und 69 GwG; Bekanntmachung nach § 57 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 17 Sep 2026
- Volksbank Düsseldorf Neuss eG: Bafin setzt Bußgelder fest Press release of an authority
- Bekanntmachung zur Volksbank Düsseldorf Neuss eG (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2026 Brown Capital Management LLCBrown Capital Management: voting rights notifications not submitted on time €187,500
The Baltimore-based US asset manager had not submitted voting rights notifications to the issuer and BaFin in time; the deadline is four trading days after reaching a notifiable threshold. BaFin imposed a fine of 187,500 EUR; the notice is final.
Anyone investing in German issuers needs automated threshold monitoring with clear responsibility for the four-day deadline.
Threshold monitoring and notification deadlines for shareholdings
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- § 33 Abs. 1 Satz 1 WpHG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 22 Jul 2026
- Brown Capital Management LLC: BaFin setzt Geldbußen fest Decision of an authority
- Bekanntmachung der BaFin zur Brown Capital Management LLC (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Unternehmen mit drei Dienstfahrzeugen (in der Mitteilung nicht namentlich genannt)Administrative Court upholds ban on continuous GPS tracking of three company vehicles Order
The data protection authority had prohibited a company from tracking its three company vehicles continuously by GPS and ordered the data to be erased; narrow purposes such as theft protection while parked remained permitted. The Upravno sodišče Republike Slovenije (Administrative Court of the Republic of Slovenia) upheld this and clarified that employee consent bundled with other declarations is invalid.
Employee consent rarely supports monitoring – and never when it is bundled with other declarations in the form.
Consent and proportionality in employee monitoring
- Authority / court
- Upravno sodišče Republike Slovenije (bekanntgemacht durch den Informacijski pooblaščenec)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 7 Abs. 2 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 7 Jul 2026
- Upravno sodišče znova potrdilo prakso IP: sistematično GPS sledenje zaposlenim ni dopustno brez tehtnega razloga Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 SIA 4YOU MEBELESFurniture retailer 4YOU MEBELES ignores cookie inspection – first a reprimand, then 1,000 EUR €1,000
In a targeted inspection of cookies on company websites, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) found fault with the site 4mebeles.lv. After a reprimand in February 2026, the company claimed that the deficiencies had been remedied, which a further inspection disproved; further requests for information went unanswered. The DVI imposed 1,000 EUR for failure to cooperate and requested the missing information by 3 August 2026.
Assurances given to the supervisory authority are checked – false statements and silence aggravate the sanction.
Cookie banners and cooperation with the supervisory authority
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Repeat case
- yes
- DVI Lēmums Par soda piemērošanu (SIA 4YOU MEBELES), 02.07.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 Moody's Deutschland GmbHESMA fines Moody's Deutschland 2.1 million EUR €2.15m
The credit rating agency did not submit up-to-date rating information to the European Securities and Markets Authority (ESMA), did not provide complete historical performance data to the central repository and lacked adequate procedures and internal control mechanisms. ESMA found negligent infringements and imposed fines totalling 2,145,000 EUR.
Reporting obligations to the supervisory authority are data quality issues – without functioning internal controls, they become a risk of fines.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EG) Nr. 1060/2009 (CRA-Verordnung), Art. 24, 36a, Anhang III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – Moody's Deutschland GmbH (ESMA43-857238790-2075) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Jun 2026 „Paysera LT“, UABPaysera: daily fine for missing annual accounts adds up to 362,000 EUR €362,000
Because Paysera did not comply with the order to submit its 2024 annual financial statements by 30 September 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) first imposed 20,000 EUR in November 2025 and then a daily fine of 1,000 EUR (rising to 2,000 and 3,000 EUR respectively). As the infringement was only remedied after 6 May 2026, the daily fine added up to 362,000 EUR. Source: archived copy of the press release.
Running daily fines make every delay expensive – supervisory orders need top-management priority.
- Authority / court
- Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Aufsichtsrechtliche Anordnung und Berichtspflichten nach litauischem E-Geld-Recht
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Published
- 30 Jun 2026
- Lietuvos bankas, Pranešimas 2026-06-30 (Archivkopie web.archive.org von lb.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jun 2026 Banque Degroof Petercam SABanque Degroof Petercam: 1 million EUR settlement over hidden costs in employee stock options €1m
In stock option plans for employees of client companies (2018–2023), the bank did not fully inform the beneficiaries about costs, had initially not recorded the conflicts of interest in this business and assessed clients’ knowledge only with a yes/no question. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 1 million EUR with publication by name and commitments on cost information.
Full cost transparency and a dedicated conflicts register also apply to ancillary business such as employee stock option plans.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi du 2 août 2002; Wohlverhaltensregeln (Loyalität, Kostentransparenz, bestmögliche Ausführung, Interessenkonflikte, Kundenkenntnis)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- Remediation of all deficiencies (appropriateness test, conflicts policy, cost disclosure, waiver of CVA/KVA discounts).
- Published
- 26 Jun 2026
- FSMA – Règlement transactionnel Banque Degroof Petercam (26.06.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jun 2026 Neonet S.A.Neonet: 3 million PLN over false delivery and availability information on Allegro €709,854
On its Allegro account, the electronics retailer promised dispatch within 24 hours even for goods not in stock and did not inform customers in good time of delays or unavailability. UOKiK imposed a fine of 3,043,000 PLN; the decision is not final.
Link delivery and availability information to stock levels; in the event of delays, inform customers immediately.
Availability and delivery information on marketplaces
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Verletzung kollektiver Verbraucherinteressen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 26 Jun 2026
Original amount 3,043,000 PLN, converted at the ECB reference rate of 26 Jun 2026.
- Empty promises from Neonet – decision by the President of UOKiK Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition €52,097
On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.
Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
- Published
- 2 Jul 2026
- КЗК Публичен електронен регистър – Производство (Решение № 591 от 25.06.2026; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2026 TotalEnergiesParis Judicial Court: TotalEnergies must include Scope 3 emissions in vigilance plan Order
In an action brought by Notre Affaire à Tous, Sherpa, ZEA, France Nature Environnement and the City of Paris, the Paris Judicial Court (Tribunal judiciaire de Paris, 34th chamber) ruled that climate risks fall under the French duty of vigilance law and that Scope 3 emissions are part of the oil and gas group's activities. The vigilance plan without Scope 3 is incomplete, the court held; TotalEnergies must supplement it within six months, with provisional enforceability, and implementation will be reviewed by the court in January 2027.
Risk analyses under due diligence laws must also cover the climate impact of the products sold (Scope 3).
- Authority / court
- Tribunal judiciaire de Paris (34. Kammer)
- Area of law
- Supply chain and human rights · Supply chain due diligence
- Legal basis
- Art. L.225-102-1 und L.225-102-2 Code de commerce (Loi n° 2017-399, devoir de vigilance); Art. 1252 Code civil
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Employees
- 10,000 or more
- Published
- 25 Jun 2026
- Communiqué de presse – Jugement du 25 juin 2026, 34ème chambre Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Ö Aktiengesellschaft (in der Entscheidung abgekürzt; Adressverlag und Direktwerbeunternehmen)VwGH sets data protection fine for party affinities definitively at 13 million EUR €13m
The company had stored statistically calculated ‘party affinities’ for around 2.2 million people and in some cases sold them to advertising clients – special categories of personal data without consent; in addition, parcel frequency data was further processed for incompatible purposes. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) had imposed 18 million EUR in 2019 and the Federal Administrative Court (Bundesverwaltungsgericht, BVwG) 16 million EUR in 2024; Austria's Supreme Administrative Court (Verwaltungsgerichtshof, VwGH) has now set the fine with final effect at 13 million EUR (plus 100,000 EUR in procedural costs).
Calculated characteristics such as political leanings are themselves special categories – companies that derive them for advertising need explicit consent.
- Authority / court
- Verwaltungsgerichtshof (Ausgangsbescheid: Datenschutzbehörde)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 4, Art. 9 Abs. 1 (VwGH Ro 2025/04/0007)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Comprehensive cooperation, deletion of the party affinities, settlements with data subjects, long duration of proceedings (5 years, 10 months).
- Published
- 16 Jul 2026
- VwGH 24.06.2026, Ro 2025/04/0007 Court decision
- VwGH bestätigt unrechtmäßige Verarbeitung von Partei-Affinitäten und setzt Geldbuße mit EUR 13 Mio. fest Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Kaufland Hrvatska k.d.Croatia: 300,000 EUR against Kaufland for unfair practices towards suppliers €300,000
The Agencija za zaštitu tržišnog natjecanja (Croatian Competition Agency, AZTN) found that Kaufland Hrvatska charged food suppliers fees for services not provided and for advertising not commissioned, and paid for perishable goods only after more than 30 days. For these unfair trading practices, and with repeat offending as an aggravating factor (final penalty already in 2020), it imposed 300,000 EUR (date = publication).
Purchasing departments must know the payment deadlines and fee prohibitions of UTP law – repeat offences become significantly more expensive.
Fair terms towards suppliers in purchasing
- Authority / court
- Agencija za zaštitu tržišnog natjecanja (AZTN)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 4, 11, 12 Zakon o zabrani nepoštenih trgovačkih praksi u lancu opskrbe hranom (ZNTP)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Repeat case
- yes
- Published
- 24 Jun 2026
- AZTN kaznio KAUFLAND HRVATSKA k.d., Zagreb s 300.000,00 eura zbog nametanja nepoštenih trgovačkih praksi Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jun 2026 Meta Platforms Ireland LimitedMeta: infringement of the P2B Regulation after fashion retailer’s Facebook page was hacked Order
After the Facebook page of the Danish fashion retailer Clothing By Ros ApS was hacked in 2023, Meta failed to respond appropriately for almost two years, gave no reasons for the de facto suspension and offered no effective complaint-handling procedure. The Konkurrencerådet (Danish Competition Council) found infringements of the P2B Regulation and ordered Meta to comply with the rules on statements of reasons and complaint handling in future.
Platform operators must give reasons for suspending business users and handle complaints promptly – silence counts as a decision in its own right.
- Authority / court
- Konkurrencerådet (Danish Competition Council)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2019/1150 (P2B) Art. 4, Art. 11
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 24 Jun 2026
- KFST – The Competition Council rules against Meta (24.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2026 Deghi S.p.A.Deghi: 2 million EUR for endlessly renewing countdown discounts €2m
From January 2024 to December 2025, the online retailer advertised time-limited discounts with countdown timers which, once they had expired, restarted with a new timer on identical terms. The AGCM classified this artificial scarcity as a particularly insidious dark pattern and imposed a fine of 2 million EUR.
A countdown must genuinely expire – an automatically restarting timer creates misleading scarcity.
False urgency and countdown timers in online marketing
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Codice del Consumo (pratiche commerciali scorrette)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 25 Jun 2026
- PS13027 - E-commerce, sanzione di 2 milioni di euro a Deghi S.p.A. per pratica commerciale scorretta Press release of an authority
- AGCM Provvedimento PS13027 (Deghi S.p.A.), adunanza del 23 giugno 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2026 VARTA AGVARTA: late ad hoc announcement and missing half-yearly financial report €620,000
BaFin imposed fines on the battery manufacturer because it had not disclosed inside information without delay and had not published the half-yearly financial report for the 2024 financial year.
Ad hoc assessments and periodic disclosure require fixed responsibilities and deadline controls so that neither inside information nor mandatory reports are left pending.
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Art. 17 Abs. 1 UAbs. 1 MAR; § 115 Abs. 1 Satz 1 WpHG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Manufacturing and mechanical engineering
- Published
- 1 Jul 2026
- VARTA AG: BaFin setzt Geldbußen fest Decision of an authority
- Bekanntmachung der BaFin zur VARTA AG (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jun 2026 Banca Popolare Commerciale SpaBanca d'Italia: 40,000 EUR against Banca Popolare Commerciale over AML deficiencies €40,000
Following an on-site inspection from February to April 2025, the Bank of Italy (Banca d'Italia) found deficiencies in customer due diligence, active cooperation (suspicious transaction reporting) and anti-money laundering controls, and imposed an administrative fine of 40,000 EUR. The duration of the deficiencies and the corrective measures initiated were taken into account.
Gaps in customer due diligence and suspicious transaction reporting are consistently sanctioned after on-site inspections, even with smaller amounts – corrective measures reduce the sanction but do not replace it.
Customer due diligence and suspicious transaction reports
- Authority / court
- Banca d'Italia
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 62 d.lgs. 231/2007; Verstöße gegen Art. 7, 16–19, 24, 25, 35, 36 d.lgs. 231/2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Corrective measures initiated
- Banca Popolare Commerciale Spa – Provvedimento n. 190 del 23 giugno 2026 (AML) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jun 2026 Ikano Bank ABIkano Bank: 140 million SEK over deficiencies in money laundering risk assessment and customer due diligence €12.9m
For the period April 2022 to May 2023, the Swedish financial supervisory authority Finansinspektionen (FI) found that the bank’s general risk assessment did not realistically assess the terrorist financing risks of its corporate products and that no enhanced due diligence measures were taken for high-risk corporate customers. FI issued a remark and imposed 140 million SEK; the bank has brought an action before the administrative court.
The money laundering risk assessment must reflect the actual customers and products – a generic assessment leaves the entire customer due diligence open to challenge.
Enhanced due diligence for high-risk customers
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 17 Jun 2026
Original amount 140,000,000 SEK, converted at the ECB reference rate of 17 Jun 2026.
- FI ger Ikano Bank en anmärkning och en sanktionsavgift (17.06.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Jun 2026 Securitas Sverige AktiebolagSecuritas Sverige: reprimand over cameras in company vehicles without legal basis Reprimand or warning
The security services provider used cameras in vehicles through which personal data was processed without any legal basis for doing so. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) issued a reprimand under Art. 58 GDPR; no fine was imposed.
Dashcams in company cars also need a verified legal basis and a balancing against the interests of employees and passers-by.
Use of cameras in vehicles
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 6 Abs. 1
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Defence and security
- IMY – Tillsyn Securitas Sverige Aktiebolag Decision of an authority
- IMY – Beslut Securitas Sverige AB Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR €1,948
An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.
Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.
Access to surveillance rooms; staff bound by instructions
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 15 Jun 2026
Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.
- ANSPDCP – Comunicat de presă 15.06.2026 (SSG SELECT SOLUTIONS S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Verkkokauppa.com OyjKHO confirms fine against Verkkokauppa.com over customer accounts without time limit €792,639
The online retailer had not set a retention period for customer accounts and kept data until customers requested deletion; purchases were only possible with an account. The sanctions board of the Finnish Data Protection Ombudsman imposed 856,000 EUR in 2024, the administrative court reduced the fine to 792,639 EUR on the basis of current turnover, and the Supreme Administrative Court (Korkein hallinto-oikeus, KHO) confirmed this on 12 June 2026.
Do not leave deletion to the customer – every online shop needs defined retention periods for accounts and order data.
- Authority / court
- Korkein hallinto-oikeus (KHO); Sanktionsgremium des Datenschutzbeauftragten
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Retail and e-commerce
- Published
- 18 Jun 2026
- Supreme Administrative Court upholds the administrative fine imposed on Verkkokauppa.com Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Jun 2026 Μάρκετ Ιν ΑΕΒΕ (Market In)Greece: 95,000 EUR against supermarket chain Market In over video footage €95,000
A data subject complained about the disclosure of footage from the supermarket chain’s video surveillance and about the inadequate response to his access request. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that Market In had passed the video footage to the judicial authorities without informing the data subject beforehand, processed more data than necessary, failed to comply with the right of access and failed to cooperate with the authority, and by Decision 10/2026 imposed a total of 95,000 EUR (50,000 EUR for lawfulness/transparency, 20,000 EUR each for data minimisation and the right of access, 5,000 EUR for failure to cooperate); in the same proceedings, ΜΕΔΕ ΑΕ received 65,000 EUR.
Release video footage only for a specific purpose – and anyone ignoring requests from the supervisory authority pays extra.
Handling video footage and access requests
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 5 Abs. 1 lit. a, c, Art. 5 Abs. 2, Art. 12, 13, 15, 31 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Απόφαση 10/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jun 2026 Deutsche Wohnen SELG Berlin I confirms GDPR infringement by Deutsche Wohnen through tenant archive without deletion function Fine
In 2019, the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) had imposed 14.5 million EUR on the housing group because tenant data such as salary statements, bank statements and social security data were held in an archive system with no means of deletion. Following the 2023 CJEU judgment on direct corporate liability, the Berlin Regional Court (Landgericht Berlin I) confirmed on 9 June 2026 infringements of data minimisation and storage limitation; the press release does not state the amount of the fine set by the court.
Ensure that archive and filing systems can technically implement deletion periods from the outset – ‘privacy by design’ is subject to fines.
- Authority / court
- Landgericht Berlin I (Bußgeldbehörde: Berliner Beauftragte für Datenschutz und Informationsfreiheit)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5, Art. 25 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Liability of senior managers
- According to the CJEU (C-807/21), a breach of duty by a person in a management position need not be proven for the corporate fine.
- Published
- 10 Jun 2026
- Landgericht Berlin bestätigt Verstoß der Deutsche Wohnen SE gegen die DSGVO Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jun 2026 A. Tsokkos Hotels Public LimitedCyprus: 16,500 EUR against A. Tsokkos Hotels for late annual financial report €16,500
The listed hotel group did not publish its 2024 annual financial report on time; the Cyprus Securities and Exchange Commission (CySEC) imposed a total of 16,500 EUR. At the same meeting, eleven other issuers were fined between 1,500 and 17,000 EUR for the same reason; a fine of 13,500 EUR had already been imposed on the company under the same law in 2025.
Publication deadlines for financial reports are not negotiable – repeated delays lead to fines and, in extreme cases, to suspension of trading.
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Sec. 9(1), 37(2)(a) Transparency Requirements (Securities Admitted to Trading on a Regulated Market) Law 2007
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Published
- 7 Aug 2026
- CySEC Board Decision – Fines under the Transparency Requirements Law (08.06.2026) Decision of an authority
- CySEC Board Decision – Fines under the Transparency Requirements Law (14.07.2025, Jahresbericht 2023) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Portugal: 8.18 million EUR against three companies over advertising in TV recordings €8.18m
With the support of a consultancy, the three largest pay-TV providers agreed from 2019 to May 2025 to introduce advertising as a condition for accessing recordings and to standardise the marketing of this advertising space. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,181,000 EUR on three companies; together with the fourth participant, already sanctioned earlier under a settlement, the fines add up to 13,351,000 EUR. Owing to ongoing court proceedings, the AdC did not publish the names in its announcement.
Jointly coordinated ‘industry solutions’ at customers’ expense are cartels – even when a service provider takes on the coordination.
Coordinated product changes among competitors
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º (Processo PRC/2020/4)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 5 Jun 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2026 Εταιρεία Προμήθειας Αερίου Θεσσαλονίκης Θεσσαλίας Α.Ε. („ZeniΘ“) und Τράπεζα Πειραιώς Α.Ε. (Piraeus Bank)Greece: 110,000 EUR against energy supplier ZENITH and Piraeus Bank (right of access) €110,000
Due to errors by a processor of the energy supplier, incorrect details of a direct debit mandate were recorded, so that three bills instead of one were debited from the customer's account; call recordings and the mandate form had not been retained. ZENITH responded inadequately to the access request and did not correct the data (100,000 EUR), while Piraeus Bank infringed the right of access (10,000 EUR and a reprimand); Decision No. 8/2026 of the Hellenic Data Protection Authority.
Answer access requests in full and retain records of mandates – this also applies to data recorded by a service provider.
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic DPA)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. d, Art. 12 Abs. 3, Art. 15, Art. 28 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Επιβολή προστίμου σε πάροχο ηλεκτρικής ενέργειας και σε τράπεζα για παραβάσεις του ΓΚΠΔ (Απόφαση 8/2026) Decision of an authority
- Αρχή Προστασίας Δεδομένων – Απόφαση 8/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Jun 2026 VF Hellas Ενδυμάτων Ε.Π.Ε. (VF Hellas, Tochter der VF Corporation)Greece: 954,485 EUR against VF Hellas for banning price comparison and Google Ads €954,485
The importer and wholesaler of the Vans, Eastpak and The North Face brands contractually prohibited its retailers from using price comparison portals and search engine advertising (in particular Google Ads). The Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) regarded this as a hardcore restriction in online sales and, in a settlement procedure (Decision 913/2026), set a reduced fine of 954,485 EUR; date = press release.
Prohibiting retailers from using price comparison sites or search engine advertising is a hardcore restriction – distribution agreements should regularly undergo competition law review.
Competition-law-compliant design of dealer agreements in online sales
- Authority / court
- Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 1 Gesetz 3959/2011; Art. 101 AEUV; Art. 4 lit. e VO (EU) 2022/720
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Settlement procedure (Diettheti Diaforon) with fine reduction
- Published
- 3 Jun 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 May 2026 TemuDSA: 200 million EUR against Temu over deficient risk assessment of illegal products €200m
Temu's 2024 risk assessment was based on general industry data rather than on findings about its own service and underestimated how often EU consumers encounter illegal products; test purchases revealed unsafe chargers and baby toys. The European Commission imposed 200 million EUR under the Digital Services Act (DSA) and required an action plan by 28 August 2026.
Risk assessments must be based on the company's own, service-specific evidence – generic industry analyses are not sufficient.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Risikobewertungspflichten sehr großer Online-Plattformen; Art. 75
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 28 May 2026
- Commission fines Temu €200 million for breaching the Digital Services Act Press release of an authority
- IP/26/1178 Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2026 Soltec Power Holdings, SASoltec: incorrect 2023 annual figures reported to the market €190,000
The manufacturer of solar tracking systems disseminated its results for 2023 by way of an "Otra Información Relevante" announcement containing inaccurate information. Spain's National Securities Market Commission (CNMV) imposed a fine of 190,000 EUR for a serious infringement; the company waived administrative appeals.
Voluntary market announcements on results are also subject to MAR – figures must be reconciled before publication.
- Authority / court
- Comisión Nacional del Mercado de Valores (CNMV)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Art. 297.1.e i. V. m. 297.2.d Ley 6/2023; Art. 17 i. V. m. Art. 7 MAR
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 3 Aug 2026
- Resolución de 17 de julio de 2026 (BOE-A-2026-16923) – sanción a Soltec Power Holdings, SA Official register or notice
- CNMV – Registro público de sanciones Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 May 2026 Mediaworks Hungary Zrt.Mediaworks Hungary: 50 million HUF for links to leaked map of party supporters €140,706
On 7 November 2025, the publisher's news portals Origo and Magyar Nemzet linked to a map, created by unknown persons, containing the names, addresses, telephone numbers, email addresses, geo-coordinates and political preferences of Tisza sympathisers; Ripost showed an image with the name of the map. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found intentional infringements of Art. 6 and 9 GDPR, prohibited further dissemination and imposed 50 million HUF.
Linking to leaked data is itself a separate processing operation – editorial teams need a data protection review before publication.
Handling leaked personal data in newsrooms
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 58 Abs. 2 lit. b und f (NAIH/962-10/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- intentional
- Published
- 26 May 2026
Original amount 50,000,000 HUF, converted at the ECB reference rate of 26 May 2026.
- NAIH/962-10/2026 – Határozat (Mediaworks Hungary Zrt.) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 May 2026 Robomarkets LtdCyprus: Robomarkets pays 100,000 EUR under settlement over CFD sales to retail clients €100,000
For the period June 2023 to June 2024, the Cyprus Securities and Exchange Commission (CySEC) examined the investment firm’s organisational requirements, client information, appropriateness assessment and compliance with the restrictions on marketing CFDs to retail investors. The proceedings were concluded with a settlement of 100,000 EUR, which the company has already paid.
When selling CFDs to retail clients, the appropriateness assessment and product intervention rules are central points of supervisory scrutiny.
Appropriateness assessment when selling complex products
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 22(1), 25(1), 26(3) Gesetz über Wertpapierdienstleistungen 2017; Art. 42 VO (EU) 600/2014; CySEC-Richtlinie DI87-09; Art. 37(4) CySEC-Gesetz
- Action
- Other
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 24 Aug 2026
- CySEC Board Decision – Robomarkets Ltd – Settlement €100.000 Decision of an authority
- CySEC Board Decisions Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 May 2026 Wind Tre S.p.A.Garante: 1.7 million EUR against Wind Tre after data exfiltration via deceived shop staff €1.72m
Attackers posed as technical support, induced staff at points of sale to grant system access and obtained data on more than 365,000 customers, including payment data for 41,359 of them. The Italian data protection authority (Garante per la protezione dei dati personali) criticised deficient management of access credentials and digital certificates as well as inadequate security assessments, and imposed 1,715,600 EUR.
Staff in branches and partner shops must verify alleged support calls before granting access.
Social engineering / fake IT support
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO (Integrität und Vertraulichkeit, Art. 32)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 16 Jul 2026
- Newsletter del 16 luglio 2026 – Data breach, il Garante privacy sanziona Wind Tre per 1,7 milioni di euro Press release of an authority
- Garante – Provvedimento del 14 maggio 2026 [10263796] (Wind Tre) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 May 2026 Oma Säästöpankki OyjOma Säästöpankki: 400,000 EUR over late and incomplete insider lists €400,000
The bank failed to draw up insider lists in good time for two pieces of inside information (termination of the core banking project with Cognizant in 2021, merger talks with Liedon Säästöpankki in 2022), did not update them and omitted mandatory information. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 400,000 EUR; the decision was not appealed and is final.
Insider lists must be created from the moment inside information exists – a fixed process with designated responsible persons prevents gaps.
Insider lists and handling of inside information
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Market abuse and insider dealing
- Legal basis
- Verordnung (EU) Nr. 596/2014 (MAR) Art. 18 Abs. 1, 3 und 4; Durchführungsverordnung (EU) 2016/347
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Measures to prevent recurrence and partial admission/cooperation had a mitigating effect.
- Published
- 15 May 2026
- Finanssivalvonta – Oma Säästöpankki Oyj:lle 400 000 euron yhteinen seuraamusmaksu (15.5.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2026/227 vom 13.05.2026 (Oma Säästöpankki Oyj) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 May 2026 Société Wallonne des Eaux (SWDE)SWDE: 86,000 EUR for call recordings without sufficient transparency €86,000
The Walloon water utility recorded and listened in on customer calls for quality control and training purposes; the Litigation Chamber of the Autorité de protection des données (Belgian Data Protection Authority, APD/GBA) found infringements of transparency and fairness as well as in the engagement of a sub-processor. It imposed two fines totalling 86,000 EUR (85,000 + 1,000) after reducing the amounts in view of the situation of the public utility; an appeal against the decision has been lodged with the Market Court.
Anyone recording customer calls must clearly communicate purpose, legal basis and the parties involved in advance and engage service providers under proper contracts.
Recording of customer calls
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 12 Abs. 1, Art. 13, Art. 28 Abs. 3
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- APD – Décision quant au fond n° 102/2026 du 12 mai 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 May 2026 Permanent TSB plcDPC: 277,500 EUR against Permanent TSB after account takeovers via call centre calls €277,500
Fraudsters in possession of customer data posed as customers at the bank's ‘Open24’ call centre, had account details changed and obtained further information because security protocols were not followed; those affected had to close accounts, and some suffered losses. Ireland's Data Protection Commission (DPC) imposed 250,000 EUR for inadequate security and 27,500 EUR for late breach notification (decision served in the week before the press release).
Call centre staff must adhere to identity checks without exception – callers with ‘matching’ data are not automatically authorised.
Identity verification by telephone (vishing)
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 8 May 2026
- Data Protection Commission Publishes Final Decision Following Inquiry into Permanent TSB Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 May 2026 HP TRONIC Zlín, spol. s r.o.HP TRONIC Zlín: 39 million CZK for price requirements imposed on electronics retailers €1.6m
For more than ten years from 2012, the distributor and retailer of consumer electronics and household appliances set minimum resale prices for its retail customers, monitored them and sanctioned deviations. The Úřad pro ochranu hospodářské soutěže (Czech Office for the Protection of Competition, ÚOHS) imposed 38.971 million CZK; a leniency application, settlement and an improved compliance programme reduced the fine, and the company appealed against the amount.
Reprimanding retailers over low prices risks high fines – an effective compliance programme can reduce them but is no substitute for ending the practice.
Resale price maintenance in sales
Missing or inadequate training played a role in the decision.
- Authority / court
- Úřad pro ochranu hospodářské soutěže (ÚOHS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Tschechisches Wettbewerbsgesetz, Art. 101 AEUV (S0551/2023)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Retail and e-commerce
- Culpability
- intentional
- Mitigating circumstances
- Leniency application, settlement and expansion of the internal compliance programme.
- Published
- 6 May 2026
Original amount 38,971,000 CZK, converted at the ECB reference rate of 6 May 2026.
- HP Tronic Faces Nearly CZK 40 Million Fine for Dictating Prices to Retailers Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 May 2026 P&V Assurances SCP&V Assurances: 150,000 EUR – distribution via a deregistered insurance intermediary €150,000
One of the insurer’s intermediaries was removed from the FSMA register in December 2023; owing to a human data entry error in the monitoring tool, P&V only noticed this after more than a month and concluded 34 contracts through him during that time. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 150,000 EUR; there had already been a settlement for the same amount in 2020.
Automated register checks are only as good as the underlying data maintenance – critical entries require a four-eyes principle.
Care in master data maintenance / register reconciliation
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi du 4 avril 2014 relative aux assurances, Art. 259
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- IT adjustments to prevent recurrence.
- Published
- 5 May 2026
- FSMA – Règlement transactionnel P&V Assurances SC (05.05.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Malta: insurer reprimanded again and fined – marketing calls despite objection €1,000
Although the Information and Data Protection Commissioner (IDPC) had already ruled in favour of a complainant, an insurance company (name redacted) again had him called for marketing purposes via a third-party company; his number remained on call lists. The IDPC criticised the lack of safeguards and inadequate contracts with processors, ordered remedial action within 20 days and imposed two fines totalling 1,000 EUR.
An objection to marketing must also reach all call centres engaged – otherwise the next complaint follows.
Passing marketing objections on to service providers (suppression lists)
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 2, Art. 21 Abs. 2, Art. 24 Abs. 1, Art. 28 Abs. 3 i. V. m. Art. 58 Abs. 2 lit. b, d, i DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- IDPC Commissioner's Decision (4. Mai 2026) Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 May 2026 Berliner Verkehrsbetriebe (BVG) AöRBlnBDI reprimands BVG: deletion at service provider not checked, data breach reported too late Reprimand or warning
A processor of Berlin's public transport operator BVG, which had sent customer letters in early 2025, was hacked; around 180,000 customer records were affected, although they should long since have been deleted after the end of the contract. BVG had never checked the deletion, had not agreed any procedure for data breaches in the data processing agreement and reported the incident only after the 72-hour deadline had expired; the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) issued a reprimand.
Have service providers prove deletion after the end of the contract, and have an internal procedure that immediately turns indications of a breach into a 72-hour notification.
Reporting process for data breaches and management of service providers
- Authority / court
- Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 5 Abs. 2 i. V. m. Abs. 1 lit. c, e, f, Art. 28 Abs. 3 S. 2 lit. f, Art. 32 Abs. 1, Art. 33 DSGVO
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Mitigating circumstances
- BVG has announced measures against similar incidents.
- Published
- 4 May 2026
- Datenschutzbeauftragte verwarnt BVG Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Apr 2026 „Вазовски машиностроителни заводи“ ЕАД (VMZ)Arms manufacturer VMZ used a partner’s know-how for disposable grenade launchers – 50,855 EUR €50,855
On application by the client Armar, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that VMZ had used technical documentation on disposable grenade launchers that had been provided in confidence (trade secret) contrary to the confidentiality agreements and good commercial practice (Art. 37(1) ZZK – Bulgarian Protection of Competition Act). Sanction of 50,855.09 EUR and obligation to cease, with immediate enforceability. Appeals have been lodged against the decision.
Design documents provided in confidence may only be used within the agreed scope – especially in sensitive industries.
Handling confidential know-how of business partners
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 37 Abs. 1 ZZK (Geschäftsgeheimnisse)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Defence and security
- КЗК Публичен електронен регистър – Производство (Решение № 389 от 30.04.2026; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Apr 2026 Amica Chips S.p.A., Pata S.p.A., Preziosi Food S.p.A.Italy: 23.3 million EUR against Amica Chips, Pata and Preziosi Food over snack cartel €23.3m
In a secret, continuing agreement, three manufacturers of salty snacks and crisps divided up among themselves the supply of private-label snacks to food retailers. Fines: Amica Chips 8,239,210 EUR, Pata 7,555,387 EUR, Preziosi Food 7,503,550 EUR; this was the first time Italy's competition authority (Autorità Garante della Concorrenza e del Mercato, AGCM) applied its settlement procedure.
Retailers' tenders for private labels are competition – coordinated sham bids to retailers constitute a cartel.
Sham bids in retailers' private-label tenders
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV; Art. 14-quater Gesetz 287/1990 (Settlement)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Mitigating circumstances
- Leniency reduction for Pata and Amica Chips; 10 % settlement discount for all
- Published
- 28 Apr 2026
- I871 - The Italian Competition Authority fines Amica Chips, Pata and Preziosi Food over €23 million Press release of an authority
- AGCM - Sanzioni per oltre 23 milioni di euro ad Amica Chips, Pata e Preziosi Food Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratóriíLaboratory cartel: 14.6 million EUR and procurement bans against diagnostic laboratories €14.6m
Four laboratories and their association coordinated negotiations on prices with health insurers, coordinated in tenders, exchanged sensitive information and allocated customers. At first instance, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 14,551,800 EUR and three-year procurement bans; Unilabs received a substantially reduced fine as leniency applicant and under a settlement.
Common negotiating positions towards payers via an association are a cartel – association meetings need minutes and a review of the agenda.
Information exchange among competitors and association work
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Unilabs: leniency reduction (50%) and settlement (a further 30%).
- Published
- 12 May 2026
- KARTELY: PMÚ odhalil kartel laboratórií a uložil pokuty takmer 15 miliónov eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Synadis Bio, Greenweez (mit Carrefour SA), ITM Entreprises (mit Les Mousquetaires), Les Comptoirs de la BioFrance: 12.67 million EUR over allocation of distribution channels for organic food €12.7m
Through the association Synadis Bio, market participants ensured for more than seven years that organic brands were not sold simultaneously in specialist organic shops and in conventional supermarkets, in order to prevent price comparisons (decision 26-D-05). Fines: Synadis Bio 10 million EUR, Greenweez/Carrefour 1.85 million EUR, ITM 740,000 EUR, Les Comptoirs de la Bio 80,000 EUR.
Association decisions that tie members to particular distribution channels amount to market sharing – even if they are justified as a quality or positioning policy.
Association rules to foreclose distribution channels
- Authority / court
- Autorité de la concurrence
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. L.420-1 Code de commerce, Art. 101 Abs. 1 AEUV; Bußgeldbemessung nach Art. L.464-2 Code de commerce
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Food and agriculture
- Published
- 16 Apr 2026
- L'Autorité de la concurrence sanctionne à hauteur de 12,67 millions d'euros (Entscheidung 26-D-05) Press release of an authority
- Décision 26-D-05 (version publique) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment Order
The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.
Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.
Consent and transparency for health data; cooperation with the supervisory authority
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data processors
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus isikuandmete kaitse asjas nr 2.1-1/24/397-890-38 (Fullgevity OÜ), 16.04.2026 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Apr 2026 Öffentliches Kommunalunternehmen (in der Mitteilung nicht namentlich genannt)Municipal company: 6,000 EUR for permanent GPS tracking of company vehicles €6,000
A provider of public utility services used GPS transmitters in company vehicles to record employees’ location data permanently and without cause, without defining a purpose, carrying out a balancing of interests or providing sufficient information. The Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP) imposed 6,000 EUR on the company and 600 EUR on the responsible person.
GPS data are not suitable for performance monitoring – consider less intrusive means before introduction and inform employees in advance.
GPS tracking and employee data protection
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Liability of senior managers
- Additional fine of 600 EUR on the responsible person.
- Published
- 15 Apr 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Apr 2026 Gyldendal A/SGyldendal: fine for storing data of 685,000 former book club members for years Fine
The publisher kept data of around 685,000 former book club members in a ‘passive database’, in around 395,000 cases more than ten years after they had left, without any deletion rules. The Danish Data Protection Agency (Datatilsynet) had recommended a fine of 1 million DKK in 2022; the case was closed on 14 April 2026 with a fine notice whose amount is not stated in the source.
‘Passive’ legacy data also needs a deletion concept – storage without a purpose is a separate infringement.
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 5 Abs. 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Mitigating circumstances
- Cooperative conduct; only two employees had access to the passive database; deletion after the supervisory visit.
- Datatilsynet – Gyldendal indstilles til bøde (Opdatering: afgjort 14. april 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Apr 2026 Arbeitgeber (in der Mitteilung nicht namentlich genannt)Slovenia: 71,474 EUR for covert monitoring of employees using spyware €71,474
An employer installed the software Spyrix Employee Monitoring on the work computers of individual employees, which for months recorded screen content, audio and even private e-mails and conversations without informing the employees. The supervisory authority, the Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia, IP), imposed 71,474 EUR on the company and 4,000 EUR on the responsible person.
Covert employee monitoring by software is practically never permissible – IT and managers must know this before tools are installed.
Permissible monitoring of employees and IT use
- Authority / court
- Informacijski pooblaščenec Republike Slovenije (IP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 und Art. 6 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- Liability of senior managers
- Additional fine of 4,000 EUR on the responsible person.
- Published
- 9 Apr 2026
- Delodajalcu, ki je prikrito nadzoroval vse aktivnosti zaposlenih na računalnikih, izrečena globa več kot 70.000 EUR Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Apr 2026 Wspólnota Mieszkaniowa K. (Wohnungseigentümergemeinschaft, im Bescheid pseudonymisiert)Homeowners’ association: 4,852 PLN – misdirected statement not notified €1,135
Acting as processor, the property management company sent an owner’s statement of service charges to an unauthorised person. The association considered notification unnecessary because only ‘ordinary’ data of one member were affected, and maintained this position in the proceedings; the UODO (Poland’s data protection authority) imposed 4,852 PLN.
Small controllers must also assess and notify data breaches by their service providers – ‘only one data subject’ is no ground for exemption.
Recognising misdirected mail as a data breach – including at service providers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
Original amount 4,852 PLN, converted at the ECB reference rate of 7 Apr 2026.
- UODO, Decyzja DKN.5131.16.2025 vom 07.04.2026 (rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Apr 2026 MLU B.V. (Rechtsnachfolgerin der Ridetech International B.V., Anbieterin der Yango-App)Yango taxi app: 100 million EUR for transferring data to Russia €100m
Amsterdam-based Ridetech offered the ride-hailing app Yango in Finland and Norway and transferred data of drivers and customers to the group companies Yandex.Taxi LLC and Yandex LLC in Russia without demonstrating appropriate safeguards. The Autoriteit Persoonsgegevens (Dutch Data Protection Authority, AP) imposed 100 million EUR on the legal successor and prohibited further transfers to Russia.
Transfers to states without legal protection against access by authorities can hardly be safeguarded – group structures with such locations need data localisation in the EU.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, Art. 46 iVm Art. 5 Abs. 1 lit. a und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR €125,083
In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).
Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 25 Mar 2026
Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.
- ANSPDCP – Comunicat de presă 25.03.2026 (RENAULT COMMERCIAL ROUMANIE S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 Familiam Asset Management OyFamiliam Asset Management: 70,000 EUR for 2,867 unreported securities transactions €70,000
Between September 2021 and August 2023, the asset manager failed to report a total of 2,867 transactions to the supervisory authority on time and in 2024 also submitted quarterly reports (FINREP) late. The Finanssivalvonta (Finnish Financial Supervisory Authority, FIN-FSA) imposed a total fine of 70,000 EUR; the admission had a mitigating effect.
Reporting obligations require deadline monitoring with a deputy arrangement – especially in small firms without their own reporting department.
Regulatory reporting
- Authority / court
- Finanssivalvonta (FIN-FSA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- MiFIR (VO (EU) 600/2014) Art. 26 Abs. 1; IFR (VO (EU) 2019/2033) Art. 54 Abs. 1; FIN-FSA-Vorschriften 20/2013 (FINREP)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Admission of the failures / cooperation.
- Published
- 25 Mar 2026
- Finanssivalvonta – Familiam Asset Management Oy:lle 70 000 euron yhteinen seuraamusmaksu (25.3.2026) Press release of an authority
- Finanssivalvonta – Toimituskirja FIVA/2025/1838 vom 25.03.2026 (Familiam Asset Management Oy) Decision of an authority
- Finanssivalvonta – Hallinnolliset seuraamukset (Übersicht mit Rechtskraftvermerk) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Mar 2026 SIA "Fitsypro"Fitsypro fails to answer access request and DVI enquiries – 1,500 EUR €1,500
A person complained that Fitsypro had not responded to their request for access, rectification and erasure of November 2023. Three requests for information from the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) between 2024 and 2026 went unanswered, and nobody attended the hearing. The DVI imposed 1,500 EUR and requested the information by 21 April 2026.
Official mailboxes (eAdrese) and data protection e-mail addresses must be monitored – silence towards the supervisory authority costs money.
Handling data subject requests and correspondence from authorities
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 58 Abs. 1 lit. e, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (SIA „Fitsypro“), 24.03.2026 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Mar 2026 Stanleybet Malta LimitedMalta: 225,730 EUR against betting operator Stanleybet over lack of customer checks in betting shops €225,730
Malta's Financial Intelligence Analysis Unit (FIAU) imposed 225,730 EUR, a penalty payment of 2,000 EUR per day and a follow-up directive on the licensed gambling operator, which works through a network of independently operated betting shops in an EU member state. The company was unable to link customers' cumulative deposits across different shops and only checked customers from a single deposit of 2,000 EUR upwards, so the threshold could be circumvented. The company has appealed.
Thresholds must be aggregated per customer across all channels and branches – otherwise the system invites structuring.
Recognising structured deposits below the checking threshold
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Regulation 21 PMLFTR; Verstöße gegen Regulations 5(5)(a)(ii), 7, 9(1) PMLFTR und FIAU Implementing Procedures
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Published
- 16 Apr 2026
- Administrative Measure Publication Notice – Stanleybet Malta Limited Decision of an authority
- Administrative Measures – FIAU Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Mar 2026 Colas Rail Asia Sdn Bhd (Colas-Gruppe)Colas Rail Asia: CJIP of 29.7 million EUR over bribery in metro contracts in Malaysia €29.7m
The Malaysian subsidiary of Colas Rail paid large, undocumented sums via intermediaries in connection with public contracts for urban rail lines in Kuala Lumpur (Kelana Jaya extension, MRT2). Following an internal investigation, Colas Rail self-reported the matter in 2017; the CJIP (Convention judiciaire d'intérêt public, a French deferred prosecution agreement) provides for a public interest fine of 29,745,974 EUR and a three-year compliance programme monitored by the French Anti-Corruption Agency (AFA) (costs of up to 1.9 million EUR).
Undocumented payments to intermediaries on foreign projects must be stopped early by the finance and compliance functions – self-reporting after an internal investigation is rewarded.
Intermediaries and consultants in public tenders
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
- Employees
- 10,000 or more
- Culpability
- intentional
- Mitigating circumstances
- Self-report (criminal complaint filed by Colas Rail on 31 May 2017) following an internal forensic investigation.
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 19 Mar 2026
- Communiqué de presse du procureur de la République financier – CJIP COLAS RAIL ASIA Press release of an authority
- Convention judiciaire d'intérêt public – COLAS RAIL ASIA (17.03.2026) Decision of an authority
- Ministère de la Justice: Conventions judiciaires d'intérêt public (Verzeichnis) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician €1.77m
In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.
Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.
Benefits to hospital physicians, integration of acquired companies
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 250 to 999
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 19 Mar 2026
- Communiqué de presse du procureur de la République financier – CJIP BALT USA Press release of an authority
- Ministère de la Justice – Conventions judiciaires d'intérêt public (Liste) Official register or notice
- CJIP Société BALT USA LLC (17.03.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Mar 2026 Trustpilot Group Plc, Trustpilot A/S, Trustpilot S.r.l.Trustpilot: 4 million EUR fine for inadequate verification of the authenticity of reviews €4m
According to the AGCM, the review platform did not adequately check whether reviews – including those labelled as "verified" – were genuine, and allowed companies to invite specifically selected customers to leave reviews via paid services, which undermined the representativeness of the star ratings. In addition, information on how the platform works and on paid services was lacking; the authority also saw dark pattern elements in this.
Anyone who advertises with verified reviews must actually carry out the verification and disclose the selective collection of reviews.
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Consumer protection and online retail · Fake reviews
- Legal basis
- Artt. 20, 21, 22 e 23, comma 1, lett. bb-ter Codice del Consumo
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 23 Mar 2026
- PS12962 - Sanzione di 4 milioni di euro a Trustpilot per pratica commerciale scorretta Press release of an authority
- AGCM Provvedimento PS12962 (Trustpilot), adunanza del 17 marzo 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2026 Associação Portuguesa das Empresas do Setor Privado de Emprego e de Recursos Humanos (APESPE)Portugal: 4.5 million EUR against temporary work association APESPE for no-poach rule €4.52m
From 1987 to March 2025, the association of temporary work agencies (around 40 members) obliged its members in its code of ethics not to poach each other’s temporary workers. The Autoridade da Concorrência (Portuguese Competition Authority, AdC) regarded this as an anticompetitive decision by an association in the labour market and imposed 4,519,000 EUR, calculated on the basis of the members’ turnover; the decision can be appealed (date = press release).
An association’s code of ethics can also be a cartel – no-poach agreements between competitors are off limits.
No-poach agreements in association rules
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 12 Mar 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Mar 2026 Amazon Europe Core S.à r.l.Luxembourg: Cour administrative annuls 746 million EUR fine against Amazon but confirms infringements overturned
In 2021, the Luxembourg data protection authority (CNPD) had imposed 746 million EUR and an order to bring processing into compliance on account of behavioural online advertising; the Administrative Tribunal (Tribunal administratif) confirmed this on 18 March 2025. On 12 March 2026, the Administrative Court (Cour administrative) confirmed that legitimate interest was not a sound legal basis and that the information was insufficient, but annulled the fine on the basis of more recent CJEU case law on the requirement of culpability; the CNPD is re-examining the sanction.
Personalised advertising cannot be based on legitimate interest – and courts now scrutinise culpability closely when it comes to fines.
- Authority / court
- Cour administrative (Luxemburg); Verfahren der CNPD
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 6 Abs. 1 lit. f, Art. 12 ff. DSGVO
- Action
- Order
- Status of proceedings
- overturned
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Mitigating circumstances
- Amazon had implemented the compliance order before the hearing.
- La CNPD obtient la mise en conformité effective des traitements d'Amazon (Arrêt de la Cour administrative du 12 mars 2026) Press release of an authority
- Décision concernant Amazon Europe Core S.À R.L. (Tribunal administratif, 18 mars 2025) Press release of an authority
- Justice Luxembourg – Arrêt de la Cour administrative du 12 mars 2026 (n° 52757C du rôle), Amazon/CNPD Court press release
- Justice Luxembourg – Jugement du tribunal administratif du 18 mars 2025, Amazon/CNPD Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2026 Fleurette Properties LtdCommodities holding Fleurette: 25.8 million EUR strafbeschikking over bribery in Congo €25.8m
According to the Dutch Public Prosecution Service (OM), the top holding company of a mining, oil and gold group, which was based in the Netherlands from 2010 to 2017, participated together with others in bribing public officials of the DR Congo in order to obtain licences for cobalt and copper mines. On 6 March 2026, the OM issued a strafbeschikking (prosecutorial penalty order) imposing a fine of 25.8 million EUR, which Fleurette accepted.
In the commodities sector, licences and concessions are the main target for bribery – holding companies share liability for payments made by their subsidiaries.
Award of licences in the commodities sector, payments to public officials
- Authority / court
- Openbaar Ministerie (OM); Ermittlungen FIOD Anti-Corruptie Centrum
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Buitenlandse ambtelijke omkoping (Wetboek van Strafrecht); OM-strafbeschikking
- Action
- Fine
- Status of proceedings
- final
- Sector
- Steel and metals
- Culpability
- intentional
- Published
- 10 Mar 2026
- Geldboete Fleurette Properties Ltd wegens omkoping in Congo Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Mar 2026 ΚΟΜΠΑ Μονοπρόσωπη Ε.Π.Ε. und HAPPY DOG Α.Ε. ΖωοτροφώνGreece: around 482,500 EUR against pet food importers for resale price maintenance €482,498
Two importers of dog and cat food monitored their retailers’ consumer prices on price comparison portals and asked them to adjust them to their price lists; the retailers complied. In a settlement procedure (Decision 901/2026), the Επιτροπή Ανταγωνισμού (Hellenic Competition Commission) imposed 387,498 EUR on KOMPA and 95,000 EUR on Happy Dog; the case began with a tip-off via the authority’s anonymous whistleblowing platform.
Recommended prices must not be enforced through monitoring and calls to retailers – and authorities’ whistleblowing channels make such practices visible.
Prohibition of resale price maintenance in sales
- Authority / court
- Επιτροπή Ανταγωνισμού (Hellenic Competition Commission)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 1 Gesetz 3959/2011; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Settlement procedure with reduced fines
- Published
- 6 Mar 2026
- Δελτίο Τύπου – Πρόστιμα σε επιχειρήσεις προμήθειας ζωοτροφών για ζώα συντροφιάς Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2026 SIA "SS"Classifieds portal ss.lv blocked users of competitor – fine of 186,781 EUR €186,781
From March 2020 to May 2021, the operator of ss.lv/ss.com (market share over 60%) deleted advertisements and blocked accounts of users – mainly car dealers and estate agents – who also advertised on the competing platform pp.lv; anyone wishing to register with an inbox.lv address additionally had to provide a different e-mail address. The Konkurences padome (Latvian Competition Council) considered this an abuse of a dominant position (Art. 102 TFEU), imposed 186,780.65 EUR and required objective criteria for dealing with customers.
Market-leading platforms must not punish users for multi-homing – internal moderation rules need objective criteria.
Competition law limits in dealing with competitors’ customers
- Authority / court
- Konkurences padome (Lettischer Wettbewerbsrat)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 102 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 18 Mar 2026
- KP konstatē SIA „SS“ dominējoša stāvokļa ļaunprātīgu izmantošanu … naudas sodu 186 780,65 EUR (18.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Mar 2026 Schaeffler AGSchaeffler: deviation of quarterly figures from market expectations disclosed too late €180,000
The automotive supplier's business figures for the first quarter of 2024 deviated significantly from market expectations; this inside information was not disclosed without delay by means of an ad hoc announcement. BaFin imposed a fine.
Make a comparison of internal figures with the analyst consensus a fixed part of the quarterly process, so that significant deviations are immediately assessed for ad hoc disclosure obligations.
Recognising inside information in deviations from market expectations (controlling/IR)
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Art. 17 Abs. 1 UAbs. 1 MAR
- Action
- Fine
- Status of proceedings
- final
- Sector
- Automotive
- Published
- 26 Mar 2026
- Schaeffler AG: BaFin setzt Geldbuße fest Decision of an authority
- Bekanntmachung der BaFin zur Schaeffler AG (Maßnahmenansicht mit Rechtskraftvermerk) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Mar 2026 BNF Bank p.l.c.Malta: 69,000 EUR against BNF Bank over late reporting to the bank account register €69,000
Following the introduction of a new core banking system in April 2025, the bank was unable, until September 2025, to submit the mandatory weekly data deliveries to the Centralised Bank Account Register (CBAR) on time. The Financial Intelligence Analysis Unit (FIAU) imposed 69,000 EUR.
Test regulatory reporting chains in advance of IT migrations – migration problems do not excuse missed deadlines.
- Authority / court
- Financial Intelligence Analysis Unit (FIAU)
- Area of law
- Money laundering and terrorist financing
- Legal basis
- Reg. 4(2), 8 Centralised Bank Account Register Regulations (S.L. 373.03)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- The bank continuously attempted to upload reports
- Published
- 6 Mar 2026
- Administrative Measure Publication Notice – BNF Bank p.l.c. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Nordic Cleaning ApSNordic Cleaning: fine for leaving access request unanswered despite an order €8,031
Despite repeated follow-ups by the trade union, the cleaning company did not respond to a union member’s access request and also failed to comply with the order of the Danish Data Protection Agency (Datatilsynet) to decide on the request. Datatilsynet reported the company; the case was closed on 2 March 2026 with a fine notice of 60,000 DKK.
Access requests and orders from authorities need a fixed intake channel and a responsible person – ignoring them leads straight to a criminal complaint.
Handling access requests (Art. 15 GDPR)
- Authority / court
- Anklagemyndigheden (Bødeforelæg) auf Anzeige der Datatilsynet
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15; Nichtbefolgung einer Anordnung der Datatilsynet; databeskyttelsesloven
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
Original amount 60,000 DKK, converted at the ECB reference rate of 2 Mar 2026.
- Datatilsynet – Klein2 ApS og Nordic Cleaning ApS indstilles til bøde (Opdatering: afgjort 2. marts 2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Mar 2026 Suomen Numerokeskus OySuomen Numerokeskus: 5,000 EUR – call recordings only played by phone instead of provided as a copy €5,000
Following six complaints, the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) found that the company did not provide a copy to customers who requested recordings of their sales calls in order to dispute invoices, offering only to let them listen via customer service, and in some cases deleted recordings. In addition to a reprimand, a fine of 5,000 EUR was imposed.
Access means a copy: anyone who records calls must be able to provide the recording to data subjects in a suitable form.
Right of access to call recordings
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 15 Abs. 1 und 3
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 25 Mar 2026
- Finlex – Tietosuojavaltuutettu 2.3.2026 (puhelutallenteet) Decision of an authority
- Tietosuojavaltuutettu – Suomen Numerokeskukselle seuraamusmaksu puutteista puhelutallenteiden antamisessa (25.03.2026) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 BVwG reduces FMA penalty against private bank over unclarified beneficial owners €356,000
From 2017 to 2020, an Austrian bank specialising in private and investment banking had not adequately examined the ownership and control structure of an offshore holding client despite the lack of evidence on shareholders, trust arrangements and beneficial owners. The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) confirmed the infringement but reduced the additional penalty imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 17 December 2024 from 476,000 to 356,000 EUR (total penalty 436,000 EUR less FMA penalties already paid), because the FMA had taken the seriousness of the offence into account twice and the bank had cooperated, admitted its errors and terminated the client relationship; an appeal on points of law has been permitted.
For offshore holdings with trustees, prove the beneficial owner with supporting documents – a self-declaration is not enough.
Identifying beneficial owners in holding and trust structures
- Authority / court
- Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 17.12.2024
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 9 Abs. 1 erster Satz i. V. m. § 6 Abs. 1 Z 2 FM-GwG; § 35 Abs. 1 und 3 i. V. m. § 34 Abs. 1 Z 2 und Abs. 2 FM-GwG; § 22 Abs. 9 FMABG (Zusatzstrafe)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Reduction by the court because the wrongfulness of the offence had been counted twice, cooperation, admission of the facts and of guilt, and termination of the client relationship
- BVwG W204 2306222-1 vom 20.02.2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR €1,999
The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.
Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.
Taking patient data when leaving; cooperation with the supervisory authority
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 20 Feb 2026
Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.
- ANSPDCP – Comunicat de presă 20.02.2026 (SC Hayat Dent SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 Restaurant Partner Polska sp. z o.o. (Betreiberin der Plattform Glovo)Glovo Poland: 5.9 million PLN for copies of identity documents without legal basis €1.4m
Since 2019, the delivery platform had required scans or photos of its users’ identity cards and passports in cases of suspected fraud, relying on legitimate interests. The Prezes Urzędu Ochrony Danych Osobowych (President of Poland’s data protection authority, UODO) regarded this as processing without a legal basis and a breach of data minimisation, imposed 5,898,064 PLN and ordered the processing to stop and the data to be erased.
Fraud prevention does not justify copies of identity documents – only those authorised by law may capture documents in full.
Copying identity documents and data minimisation
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 5 Abs. 2, Art. 6 Abs. 1 DSGVO (DKN.5112.33.2022)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Published
- 16 Mar 2026
Original amount 5,898,064 PLN, converted at the ECB reference rate of 19 Feb 2026.
- Nie można kopiować dokumentów bez podstawy prawnej - kara dla Glovo Press release of an authority
- Decyzja DKN.5112.33.2022 z 19 lutego 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Feb 2026 AZOP: 100,000 EUR against estate agent over ID copies and old files €100,000
An estate agency (name not published) kept 11,887 brokerage contracts from 2010 to 2019, together with 914 copies of identity cards, passports and bank cards, without a legal basis, although the managing director stated that no card copies were collected. The Croatian data protection authority (Agencija za zaštitu osobnih podataka, AZOP) also criticised irregular and inadequate data protection training for employees and imposed 100,000 EUR (date of publication; exact date of the decision not stated).
Make copies of identity documents and cards only with a legal basis, destroy old files on time and train employees regularly.
Data minimisation for ID copies, retention periods
Missing or inadequate training played a role in the decision.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. c und e, Art. 6 Abs. 1, Art. 32 Abs. 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- No damage to data subjects was found.
- Published
- 19 Feb 2026
- Agenciji za nekretnine izrečena kazna u iznosu od 100.000,00 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Périphériques et Matériels de Contrôle SAS (Groupe Carrus)Betting terminal manufacturer PMC: CJIP over payments to the head of state-owned PMU Mali €499,150
From 2008 to 2011, the Paris-based supplier of betting and gaming terminals made unjustified payments of 78,972 EUR to the head of the majority state-owned Pari Mutuel Urbain Mali, with which it had a supply contract awarded without a tender. The case was triggered by a report from TRACFIN (the French financial intelligence unit). Public interest fine of 499,150 EUR (including 335,000 EUR already seized) and a three-year AFA compliance programme.
Managers of state-controlled companies are also public officials – even small private payments to them create a risk of criminal liability for medium-sized companies.
Payments to heads of state-owned companies abroad
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger und Geldwäsche
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Employees
- 50 to 249
- Culpability
- intentional
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 18 Feb 2026
- Communiqué de presse du procureur de la République financier – CJIP PMC Press release of an authority
- Convention judiciaire d'intérêt public – Périphériques et Matériels de Contrôle SAS Decision of an authority
- Ministère de la Justice: Conventions judiciaires d'intérêt public (Verzeichnis) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 REGIS-TR S.A.Trade repository REGIS-TR: deficiencies in organisation and data protection – 1.37 million EUR €1.37m
The Luxembourg trade repository lacked adequate compliance procedures and an appropriate organisational structure, failed to identify operational risks and did not adequately protect the confidentiality and integrity of the reported data. ESMA imposed fines totalling 1,374,000 EUR for negligent infringements under EMIR and SFTR; the case is under appeal.
Market infrastructures must manage operational risks and data access as strictly as banks manage their credit risks.
- Authority / court
- Europäische Wertpapier- und Marktaufsichtsbehörde (ESMA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Verordnung (EU) Nr. 648/2012 (EMIR), Art. 65, 73, Anhang I; Verordnung (EU) 2015/2365 (SFTR), Art. 9
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Culpability
- negligent
- Repeat case
- yes
- Decision of the Board of Supervisors – REGIS-TR S.A. (ESMA43-857238790-1634) Decision of an authority
- ESMA Sanctions and Enforcement Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Feb 2026 BVwG upholds 588,000 EUR FMA penalty against major bank over incorrect risk classification €588,000
The Austrian Federal Administrative Court (Bundesverwaltungsgericht, BVwG) dismissed the appeal of a listed major Austrian bank and upheld the fine of 588,000 EUR (plus 58,800 EUR in procedural costs) imposed by the Financial Market Authority (Finanzmarktaufsicht, FMA) in its penalty decision of 19 November 2024. From 2017 to 2020, the bank had not adequately risk-classified three business relationships and had disregarded sector risks such as gambling and precious metals trading as well as cash intensity; an appeal on points of law has been permitted.
Customers from gambling or precious metals trading with a high share of cash belong in a higher risk class – otherwise the enhanced obligations are missing.
Risk classification of cash-intensive high-risk sectors
- Authority / court
- Bundesverwaltungsgericht (BVwG); Straferkenntnis der Finanzmarktaufsicht (FMA) vom 19.11.2024
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- § 6 Abs. 5 i. V. m. § 34 Abs. 1 Z 2 und § 35 Abs. 1–3 FM-GwG
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- BVwG W204 2304676-1 vom 17.02.2026 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Feb 2026 ELKOND HHK, VUKI, Prysmian, NKT, KABEX u. a. (Kabelkartell, 9 Unternehmen und ein Verband)Cable cartel: PMÚ imposes record fines of 97.4 million EUR €97.4m
Manufacturers and suppliers of copper and aluminium cables coordinated a common calculation of the metal surcharge, which makes up a significant part of the final price; an industry association acted as facilitator. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a total of 97,434,800 EUR, the highest amount in a single proceeding; two leniency applicants were not fined (not final). Addressees: ELKOND HHK, a.s.; VUKI a.s.; Prysmian Kablo s.r.o.; Prysmian Kabely, s.r.o.; Kablo Vrchlabí s.r.o.; NKT s.r.o.; PRECON s.r.o.; Tele–Fonika Kabely CZ s.r.o.; KABELOVNA KABEX a. s.; Asociace výrobců kabelů a vodičů ČR a SR (leniency applicants without a fine: ICS Industrial Cables Slovakia, PRAKAB).
A coordinated calculation formula for price components is also price fixing – association work needs competition law support.
Price coordination via associations and surcharge formulas
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Manufacturing and mechanical engineering
- Culpability
- intentional
- Published
- 11 Mar 2026
- KARTELY: PMÚ odhalil kartel výrobcov a dodávateľov káblov, uložil pokuty takmer 100 miliónov eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Feb 2026 DPG Media nv; Mediahuis nv; PPP Belgium bv; bpost nv (Kronzeuge)Press concession: 11.9 million EUR for collusion in newspaper delivery tender €11.9m
So that bpost would obtain the state concession for newspaper delivery for 2023–2027, its competitor PPP refrained from submitting a bid and in return received additional delivery volumes from DPG Media and Mediahuis (bid rigging). In a settlement procedure, the Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (Belgian Competition Authority, BMA) imposed 3,786,574 EUR (DPG Media), 7,788,423 EUR (Mediahuis) and 323,486 EUR (PPP); bpost, as leniency applicant, received full immunity, and two bpost employees involved were fined a total of 6,300 EUR.
Agreements on who participates in a tender are hardcore cartels – individuals are also liable, and leniency applicants benefit.
Collusion in public tenders
- Authority / court
- Autorité belge de la Concurrence / Belgische Mededingingsautoriteit (BMA)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Code de droit économique Art. IV.1; AEUV Art. 101
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Mitigating circumstances
- Leniency programme (immunity for bpost; reductions of 50% and 40% for DPG Media and Mediahuis respectively) and 10% settlement reduction.
- Liability of senior managers
- First-ever fines against two natural persons (employed by bpost), totalling 6,300 EUR.
- Published
- 13 Feb 2026
- BMA – Communiqué de presse N° 6/2026 (13.02.2026) Press release of an authority
- BMA – Beslissing BMA-2026-RPR-04-AUD (Krantenconcessie), publieke versie, 12.02.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Feb 2026 UAB „Manado“, MB „Parts ready“Manado and Parts ready: cartel in Vilnius public transport spare parts tender €41,080
In two tenders by ‘Vilniaus viešasis transportas’ for vehicle spare parts (May–October 2025), the dealers coordinated bids and prices, wrote the bids for each other and sent them from the same computer. The contracting entity reported the suspicion. Following acknowledgement (minus 15%), fines of 17,950 EUR (Manado) and 23,130 EUR (Parts ready). Source: archived copy of the press release.
Even jointly prepared bids by small dealers are a cartel – and contracting entities increasingly recognise such patterns.
Competition law in tenders
- Authority / court
- Konkurencijos taryba (Litauischer Wettbewerbsrat)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Konkurencijos įstatymas (verbotene Vereinbarungen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Mitigating circumstances
- Acknowledgement of the infringement (15% reduction)
- Published
- 12 Feb 2026
- Konkurencijos taryba, Pranešimas 2026-02-12 (Archivkopie web.archive.org von kt.gov.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Feb 2026 Strukton Civiel Projecten B.V. und Strukton International B.V. (Strukton-Gruppe)Construction group Strukton pays 10 million EUR out-of-court settlement over bribery on the Riyadh Metro €10m
To secure a share in the Riyadh Metro project, around 31 million USD was paid between 2013 and 2021 to an agent representing a high-ranking member of the Saudi royal family; the agent payments were understated to the export credit insurer Atradius. Strukton accepted a transaction (out-of-court settlement) of 10 million EUR.
Commissions to agents with ties to ruling families carry the highest risk – and false statements to export credit insurers constitute a second offence.
Agent commissions and false statements to export credit insurers
- Authority / court
- Openbaar Ministerie (OM)
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Buitenlandse ambtelijke omkoping und valsheid in geschrift (Wetboek van Strafrecht); Transactie nach Art. 74 Sr
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
- Culpability
- intentional
- Mitigating circumstances
- Cooperation from mid-2023; compliance programme in place since 2017; the employees involved are no longer with the company.
- Liability of senior managers
- The Dutch Public Prosecution Service (OM) is considering prosecuting several natural persons involved (not named).
- Published
- 30 Mar 2026
- Strukton betaalt hoge transactie van 10 miljoen euro na corruptieonderzoek Press release of an authority
- OM Functioneel Parket: Transactieovereenkomst Calisto (10.02.2026) Decision of an authority
- College van procureurs-generaal: Beslissing hoge transactie onderzoek Calisto (09.02.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2026 RASEMA s.r.o.; M – D – J, spol. s.r.o.; SIMA plus Krompachy, s.r.o.; BarCom spol. s.r.o.Photovoltaic tender: 1.1 million EUR – the contracting entity was also a cartel member €1.1m
In a tender for industrial photovoltaic installations that was to be financed from EU Structural Funds, three bidders coordinated their bids so that a pre-selected bidder would win; the contracting entity BarCom acted as facilitator. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed a total of 1,098,200 EUR and three-year procurement bans on all four; the EU funding was refused because of the indications of competition infringements, and the collusion was proven by e-mails secured during the inspection.
A contracting entity that determines the winner of a funded tender in advance is itself liable under competition law and additionally risks losing the funding.
Collusion in funded procurement
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Culpability
- intentional
- Published
- 11 Feb 2026
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Jan 2026 Associação de Guias de Informação Turística dos Açores (AGITA)Portugal: 8,200 EUR against Azores tour guide association for minimum price list €8,200
Since 2020, the only association of tour guides in the Azores (57 active members, around 43% of active guides) had recommended a fee table to its members by e-mail as minimum prices. Following a complaint, the Autoridade da Concorrência (Portuguese Competition Authority, AdC) imposed 8,200 EUR, taking the economic situation into account (date = press release).
Even small professional associations must not circulate fee tables as minimum prices – an e-mail is sufficient evidence.
No price recommendations by professional associations
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 9.º; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 29 Jan 2026
- AdC sanciona Associação de Guias de Informação Turística dos Açores por fixação de preços Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Jan 2026 CCV Group B.V.Netherlands: payment institution CCV without integrity risk analysis – 406,125 EUR fine €406,125
Until March 2018, the payment institution had no systematic integrity risk analysis (SIRA) and therefore no systematic identification and analysis of integrity risks for its gatekeeper function. The Dutch central bank (De Nederlandsche Bank, DNB) imposed the fine in 2020; following objection and appeal proceedings, it was fixed at the reduced amount of 406,125 EUR by the decision of 28 January 2026 and was published in July 2026.
Without a documented integrity risk analysis, any money laundering prevention lacks its foundation – and that alone is subject to fines.
- Authority / court
- De Nederlandsche Bank (DNB)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Art. 3:10 Wet op het financieel toezicht (Wft); Art. 10 Besluit prudentiële regels Wft (Bpr)
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Financial services and insurance
- Mitigating circumstances
- Fine reduced in the objection and appeal proceedings
- Published
- 21 Jul 2026
- Fine for CCV Group B.V. for lack of SIRA Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Jan 2026 Sportadmin i Skandinavien ABSportadmin: 6 million SEK after hacker attack on club management system holding children’s data €564,626
The provider of management software and an app for sports clubs suffered a data exfiltration by an external attacker in January 2025. The Swedish Authority for Privacy Protection (IMY) found that no appropriate technical and organisational security measures were in place before and at the time of the incident, even though the data processed related predominantly to children and also included health information (allergies, disabilities), and imposed 6 million SEK; in setting the amount it took into account the 2024 group turnover of the Lime group (around 685.7 million SEK).
Software providers that pool sensitive data from many customers must align their security level and attack surfaces with how sensitive the data is (children, health) – not only after an incident.
- Authority / court
- Integritetsskyddsmyndigheten (IMY)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Prompt and comprehensive information of the clubs and data subjects after the incident; support for around 1,700 clubs in filing their notifications within 72 hours.
- Published
- 26 Jan 2026
Original amount 6,000,000 SEK, converted at the ECB reference rate of 26 Jan 2026.
- IMY – Tillsyn Sportadmin i Skandinavien AB Decision of an authority
- IMY – Beslut efter tillsyn, IMY-2025-7801 (26.01.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jan 2026 France TravailCNIL: 5 million EUR against France Travail after social engineering attack €5m
In early 2024, attackers used social engineering to take over accounts of Cap Emploi advisers and accessed data on jobseekers from the last 20 years, including social security numbers. The French data protection authority (CNIL) criticised weak authentication, insufficient logging and overly broad access rights, and imposed 5 million EUR together with an order carrying a penalty payment of 5,000 EUR per day of delay.
Accounts of external partners with extensive data access need strong authentication, narrow rights and anomaly detection – and their users need training against social engineering.
Social engineering and account takeover
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Employees
- 10,000 or more
- Published
- 29 Jan 2026
- Violation de données : sanction de 5 millions d'euros à l'encontre de FRANCE TRAVAIL Press release of an authority
- CNIL – Les sanctions prononcées par la CNIL (Eintrag 22/01/2026) Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jan 2026 Logistics business: fines for minimum wage, reporting and foreign employment violations €13,731
Between June and December 2023, a logistics and transport business withheld a total of around 2,000 EUR in minimum wages from several employees, breached reporting and immediate notification obligations, and in July/August 2023 employed a foreign national without a residence permit. The fines: 5,231 EUR (minimum wage), 750 EUR each (reporting obligations) and 7,000 EUR (unauthorised employment of foreign nationals), totalling 13,731 EUR (date = publication).
Even small wage arrears are penalised individually alongside reporting and residence violations – HR processes for new hires need a fixed checklist.
Immediate notification and checking of work permits when hiring
- Authority / court
- Hauptzollamt Karlsruhe (Finanzkontrolle Schwarzarbeit)
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- § 21 Abs. 1 Nr. 11 MiLoG; § 111 Abs. 1 Nr. 2 SGB IV; § 404 Abs. 2 Nr. 3 SGB III
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 22 Jan 2026
- Zoll ahndet Mindestlohn- und Meldepflichtverstöße bei Logistikunternehmen (Hauptzollamt Karlsruhe) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2026 PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs)Pharmaceutical cartel uncovered thanks to whistleblower: 7.8 million EUR against PHOENIX and TRANSMEDIC €7.8m
The two companies colluded in tenders of the General Health Insurance Company for the supply of medicines (2017–2020). For the first time, a cartel was uncovered on the basis of information from a whistleblower; the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 7,595,200 EUR and a one-year procurement ban on PHOENIX and 201,800 EUR and a three-year procurement ban on TRANSMEDIC (first instance).
Whistleblowers receive a reward in Slovakia – internal reporting channels should be faster than the route to the authority.
Bid rigging in public tenders; whistleblowing channels
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- PHOENIX: settlement with a 30% fine reduction and a shortened procurement ban.
- Published
- 24 Feb 2026
- KARTELY: PMÚ aj vďaka whistleblowerovi odhalil kartel v dodávkach liekov a uložil pokuty takmer 7,8 milióna eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2026 Cardif Lux Vie S.A.Cardif Lux Vie: 615,000 EUR over deficiencies in money laundering questionnaires and customer files €615,000
An on-site inspection in 2023 revealed that the life insurer in some cases did not handle the mandatory money laundering risk assessment questionnaires in compliance with the rules, that the employees responsible lacked sufficiently precise instructions and that customer files contained many incorrect answers. The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) imposed 615,000 EUR.
Risk questionnaires are only as good as the guidance given to those who complete them – clear work instructions and training are part of this.
Money laundering risk assessment by employees
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Loi modifiée du 12 novembre 2004 (LBC/FT), Art. 2-1, 8-4, 8-5; Règlement CAA 20/03
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Close cooperation with the CAA during and after the inspection; remediation plan for all deficiencies submitted promptly.
- Published
- 1 Jul 2026
- CAA – Sanction administrative Cardif Lux Vie S.A. (01.07.2026) Decision of an authority
- CAA – Sanctions et autres mesures administratives Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 D*** GmbH (Digitalmarketing- und Recruitingagentur, anonymisiert)Recruitment agency: 25,500 EUR for secretly recorded calls with applicants €25,500
The agency conducted telephone pre-screening interviews with applicants on behalf of client companies, recorded them without valid consent, stored them indefinitely and presented itself as the client company in doing so. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 25,500 EUR (plus 2,550 EUR in costs) for lack of a legal basis and transparency; the company has lodged an appeal against the amount of the fine with the Federal Administrative Court (Bundesverwaltungsgericht).
Call recordings in recruitment need a genuine legal basis and clear information about who is actually responsible.
Recording of telephone calls and applicant data
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, c und e, Art. 6 Abs. 1, Art. 12, 13
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Other
- Employees
- Under 50
- Mitigating circumstances
- No relevant previous violations, cooperation in the proceedings; adjustment of the starting amount to the company's small size.
- Datenschutzbehörde, Straferkenntnis 2025-1.049.138 vom 19.01.2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR €14,997
An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.
Handling employees’ health data, e-mail distribution lists
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 19 Jan 2026
Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.
- ANSPDCP – Comunicat de presă 19.01.2026 (Continental Automotive Products SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jan 2026 Zalando SEZalando: around 31 million PLN for missing 30-day lowest prices on discounts €7.34m
Zalando did not display the lowest price of the previous 30 days for discounts, manipulated reference prices to make reductions appear larger and did not present the mandatory information consistently at all stages of the purchasing process. Poland's Office of Competition and Consumer Protection (UOKiK) imposed a fine of 30,945,000 PLN; the decision is not final.
Discount information must be identical and correct on all pages of a shop – listing, product page, shopping basket.
Presentation of discounts in online shops
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 14 Jan 2026
Original amount 30,945,000 PLN, converted at the ECB reference rate of 14 Jan 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Jan 2026 Whaleco Technology Limited (Temu)Temu: almost 6 million PLN over changing reference prices and discount labelling €1.4m
The operator of the Temu interface omitted the 30-day lowest price or stated it incorrectly, labelled promotions inconsistently and changed reference prices from day to day without the actual price changing. UOKiK imposed a fine of 5,910,900 PLN; the decision is not final.
Reference prices that shift daily without any real price change are a misleading staging of discounts.
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Polnische Umsetzung der Omnibus-Richtlinie (Preisangaben bei Preisermäßigungen); Verletzung kollektiver Verbraucherinteressen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 14 Jan 2026
Original amount 5,910,900 PLN, converted at the ECB reference rate of 14 Jan 2026.
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Jan 2026 Bulgarian construction subcontractor: 232,500 EUR for paying below the minimum wage €232,500
A Bulgarian construction company that worked as a subcontractor for a German firm on a major construction site in the district of Tuttlingen between January and May 2023 paid below the minimum wage, recorded only the duration of working time rather than its start and end, and did not register the posting. The decisions issued in September 2025, final since the end of 2025, amount to 232,500 EUR – of which 215,000 EUR is disgorgement of the economic benefit and 17,500 EUR is imposed on the managing director (date = publication; exact date of the decision not specified).
General contractors should actively check the minimum wage, working time records and posting notifications of their foreign subcontractors – the economic benefit is disgorged in full.
- Authority / court
- Hauptzollamt Singen (Finanzkontrolle Schwarzarbeit)
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- Mindestlohngesetz; Arbeitnehmer-Entsendegesetz (Aufzeichnungs- und Meldepflichten)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Construction and real estate
- Liability of senior managers
- Separate fine of 17,500 EUR against the managing director.
- Published
- 9 Jan 2026
- Zeit, Geld, Meldepflicht – Zoll ahndet Verstöße mit sechsstelligem Bußgeld (Hauptzollamt Singen) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Free Mobile SAS und Free SASCNIL: 42 million EUR against Free Mobile and Free after data leak affecting 24 million contracts €42m
Following an attack in October 2024 in which data relating to around 24 million customer contracts, including IBANs, was exfiltrated, the French data protection authority (CNIL) imposed 27 million EUR on Free Mobile and 15 million EUR on Free (42 million EUR in total). The authority objected to VPN access without adequate authentication, deficient detection of suspicious access, incomplete notification of data subjects and, at Free Mobile, excessively long retention of old contracts; orders with deadlines were also issued.
Put remote access such as VPN behind multi-factor authentication, and consistently delete legacy data from terminated contracts.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 32, Art. 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- During the proceedings, the companies introduced multi-factor authentication, a Security Operations Centre and improved logging.
- Published
- 14 Jan 2026
- Violation de données : sanction de 42 millions d'euros à l'encontre des sociétés FREE MOBILE et FREE Press release of an authority
- Délibération SAN-2026-001 du 8 janvier 2026 (FREE MOBILE) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Jan 2026 Αρχηγείο Πυροσβεστικού Σώματος (Hauptquartier der griechischen Feuerwehr)Greece: 10,000 EUR against Fire Service Headquarters over health data in duty log €10,000
In a daily orders book of a fire service unit that was accessible to staff, not only the transfer of a female officer to light duties was recorded, but also her illness, the treatment and the medication prescribed. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found a breach of lawfulness and data minimisation and, by Decision 1/2026, imposed a fine of 10,000 EUR on the Fire Service Headquarters.
Employees’ health information never belongs in generally accessible official records – the reason for an absence generally does not need to be disclosed.
Confidential handling of employees’ health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a und c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Απόφαση 1/2026 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jan 2026 Portugal: 16,000 EUR against filling station operator for forwarding complaints late €16,000
A filling station operator (medium-sized company, name not published) did not send the originals of eight sheets from the statutory complaints book to the authority on time. The Entidade Reguladora dos Serviços Energéticos (Portuguese Energy Services Regulatory Authority, ERSE) imposed 16,000 EUR for eight negligent administrative offences; the Competition, Regulation and Supervision Court upheld the fine in full on 14 July 2026.
Even formal obligations such as forwarding complaints book sheets are sanctioned per case – branch staff must know the procedure.
Timely forwarding of customer complaints from the complaints book
- Authority / court
- Entidade Reguladora dos Serviços Energéticos (ERSE)
- Area of law
- Consumer protection and online retail
- Legal basis
- Decreto-Lei n.º 156/2005 (Livro de Reclamações); Regime Jurídico das Contraordenações Económicas, Art. 18, 19
- Action
- Fine
- Status of proceedings
- final
- Sector
- Energy and utilities
- Employees
- 50 to 249
- Culpability
- negligent
- Mitigating circumstances
- No previous record, no economic advantage
- ERSE – Decisões sancionatórias: Processo n.º 15/2024 – Postos de abastecimento de combustíveis Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jan 2026 Poczta Polska S.A.Poczta Polska: 978,128 PLN because the data protection officer was not independent €232,208
The function of data protection officer was performed by a manager who was at the same time responsible for security and protection of classified information and thus monitored their own activities; there was no conflict analysis. Poland’s data protection authority (UODO) imposed 978,128 PLN and referred to numerous previous reprimands and orders against the company.
Data protection officers must not be responsible for the processes they monitor – check dual roles for conflicts of interest in advance.
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 3 und 6 DSGVO (DKN.5131.4.2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Repeat case
- yes
- Mitigating circumstances
- During the proceedings the function was made independent and placed directly under the management board.
- Published
- 26 Jan 2026
Original amount 978,128 PLN, converted at the ECB reference rate of 2 Jan 2026.
- Kara dla Poczty Polskiej za brak zapewnienia niezależności sprawowania funkcji IOD Press release of an authority
- Decyzja DKN.5131.4.2025 z 2 stycznia 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 C2MAC Group, Fonderie De Riccardis, Zanardi Fonderie u. a. (Gießereikartell, 12 Unternehmen und Assofond)Italy: 70 million EUR against 16 foundries and the association Assofond over price index cartel €70m
From 2004 to June 2024, foundries coordinated their pricing strategies via the association Assofond: they exchanged sensitive information and developed joint indexation mechanisms ("Assofond indicators") in order to push through price increases including margins. The AGCM imposed fines of 70 million EUR (maximum around 600 million EUR), taking the crisis in the sector into account as a mitigating factor. Addressees: C2MAC Group, Fonderia Corrà, Fonderie De Riccardis, Fonderie Guido Glisenti/Lead Time, Pilenga Baldassarre/E.F. Group, Fonderie Mora Gavardo/Camozzi Group, Zanardi Fonderie, VDP Fonderia, Fonderie Ariotti, Ironcastings, Fonderia Zardo, ZML Industries/Cividale, Assofond.
Joint price indices within an association are only permissible if they do not enable coordination of margins or prices – metalworking companies should have their association activities accompanied by competition law advice.
Association indices and price adjustment clauses as a coordination tool
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Steel and metals
- Mitigating circumstances
- The severe crisis in the foundry sector was taken into account in setting the fines
- Published
- 31 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Dec 2025 ONE WAY PRIVATE COMPANYGreece: 80,000 EUR against call centre One Way over marketing calls for gas supplier €80,000
Following numerous complaints about marketing calls for the gas supplier ZENITH, the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority) found that the call centre engaged had insufficient security measures and called persons without valid consent. By Decision 44/2025, One Way received 40,000 EUR each as processor and as controller, together with an order to delete the data of persons without valid consent; ZENITH and two other service providers were also held liable (10,000, 10,000 and 5,000 EUR).
Anyone outsourcing telemarketing must regularly carry out sample checks on call centres – and call centres are themselves liable for calls made without consent.
Checking consent before telemarketing
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5, 6, 7, 29, 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Repeat case
- yes
- Απόφαση 44/2025 της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2025 Ryanair DAC, Ryanair Holdings plcItaly: 255.8 million EUR against Ryanair for obstructing travel agencies €255.8m
From April 2023 until at least April 2025, Ryanair obstructed travel agencies from buying Ryanair flights in combination with other services, for example through facial recognition procedures, account deletions, blocking of means of payment and restrictive partner agreements. The AGCM considered this to be an abuse of a dominant position and imposed fines of 255,761,692 EUR on a joint and several basis.
Dominant providers must not use technical barriers to force sales partners and resellers out of the market.
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 102 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Published
- 23 Dec 2025
- A568 - Ryanair DAC and its parent company Ryanair Holdings plc fined over € 255 million for abuse of a dominant position Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Dec 2025 Amazon France Logistique SASConseil d'État reduces CNIL fine against Amazon France Logistique to 15 million EUR €15m
In 2023, the French data protection authority (CNIL) had imposed 32 million EUR for the real-time monitoring of warehouse staff through scanner metrics. France's supreme administrative court (Conseil d'État) held that three metrics (‘Stow Machine Gun’, ‘Idle Time’, ‘Latency’) were covered by legitimate interest, but upheld the findings on the 31-day retention of all metrics, information deficiencies and security flaws in the video surveillance, and reduced the fine to 15 million EUR.
Store employee performance metrics only for as long and in as much detail as their specific purpose requires.
- Authority / court
- Conseil d'État
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c, Art. 12, 13, 32 DSGVO
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Transport, logistics and shipping
- Employees
- 10,000 or more
- Conseil d'État, décision n° 492830 du 23 décembre 2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Nexpublica FranceCNIL: 1.7 million EUR against processor Nexpublica over security flaws €1.7m
As a processor, Nexpublica developed and operated the case management software ‘Public CRM’ for the disability authority MDPH Nord. Following two data breaches in 2022, audits revealed critical vulnerabilities that had existed since 2021, such as outdated SHA-1 hashing; the French data protection authority (CNIL) imposed 1.7 million EUR directly on the service provider.
Processors are themselves liable for the data security of their software; do not leave known vulnerabilities unaddressed until the next breach.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Délibération SAN-2025-015 du 22 décembre 2025 (NEXPUBLICA FRANCE) Decision of an authority
- Les sanctions prononcées par la CNIL Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Dec 2025 Curenergía Comercializador de Último Recurso, S.A.U.AEPD: 500,000 EUR against energy supplier Curenergía after misdirected message in dual chat €500,000
An employee of the customer service provider was serving two customers in chat at the same time and assigned one customer's e-mail address to the other; as a result, the complainant received the name, debts and billing data of a stranger. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) saw the cause in the process design, which allowed parallel chats, and imposed 500,000 EUR for lack of data protection by design; the request for reconsideration was rejected.
Design service channels so that mix-ups between customers are technically harder – an individual error can be an organisational failure.
Diligence in customer service / misdirected messages
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 25 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- AEPD Resolución PS/00190/2024 (EXP202316394) Decision of an authority
- AEPD Resolución recurso de reposición PS/00190/2024 (Datum der Ausgangsentscheidung 22.12.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Snowball.xyz-Gruppe (Snowball.xyz, Šviesa, Tavo mokykla, Ateities pamoka) und AL holdingas-Gruppe (AL holdingas, Ugdymo sprendimai, UNT nuoma)E-register providers shared the market – 3.6 million EUR in cartel fines €3.63m
In August 2020, the operators of the electronic class registers ‘Tamo’ and ‘Eduka’ agreed to stop competing: one group kept the class register business, the other took over the digital learning content. Following acknowledgement of the infringement, the fines were reduced by 15%: 2,714,940 EUR jointly and severally for the Snowball.xyz group and 913,340 EUR for the AL holdingas group (Art. 101 TFEU). The decision can be appealed. Source: archived copy of the press release.
Agreements between competitors on ‘who does what’ are cartels – even when dressed up as portfolio streamlining.
Market sharing among competitors
- Authority / court
- Konkurencijos taryba (Litauischer Wettbewerbsrat)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Konkurencijos įstatymas; Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- Acknowledgement of the infringement (15% reduction)
- Published
- 18 Dec 2025
- Konkurencijos taryba, Pranešimas 2025-12-18 (Archivkopie web.archive.org von kt.gov.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Croatia: 1.5 million EUR against bank whose app recorded all apps installed by customers €1.5m
The mobile banking app of a bank (name not published) scanned the list of all installed applications on the Android and Huawei devices of 433,922 customers and stored it centrally – without a legal basis, without transparent information and without a data-minimising design. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 1.5 million EUR; the decision is not final (date = publication).
Fraud prevention does not justify capturing device data in full – a blocklist of known malicious apps would have been the less intrusive means.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und c, Art. 6 Abs. 1, Art. 12, 13, 25 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 18 Dec 2025
- Banci izrečena upravna novčana kazna u iznosu od 1,5 milijuna eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi: 120,000 EUR for monitoring field staff's driving style €120,000
At the instruction of a group company based in Switzerland, the seed company had telematics devices installed in company cars that also recorded private journeys and assigned employees scores for their driving behaviour. Italy's data protection authority (Garante per la protezione dei dati personali) found breaches of transparency, purpose limitation, data minimisation and employee protection rules, imposed 120,000 EUR and ordered the deletion of the data on private journeys.
Group-wide telematics requirements must be assessed against local employment and data protection law before roll-out – especially where vehicles are also used privately.
Employee monitoring through telematics
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a-c, 6 Abs. 1 lit. f, 13, 28, 88; Codice privacy Art. 2-quaterdecies, 113, 114
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- Mitigating circumstances
- Small number of data subjects (five employees), immediate suspension of the processing.
- Provvedimento del 18 dicembre 2025 [10213711] (Reg. 755/2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Dec 2025 Bravogroup Holding Vagyonkezelő Kft.Bravogroup: 32.6 million HUF for unnotified stake in Xiaomi distributor €84,042
In February 2023, the IT holding company acquired a 50% stake with negative sole control in the Xiaomi distributor Mystical Hungary Zrt., but only approached the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) after 582 days and notified the concentration thereafter. Following voluntary disclosure, acknowledgement and waiver of legal remedies, the authority imposed a significantly reduced 32.6 million HUF.
Blocking rights (negative control) can also trigger a notification requirement – review stakes under merger control law before signing.
Merger control for minority stakes with veto rights
- Authority / court
- Gazdasági Versenyhivatal (GVH)
- Area of law
- Competition law · Merger control
- Legal basis
- Ungarisches Wettbewerbsgesetz, Vollzugsverbot (VJ/20/2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Voluntary disclosure, acknowledgement and waiver of legal remedies.
- Published
- 18 Dec 2025
Original amount 32,600,000 HUF, converted at the ECB reference rate of 18 Dec 2025.
- Bejelentés és engedély nélkül végrehajtott fúzió miatt bírságolt a GVH Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Dec 2025 Asparagus farm without reliable working time records: Raad van State upholds 11,250 EUR €11,250
In May/June 2022, the working time records of an asparagus business (anonymised in the judgment) deviated structurally from the hours actually worked; among other things, Sunday work went unrecorded, so compliance with working and rest times could not be checked. The Administrative Jurisdiction Division of the Dutch Council of State (Raad van State, Afdeling bestuursrechtspraak) upheld the fine of 11,250 EUR, imposed in 2023 without prior warning, including the increase factor of 1.5.
Working time records that do not reflect actual hours are treated as missing – businesses are then sanctioned without prior warning.
Correct recording of working and rest times
- Authority / court
- Raad van State, Afdeling bestuursrechtspraak (Bußgeld: Minister van Sociale Zaken en Werkgelegenheid)
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- Art. 4:3 Abs. 1 Arbeidstijdenwet
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- Raad van State, ECLI:NL:RVS:2025:6142 vom 17.12.2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Dec 2025 Hardeck Möbel GmbH & Co. KGFurniture retailer Hardeck: 379,503 EUR fine for breach of AML due diligence obligations €379,504
The Arnsberg regional government (Bezirksregierung Arnsberg), as anti-money laundering supervisor for the non-financial sector, imposed a fine of 379,503.50 EUR, final since 16 December 2025, on the furniture retailer as a dealer in goods for breach of due diligence obligations under the German Money Laundering Act (Geldwäschegesetz, GwG). Karl-Ernst Hardeck is named as the person responsible for the company.
Furniture retailers, as dealers in goods, are also obliged entities under the GwG – breaches of due diligence obligations can trigger six-figure fines.
Identification for cash payments in the trade in goods
- Authority / court
- Bezirksregierung Arnsberg (Geldwäscheaufsicht Nichtfinanzsektor)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Geldwäschegesetz (Sorgfaltspflichten); Bekanntmachung nach § 57 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Liability of senior managers
- The announcement names Karl-Ernst Hardeck as the person responsible for the infringement
- Bekanntmachung nach § 57 GwG – Bezirksregierung Arnsberg Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Exide, FET (inkl. Elettra), Rombat, EUROBAT (Clarios Kronzeuge)EU: 72 million EUR against starter battery manufacturers and the association EUROBAT €72m
From 2005 to 2017, the manufacturers of automotive starter batteries agreed, with the help of the association EUROBAT, to publish jointly calculated lead surcharges (EUROBAT premiums) and to use them in price negotiations with carmakers. Fines: Exide 30 million EUR, Rombat 20.218 million EUR, Elettra 15.594 million EUR, FET 6.11 million EUR, EUROBAT 125,000 EUR; Clarios escaped a fine as leniency applicant.
Suppliers may pass on raw material surcharges individually, but must never fix them in an industry-wide coordinated manner via association indices.
Joint raw material surcharges among competitors via association indices
- Authority / court
- Europäische Kommission
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 101 AEUV, Art. 53 EWR-Abkommen
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Mitigating circumstances
- Leniency programme (Clarios 100 %, FET 50 %, Rombat 30 %); reduction for inability to pay for one company; payment in instalments
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Dec 2025 Stichting Hogeschool van Arnhem en Nijmegen (HAN University of Applied Sciences)Netherlands: 175,000 EUR against HAN university over inadequate security after hack €175,000
In 2021, a hacker gained access via a web form to a web server and a database server of the university, obtained, among other things, names with passwords and citizen service numbers of students and staff, and unsuccessfully demanded a ransom. According to the Dutch data protection authority (Autoriteit Persoonsgegevens, AP), security was not aligned with the risks, and the rights of a database account were not restricted.
Give database accounts of web applications minimal rights so that a single vulnerability does not expose the entire data set.
- Authority / court
- Autoriteit Persoonsgegevens (AP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- Settlement without objection; active damage limitation, strengthened resilience and sharing of lessons learned with other organisations.
- Published
- 17 Dec 2025
- HAN krijgt boete van 175.000 euro voor onvoldoende beveiliging van persoonsgegevens Press release of an authority
- Boete HAN Decision of an authority
- AP: Besluit tot oplegging van een bestuurlijke boete aan Stichting Hogeschool van Arnhem en Nijmegen Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Dec 2025 „ЗП Либра“ ООДZP Libra: 44,205 leva for poaching customers using competitor’s trade secrets €22,602
With the help of an employee of its competitor I&G Insurance Brokers who later moved to ZP Libra, the broker unfairly concluded a brokerage agreement to the detriment of the competitor and used the competitor’s trade secrets to poach customers. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) imposed 29,470 leva (1% of 2024 turnover, Art. 36(1) ZZK – Bulgarian Protection of Competition Act) and 14,735 leva (0.5%, Art. 37(1) ZZK); fines totalling 1,000 leva were also imposed on the employee.
When hiring employees from competitors, make sure they do not bring customer lists or secrets with them – otherwise both the company and the individual are liable.
Taking customer data and trade secrets when changing employer
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 36 Abs. 1, Art. 37 Abs. 1 ZZK
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Fines on the employee involved (1,000 leva in total)
- Published
- 16 Dec 2025
Original amount 44,205 BGN, converted at the ECB reference rate of 11 Dec 2025.
- КЗК Публичен електронен регистър – Производство (Решение № 1175 от 11.12.2025; Volltext als PDF im Register) Official register or notice
- КЗК санкционира „ЗП Либра“ ООД за нелоялна конкуренция, 17.12.2025 (Archivkopie web.archive.org von cpc.bg) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Dec 2025 Invest in OÜLender Invest in OÜ pays 16,000 EUR for failing to submit annual accounts €16,000
The lender did not submit its 2024 annual report, together with the audit report, the resolution on the appropriation of profits and the minutes of the shareholders’ meeting, to the financial supervisory authority on time. In misdemeanour proceedings, the Finantsinspektsioon (Estonian Financial Supervision Authority) imposed a fine of 16,000 EUR; the maximum is 1 million EUR or 10% of annual turnover. Date = publication.
Even small supervised lenders need a reliable deadline calendar for mandatory supervisory reports.
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- § 56 Abs. 3, § 96 Abs. 2 KAVS (Gesetz über Kreditgeber und -vermittler)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 10 Dec 2025
- Finantsinspektsioon tegi Invest in OÜ-le 16 000 eurot trahvi (10.12.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 XEuropean Commission: 120 million EUR DSA fine against X over blue checkmark and advertising repository €120m
First non-compliance decision under the Digital Services Act (DSA): the European Commission imposed 120 million EUR on X because the purchasable ‘verified’ checkmark deceives users, the advertising repository lacks essential information (content, topic, advertiser) and researchers are denied access to public data. X must present remedies within 60 working days and an action plan within 90 working days respectively.
Use verification and trust symbols only if verification actually takes place – otherwise they are treated as deceptive design.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2022/2065 (DSA), Art. 25 Abs. 1, Art. 39, Art. 40 Abs. 12
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 5 Dec 2025
- Commission fines X €120 million under the Digital Services Act Press release of an authority
- IP/25/2934 (Druckfassung) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 Volvo Hungária Kereskedelmi és Szolgáltató Kft.; Seres Gépipari Kereskedelmi Kft.; GIF Modul Kft.; Interteher Kft.; Eurotrade Kft.; He Hans Eibinger Kft. (MUT Kft. ohne Buße nach Entschädigung)Refuse vehicle cartel: over 1.5 billion HUF, of which 270 million for obstructing the inspection €4.06m
In 2014–2015, chassis and body manufacturers allocated contracts and submitted cover bids in tenders for refuse collection and sewer cleaning vehicles. The Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH) imposed cartel fines of 1,278.4 million HUF (of which 972.9 million on Volvo Hungária) and, in addition, a record procedural fine of 270 million HUF on Volvo Hungária for obstructing access to data secured during the inspection.
Regular meetings on ‘capacity planning’ with competitors are cartel evidence – and obstructing an inspection costs extra.
Bid rigging and conduct during inspections
- Authority / court
- Gazdasági Versenyhivatal (GVH)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Ungarisches Wettbewerbsgesetz, Art. 101 AEUV (Submissionsabsprachen, Verfahrensbuße; VJ/30/2018)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Culpability
- intentional
- Mitigating circumstances
- Admissions and leniency applications by most participants; MUT paid 116 million HUF in compensation to contracting authorities.
- Published
- 5 Dec 2025
Original amount 1,548,400,000 HUF, converted at the ECB reference rate of 5 Dec 2025.
- Kukásautó-kartellt tárt fel a GVH Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Dec 2025 TikTokTikTok: binding DSA commitments for a complete advertising repository Order
Following preliminary findings in May 2025 that TikTok’s advertising repository did not meet the requirements of the Digital Services Act, the European Commission declared commitments binding: complete ad content including links, updates within 24 hours, disclosure of targeting criteria with aggregated reach data and improved search functions. Depending on the commitment, implementation must take place within 2 to 12 months; breaches of the commitments count as breaches of the DSA.
Advertising repositories are a separate platform obligation – they must be complete, up to date and searchable, not merely exist formally.
- Authority / court
- Europäische Kommission
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Digital Services Act (Verordnung (EU) 2022/2065): Pflicht zum Werbearchiv; verbindliche Zusagen nach Art. 71
- Action
- Order
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Dec 2025 Jeronimo Martins Polska (Biedronka)Biedronka: almost 105 million PLN over undisclosed conditions for "100 % back" €24.7m
The supermarket chain advertised promotions such as "Special Wednesday" with "100 % money back as a voucher", but did not state restrictions concerning product categories, minimum spend and use of the vouchers in radio, app and in-store advertising, only on the receipt, the website or in-store notices. UOKiK imposed a fine of 104,722,016 PLN; the decision is not final.
State the essential restrictions of a promotion in the advertising itself, not just on the receipt.
Complete promotion terms in advertising
- Authority / court
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Verletzung kollektiver Verbraucherinteressen (irreführende Werbung durch Unterlassen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Culpability
- intentional
- Published
- 4 Dec 2025
Original amount 104,722,016 PLN, converted at the ECB reference rate of 4 Dec 2025.
- When a promotion fails to mention what is important – nearly PLN 105 million in fines for Biedronka Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Dec 2025 Russmedia Digital SRLCJEU: online marketplace is liable as controller for data in user adverts —
On the Romanian marketplace publi24.ro, a fake advert appeared with photos and the telephone number of a woman, claiming that she offered sexual services. The Court of Justice of the European Union (Grand Chamber, Case C-492/23) ruled that the operator is a controller within the meaning of the GDPR, must identify adverts containing sensitive data before publication and verify identity or consent, and cannot rely on the liability exemption of the E-Commerce Directive.
Platforms with user content must technically detect and check sensitive data before publication – notice and takedown alone is not sufficient.
- Authority / court
- Gerichtshof der Europäischen Union (Große Kammer), Rs. C-492/23
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Verantwortlicher, Art. 9, Art. 32); Richtlinie 2000/31/EG
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 2 Dec 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Dec 2025 SUROVINA d.o.o.; SALOMON d.o.o.; RECIKEL d.o.o.; DINOS d.o.o.Packaging waste: AVK finds market sharing by four waste management companies Order
In the reopened proceedings, the Javna agencija Republike Slovenije za varstvo konkurence (Slovenian Competition Protection Agency, AVK) found that the companies had shared the market for take-back schemes for packaging waste and agreed to stop providing their services to a competitor (now Interzero). The authority ordered immediate termination; the decision is not final, and an earlier decision from 2019 in the same matter is partly final.
An agreement to stop supplying a common competitor is a cartel – even in regulated waste management markets.
Boycott and market-sharing agreements
- Authority / court
- Javna agencija Republike Slovenije za varstvo konkurence (AVK)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 6 ZPOmK-1, Art. 101 AEUV (3062-5/2017)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 16 Apr 2026
- Izrek odločbe z dne 1. 12. 2025 (3062-5/2017) Decision of an authority
- AVK – Odločitve agencije Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 American Express Carte FranceAmerican Express Carte France: 1.5 million EUR – marketing cookies despite ‘Reject all’ €1.5m
When the website was accessed, eight non-exempt cookies were placed without any user action; after ‘Reject all’, three marketing cookies were nevertheless placed when switching to an affiliated domain, and after consent was withdrawn, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 1.5 million EUR for this and, in view of the rectification during the proceedings, refrained from issuing an order; it found an infringement of data minimisation in the recording of customer calls but did not sanction it.
Cookie settings must apply across all domains of a service – including when users move to affiliated sites.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés (Geldbuße); Verstoß gegen Art. 5 Abs. 1 lit. c DSGVO (Gesprächsaufzeichnungen) festgestellt, aber nicht sanktioniert
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Mitigating circumstances
- Corrections during the proceedings, cooperation.
- CNIL, Délibération SAN-2025-011 du 27 novembre 2025 (Légifrance) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2025 Infobel SAInfobel: data broker sold consumer data for direct marketing without legal basis €5,000
The address broker (formerly Kapitol) had passed on the complainant’s data via a media agency to an advertiser for direct marketing without being able to demonstrate valid consent. The Autorité de protection des données (Belgian Data Protection Authority, APD) imposed 40,000 EUR and ordered erasure and information of the recipients; on 3 June 2026 the Cour des marchés (Brussels Market Court) set aside these parts and itself set the fine at 5,000 EUR.
Data brokers must be able to prove for every record on which legal basis it was collected and resold.
- Authority / court
- Autorité de protection des données (APD/GBA) – Chambre Contentieuse; Cour des marchés
- Area of law
- Data protection · Marketing and consent
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1, Art. 24
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Telecoms, IT and software
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Nov 2025 SIA "EUROPARK LATVIA"Europark Latvia pays 25,000 EUR for payment reminders sent to outdated addresses €25,000
Following several complaints, the Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined how the parking operator collects contractual penalties: invoices were sent to previous rather than current registered addresses, claims were handed over to debt collection services and entered in the database of Kredītinformācijas Birojs. The authority found breaches of the principles of lawfulness, data minimisation and confidentiality and of the accountability obligation and imposed 25,000 EUR (previous year’s turnover according to the decision: 8,323,178 EUR).
Anyone collecting debts or reporting them to credit agencies must first ensure that address data are up to date.
Data quality in receivables management
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection
- Legal basis
- Art. 5 Abs. 1 lit. a, c, f und Abs. 2, Art. 83 Abs. 5 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Culpability
- intentional
- Mitigating circumstances
- Practice changed after the proceedings began; contracts concluded with the population and vehicle registers (PMLP, CSDD)
- DVI Lēmums Nr. 01630000100425-3 Par soda piemērošanu (SIA „EUROPARK LATVIA“), 24.11.2025 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Nov 2025 Les Publications Condé NastCNIL: 750,000 EUR against Vanity Fair publisher Condé Nast over cookies without consent €750,000
On vanityfair.fr, cookies requiring consent were set before any interaction with the banner, trackers were labelled as ‘strictly necessary’ and cookies continued to be placed even after ‘Reject all’. Following a complaint by noyb, the publisher had already received a formal notice in 2021; follow-up inspections in 2023 and 2025 by the French data protection authority (CNIL) showed continuing infringements.
A cookie banner must technically deliver what it promises: after ‘Reject’, no further trackers may be set – and this should be tested regularly.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Published
- 27 Nov 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Nov 2025 Betreibergesellschaft des Onlineshops About You (Sitz Hamburg; in der Mitteilung nicht namentlich genannt)About You: 505 million HUF fine and compensation for countdown pressure and discount claims €1.32m
The fashion mail-order company presented discounts in a misleading manner and exerted psychological pressure with countdowns running down by the second and scarcity notices. In addition to a fine of 505 million HUF imposed by the Gazdasági Versenyhivatal (Hungarian Competition Authority, GVH), the Hamburg-based operating company committed to paying compensation of 1,750 HUF each to all Hungarian customers who made purchases between 31 December 2022 and 31 December 2024 (estimated at over 500 million HUF) and to a consumer protection compliance programme.
Countdown timers and scarcity banners must be true – otherwise they are prohibited purchasing pressure.
Dark patterns and price information in online shops
- Authority / court
- Gazdasági Versenyhivatal (GVH)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Verbot unlauterer Geschäftspraktiken gegenüber Verbrauchern
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Acknowledgement, cooperation, customer compensation and compliance programme almost halved the fine.
- Published
- 19 Nov 2025
Original amount 505,000,000 HUF, converted at the ECB reference rate of 19 Nov 2025.
- Több mint egymilliárd forintot fizet az About You a magyaroknak Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Nov 2025 TotalEnergies Marketing France, Rubis Énergie, Rubis Terminal, EG RetailFrance: 187.5 million EUR against fuel suppliers over depot agreement in Corsica €187.5m
Between 2016 and 2023, the shareholders of the Corsican fuel storage company DPLC made the use of the depots conditional on a shareholding by means of a contractual clause; non-shareholders had to buy their fuel from their competitors, which could push up pump prices in Corsica (decision 25-D-07). Fines: TotalEnergies Marketing France 115.82 million EUR, Rubis 64.67 million EUR, EG Retail 7 million EUR.
Shared infrastructure of competitors must be open to third parties on fair terms – shareholder agreements should be reviewed under competition law.
Joint ventures of competitors and access conditions for third parties
- Authority / court
- Autorité de la concurrence
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. L.420-1 Code de commerce, Art. 101 AEUV
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Energy and utilities
- Employees
- 10,000 or more
- Published
- 17 Nov 2025
- Carburants en Corse : l'Autorité de la concurrence inflige une sanction de 187,5 millions d'euros Press release of an authority
- Décision 25-D-07 relative à des pratiques mises en œuvre dans le secteur de l'approvisionnement, du stockage et de la distribution des carburants en Corse Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Nov 2025 Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt)Croatian telecoms provider: 4.5 million EUR – customer data sent to Serbia without clauses €4.5m
The telecommunications provider allowed a software service provider belonging to the group in Serbia to access the entire SAP CRM customer database with administrator rights, from the end of 2022 without standard contractual clauses and without clear information to customers. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) also sanctioned the copying of employees’ identity cards and criminal records certificates and the failure to vet a telemarketing service provider; 4.5 million EUR in total.
Expiring or never-renewed standard contractual clauses with group companies only come to light during an inspection – transfer agreements need a deadline register.
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · International data transfers
- Legal basis
- Art. 44, 46, 12 Abs. 1, 13 Abs. 1 lit. f, 5, 6 Abs. 1, 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 14 Nov 2025
- AZOP: Administrative Fine of EUR 4.5 Million Imposed on a Telecommunications Operator (14.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Nov 2025 BSG: company car does not replace the minimum wage – additional contribution claims upheld Order
Two employers remunerated part-time workers solely by providing a company car. Germany's Federal Social Court (Bundessozialgericht, BSG) upheld the German pension insurance's claims for additional contributions: the benefit in kind does not satisfy the minimum wage entitlement, and contributions must be paid on the minimum wage owed (B 12 BA 8/24 R, B 12 BA 6/23 R).
Remuneration models involving benefits in kind should be checked for minimum wage compliance before they are introduced – otherwise additional contribution claims going back years may follow.
Minimum wage in money only – benefits in kind in payroll
- Authority / court
- Bundessozialgericht, 12. Senat (Betriebsprüfung: Deutsche Rentenversicherung Bund)
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- § 1 MiLoG; § 28p SGB IV (Betriebsprüfung)
- Action
- Order
- Status of proceedings
- final
- Published
- 14 Nov 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
11 Nov 2025 Avida Finans ABAvida Finans: 20 million SEK for loans to consumers unable to repay €1.82m
The Swedish financial supervisory authority Finansinspektionen (FI) examined consumer loans granted by the lender over four weeks in summer 2024 and found at least around 30 cases in which consumers without the ability to repay received loans. FI issued a remark and imposed 20 million SEK.
Carry out credit checks consistently even under sales pressure and verify them internally through sample checks.
Creditworthiness assessment in sales
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Consumer protection and online retail
- Legal basis
- Konsumentkreditlagen (2010:1846), Kreditprüfung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 11 Nov 2025
Original amount 20,000,000 SEK, converted at the ECB reference rate of 11 Nov 2025.
- Avida Finans får en anmärkning och en sanktionsavgift för bristande kreditprövningar (11.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Nov 2025 DoctolibFrance: 4.665 million EUR against Doctolib for abuse in doctor appointment booking €4.67m
Doctolib tied doctors with exclusivity clauses, bundled telemedicine with the appointment booking subscription and in 2018 acquired its main competitor MonDocteur in order to eliminate it (decision 25-D-06). Fines: 4.615 million EUR for exclusivity and tying, 50,000 EUR for the acquisition.
Platforms with high market shares should have exclusivity clauses, bundled offers and acquisitions of rivals reviewed under competition law.
- Authority / court
- Autorité de la concurrence
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 102 AEUV, Art. L.420-2 Code de commerce
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
- Culpability
- intentional
- Published
- 6 Nov 2025
- L'Autorité de la concurrence sanctionne Doctolib à hauteur de 4 665 000 euros Press release of an authority
- Décision 25-D-06 relative à des pratiques mises en œuvre dans le secteur de la prise de rendez-vous médicaux en ligne Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Nov 2025 UAB „Emsi“Emsi took over four filling stations without merger clearance – 1.02 million EUR €1.02m
In 2024, Emsi acquired control of four filling stations in Kaunas, Vilnius and Maišiagala through leases (via an affiliated company) and purchases without obtaining the required clearances, ignoring previous notices from the Konkurencijos taryba (Lithuanian Competition Council). For two concentrations, fines of 545,160 EUR and 477,010 EUR were imposed, a total of 1,022,170 EUR, together with an obligation to remedy the situation within three months. Source: archived copy of the press release.
Even the long-term lease of individual sites may require notification – if in doubt, ask the authority beforehand.
Merger control also for leases of individual sites
- Authority / court
- Konkurencijos taryba (Litauischer Wettbewerbsrat)
- Area of law
- Competition law · Merger control
- Legal basis
- Konkurencijos įstatymas (Anmelde- und Genehmigungspflicht für Zusammenschlüsse)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 6 Nov 2025
- Konkurencijos taryba, Pranešimas 2025-11-06 (Archivkopie web.archive.org von kt.gov.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Nov 2025 Coinbase Europe LimitedIreland: 21.5 million EUR against Coinbase Europe – 30 million transactions unchecked €21.5m
In a settlement of 5 November 2025, the Central Bank of Ireland imposed a reprimand and 21,464,734 EUR (after a 30% discount on 30,663,906 EUR) for breaches of transaction monitoring obligations between April 2021 and March 2025: because of configuration errors in the monitoring system, more than 30 million transactions worth over 176 billion EUR – around 31% of all transactions – were not properly monitored over a period of twelve months. The subsequent review took almost three years and led to 2,708 suspicious transaction reports; the High Court confirmed the sanction on 12 January 2026, and it is the Central Bank's first enforcement action in the crypto sector.
Test monitoring rules regularly for complete coverage – a silent configuration error can go undetected for years.
- Authority / court
- Central Bank of Ireland
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- 30% settlement discount
- Published
- 6 Nov 2025
- Enforcement Action against Coinbase Europe Limited Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Nov 2025 Groupe ParfaitFrance: 7.6 million EUR against Groupe Parfait for failing to meet merger remedies (Martinique) €7.6m
In 2022, clearance of an acquisition in food retail in Martinique was made conditional on the divestiture of a Géant Casino hypermarket by September 2023; Parfait only sold it in September 2025, allowed the value of the assets to deteriorate and obstructed the trustee (decision 25-D-05). Fines: 4.5 million EUR (divestiture), 2.5 million EUR (preservation of value), 600,000 EUR (cooperation).
Merger control commitments are binding – missed deadlines and a lack of cooperation with the trustee are sanctioned separately.
Compliance with merger remedies and cooperation with trustees
- Authority / court
- Autorité de la concurrence
- Area of law
- Competition law · Merger control
- Legal basis
- Verstoß gegen Zusagen aus Freigabeentscheidung 22-DCC-254 (Fusionskontrolle, Code de commerce)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Retail and e-commerce
- Published
- 3 Nov 2025
- Distribution alimentaire à la Martinique : l'Autorité inflige au groupe Parfait des sanctions (25-D-05) Press release of an authority
- Décision 25-D-05 relative au respect des engagements annexés à la décision n° 22-DCC-254 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Oct 2025 "MAXIMA Latvija" SIAMaxima Latvija pays 1.87 million EUR for price pressure on food suppliers €1.87m
From November 2021 to August 2024, the retailer (market share 28%) put pressure on economically dependent suppliers: price increases remained unapproved for months, lower prices were demanded in the form of ultimatums and delisting was threatened. The Konkurences padome (Latvian Competition Council) found an unfair trading practice, imposed 1,872,805 EUR and set clear deadlines for negotiations.
Purchasing departments of retailers with strong market power need clear rules for price negotiations – threats of delisting are off limits.
Fair purchasing negotiations with suppliers
- Authority / court
- Konkurences padome (Lettischer Wettbewerbsrat)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Negodīgas tirdzniecības prakses aizlieguma likums (NTPAL)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 5 Nov 2025
- Konkurences padome soda „MAXIMA Latvija“ SIA par negodīgas tirdzniecības prakses īstenošanu (05.11.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Oct 2025 MM Grupp OÜCinema chain MM Grupp (Apollo) took over Forum Cinemas without clearance – 7.5 million EUR €7.51m
In 2021, the Estonian parent company of Apollo cinemas acquired control of Forum Cinemas Lithuania before the notified merger had been cleared and integrated the cinemas in Vilnius and Kaunas into its network, even though the Konkurencijos taryba (Lithuanian Competition Council) had provisionally expressed competition concerns. Fine of 7,507,930 EUR (0.8% of consolidated worldwide turnover) and obligation to end the infringement within six months. Source: archived copy of the press release.
No implementation before clearance: restructurings and leases can also constitute prohibited early implementation.
- Authority / court
- Konkurencijos taryba (Litauischer Wettbewerbsrat)
- Area of law
- Competition law · Merger control
- Legal basis
- Konkurencijos įstatymas (Vollzugsverbot bei Zusammenschlüssen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 30 Oct 2025
- Konkurencijos taryba, Pranešimas 2025-10-30 (Archivkopie web.archive.org von kt.gov.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
28 Oct 2025 Landesbank Hessen-Thüringen Girozentrale (Helaba)BaFin: fine against Helaba over inadequate monitoring systems for money laundering prevention €20,000
By decision of 28 October 2025 (final since 7 November 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 20,000 EUR because, from October 2022 to September 2023, the Landesbank operated data processing systems for money laundering prevention that were only partially adequate. Under the German Banking Act (KWG), the criteria by which monitoring identifies suspicious transactions must be documented, and the systems must be checked regularly by an independent auditor.
Transaction monitoring needs documented indicators and a regular independent quality review – the mere existence of software is not enough.
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Internal controls
- Legal basis
- § 56 Abs. 2 Nr. 11b KWG (Betrieb angemessener Datenverarbeitungssysteme zur Geldwäscheprävention)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 10 Dec 2025
- Mangelhafte Geldwäscheprävention: BaFin setzt Bußgeld gegen die Landesbank Hessen-Thüringen Girozentrale fest Press release of an authority
- Bekanntmachung zur Landesbank Hessen-Thüringen Girozentrale Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Oct 2025 SINOP ALFA, s.r.o.SINOP ALFA: 70,000 EUR for refusing to hand over business mobile phone during inspection €70,000
During an unannounced inspection in the air-conditioning, refrigeration and heat pump services sector, the company repeatedly refused to produce a mobile phone used for business purposes. The Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) regarded this as obstruction of the inspection and imposed 70,000 EUR, around 1% of the previous year’s turnover (not final).
Business smartphones are part of the documents that may be inspected – a dawn raid guide for employees prevents costly wrong reactions.
Conduct during inspections (dawn raids), handing over mobile devices
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Mitwirkungspflicht bei Nachprüfungen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- intentional
- Published
- 28 Oct 2025
- KARTELY: PMÚ uložil pokutu za nespoluprácu počas inšpekcie Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Aktia Pankki OyjAktia: 865,000 EUR – other people’s data visible in OmaKanta and OmaKela via bank login €865,000
Following a technical change to the bank’s strong electronic identification service, a disruption lasting around one hour occurred in January 2023 during which customers logging in with Aktia credentials to services such as OmaKanta, OmaKela, unemployment funds, insurers and healthcare providers saw data of other persons; around 350 people were affected. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) criticised the deficient planning, implementation and testing of the change and imposed 865,000 EUR in addition to a reprimand.
Changes to identification services have effects far beyond one’s own organisation – testing and release processes must reflect this.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 28 Oct 2025
- Finlex – Tietosuojavaltuutettu 23.10.2025 (pankin tunnistamispalvelun muutosprosessi) Decision of an authority
- Tietosuojavaltuutettu – Aktialle seuraamusmaksu tietoturvapuutteista vahvan sähköisen tunnistamisen palvelussa (28.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Comune di CurtaroloMunicipality of Curtarolo: 15,000 EUR for video surveillance of streets and employees €15,000
The municipality in the province of Padua monitored public streets and work areas without a sound legal basis, without adequate information and without a data protection impact assessment; recordings were used for disciplinary purposes, and an employee was secretly filmed while on sick leave. Italy's data protection authority (Garante per la protezione dei dati personali) imposed a fine of 15,000 EUR (5,000 EUR for public surveillance, 10,000 EUR for workplace surveillance).
Do not repurpose video recordings for disciplinary proceedings; specific employment law protections apply to employees.
Purpose limitation in video surveillance and employee data
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Video surveillance
- Legal basis
- DSGVO Art. 5, 6, 12, 13, 35, 88
- Action
- Fine
- Status of proceedings
- final
- Sector
- Public sector
- Provvedimento del 23 ottobre 2025 [10196164] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 Komornik Sądowy przy Sądzie Rejonowym w S. (Gerichtsvollzieherkanzlei, im Bescheid pseudonymisiert)Bailiff: 20,900 PLN – documents with PESEL number misdirected, not notified €4,938
In October 2023, an uninvolved person received a debtor’s enforcement documents containing name, address, date of birth, PESEL number, amount of the claim and employer. The bailiff’s office neither notified the supervisory authority nor informed the data subject; the UODO (Poland’s data protection authority) imposed 7,700 PLN for the failure to notify and 13,200 PLN for the failure to inform the data subject, and ordered the data subject to be informed within three days.
Where identification numbers such as the PESEL number are disclosed, a high risk can almost always be assumed – notification of the authority and of the data subject is then mandatory.
Checking postal mailings; notifying data breaches involving identification numbers
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1, Art. 34 Abs. 1 und 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
Original amount 20,900 PLN, converted at the ECB reference rate of 23 Oct 2025.
- UODO, Decyzja DKN.5131.17.2024 vom 23.10.2025 (nicht rechtskräftig) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Oct 2025 TotalEnergies; TotalEnergies Electricité et Gaz de FranceParis Judicial Court: TotalEnergies advertising on climate neutrality misleading Order
In an action brought by Greenpeace France, Les Amis de la Terre and Notre Affaire à Tous, the Paris Judicial Court (Tribunal judiciaire de Paris, 34th chamber) found that TotalEnergies had advertised on totalenergies.fr with the goal of ‘carbon neutrality by 2050’ and its role as a player in the energy transition without disclosing that oil and gas production continues to be expanded – a misleading commercial practice. The court ordered the communication to cease, damages to be paid to the associations and the operative part of the judgment to be published on the website (RG 22/02955); claims relating to gas and agrofuels were dismissed.
Net-zero targets may only be advertised to consumers with reference to the actual business strategy.
Climate targets in consumer communication
- Authority / court
- Tribunal judiciaire de Paris (34. Kammer)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Art. L121-1 ff. Code de la consommation (Umsetzung der Richtlinie 2005/29/EG)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Employees
- 10,000 or more
- Published
- 23 Oct 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Oct 2025 Taxshelter.be SATaxshelter.be: 75,000 EUR for missing prospectus supplement on guarantee risks €75,000
After the tax authority had refused the tax shelter certificates for a financed show and the insurer left cover open, the provider failed to inform investors of this material risk in good time by means of a prospectus supplement. The Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA) accepted a settlement of 75,000 EUR with publication by name.
New material risks for investors trigger an immediate obligation to publish a supplement – not only in the next annual prospectus.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Verordnung (EU) 2017/1129 Art. 23; Loi du 11 juillet 2018 (Loi Prospectus)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 21 Oct 2025
- FSMA – Règlement transactionnel Taxshelter.be (21.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Oct 2025 WhatsApp Ireland Limited (Dienst „Channels“) und PinterestWhatsApp (Channels) and Pinterest: designated as ‘exposed to terrorist content’ Order
After both hosting services had received at least two final removal orders from EU authorities within twelve months, Coimisiún na Meán (Ireland’s media and online safety regulator) designated them as exposed to terrorist content under the TCO Regulation. They must take specific protective measures and report on them within three months; the regulator assesses their effectiveness.
Repeated removal orders trigger additional, monitored prevention obligations for platforms – content moderation must be prepared for this.
- Authority / court
- Coimisiún na Meán (irische Medien- und Online-Sicherheitsaufsicht)
- Area of law
- AI and digital regulation · Platform obligations
- Legal basis
- Verordnung (EU) 2021/784 (Terrorist Content Online Regulation): Einstufung als exponiert, spezifische Maßnahmen
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Coimisiún na Meán: Further determinations made under Terrorist Content Online Regulation (TCOR) (17.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Oct 2025 Zimpler ABZimpler: 3 million SEK over anti-money laundering deficiencies at gambling-related payment service €272,245
Between July 2023 and April 2024, the payment service provider, a substantial part of whose business is linked to the gambling sector, had gaps in its general risk assessment (including a missing assessment of its currency exchange service), in its customer risk assessment and in customer due diligence. The Swedish financial supervisory authority Finansinspektionen (FI) issued a remark and imposed 3 million SEK.
Include every new product – even an ancillary service such as currency exchange – in the money laundering risk assessment before launch.
Money laundering risks in the gambling environment
- Authority / court
- Finansinspektionen (FI)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Penningtvättslagen (2017:630)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 15 Oct 2025
Original amount 3,000,000 SEK, converted at the ECB reference rate of 15 Oct 2025.
- Zimpler får en anmärkning och sanktionsavgift (15.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 AS Inbank FinanceOrder against Inbank Finance over deficiencies in creditworthiness assessment Order
During an inspection, the Finantsinspektsioon (Estonian Financial Supervision Authority) found that Inbank Finance’s internal rules on assessing the creditworthiness of consumers did not fully comply with the law and that the assessment itself showed deficiencies. It issued an order requiring the company to remedy the deficiencies by mid-December. Date = publication.
Creditworthiness assessments must be documented, rule-based and actually applied in day-to-day business.
Responsible lending in sales
- Authority / court
- Finantsinspektsioon (Estnische Finanzaufsicht)
- Area of law
- Consumer protection and online retail
- Legal basis
- Gesetz über Kreditgeber und -vermittler (KAVS), verantwortungsvolle Kreditvergabe
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 14 Oct 2025
- Finantsinspektsioon tegi AS-ile Inbank Finance ettekirjutuse (14.10.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 J.P. Morgan SEBaFin: 45 million EUR against J.P. Morgan SE over late suspicious activity reports €45m
By decision of 13 October 2025 (final since 30 October 2025), Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 45 million EUR on J.P. Morgan SE because the institution had culpably breached its duty of supervision in the internal processes for filing money laundering suspicious activity reports; from 4 October 2021 to 30 September 2022, suspicious activity reports were systematically not filed on time. BaFin points out that, in the case of systematic infringements, the amount of the fine can be based on the institution's total turnover.
File suspicious activity reports without delay – systematic backlogs in the reporting process are themselves an infringement, and the fine can then be calculated on the basis of the institution's total turnover.
Filing money laundering suspicious activity reports without delay
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- § 130 Abs. 1 OWiG (Aufsichtspflichtverletzung) i. V. m. Pflichten nach dem GwG (Verdachtsmeldungen); Bekanntmachung nach § 57 Abs. 1 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Published
- 6 Nov 2025
- Mängel in der Geldwäscheprävention: Bußgeld in Höhe von 45 Millionen Euro gegen J.P. Morgan SE Press release of an authority
- Bekanntmachung zur J.P. Morgan SE (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Wonderinterest Trading LtdCyprus: 100,000 EUR against Wonderinterest Trading over misleading client information €100,000
For 2022 to 2024, the Cyprus Securities and Exchange Commission (CySEC) found that the investment firm had no adequate compliance procedures, did not define target markets for its financial instruments, did not act in the best interests of clients and did not inform clients in a fair, clear and not misleading manner. It imposed fines of 50,000, 30,000 and 20,000 EUR; a judicial review of the decision has been recorded.
Advertising statements by financial service providers must present risks in a balanced way – marketing belongs in the compliance approval process.
Fair and not misleading marketing communications
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Sec. 17(2), 17(3)(c), 22(1), 25(1), 25(3)(a) Gesetz über Wertpapierdienstleistungen 2017; Art. 22, 44 Delegierte VO (EU) 2017/565
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Financial services and insurance
- Published
- 17 Dec 2025
- CySEC Board Decision – Wonderinterest Trading Ltd – Total fine €100.000 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Sport & Spa Gest, S.L.AEPD: 17,600 EUR against sports centre over location tags for swimmers €17,600
The operator of a sports facility rented a Bluetooth system with which swimmers were located in the pool via tags and their training was recorded. The Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) imposed 8,000 EUR for the processing of special categories of data and – after a 20% reduction for immediate payment – 4,000, 2,400 and 3,200 EUR for lack of a legal basis, insufficient information and a deficient impact assessment (17,600 EUR in total); the request for reconsideration was unsuccessful.
New tracking or sensor technology in customer-facing operations requires a legal basis, information and a genuine impact assessment in advance.
- Authority / court
- Agencia Española de Protección de Datos (AEPD)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 6 Abs. 1, Art. 9 Abs. 1, Art. 13, Art. 35 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Mitigating circumstances
- Partial immediate payment (20% reduction under Art. 85 LPACAP).
- AEPD Resolución PS/00160/2024 (EXP202308414) Decision of an authority
- AEPD Resolución recurso de reposición PS/00160/2024 (Datum der Ausgangsentscheidung 13.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Finamore S.A.Finamore: licence of insurance broker withdrawn over serious deficiencies Other
The Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broking firm’s licence (effective from 1 December 2025), among other things for using unregistered intermediaries, lacking internal expertise, insufficiently protected confidential data, economically unexplained payment flows with affiliated companies, incomplete or false information provided to the supervisory authority and deficient customer information.
False information to the supervisory authority and unregistered distribution partners can cost the business its existence – not just a fine.
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 303 Abs. 3 lit. c
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 29 May 2026
- CAA – Sanction administrative FINAMORE S.A. (29.05.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
9 Oct 2025 BGH: price reduction only permissible with a clearly legible 30-day lowest price Order
A food discounter advertised a coffee with a price reduction without stating the lowest total price of the previous 30 days unambiguously, clearly recognisably and legibly. In an action brought by the Wettbewerbszentrale (Centre for Protection against Unfair Competition), the BGH upheld the injunction issued by the lower courts (Regional Court of Amberg, Higher Regional Court of Nuremberg).
In all discount advertising, state the 30-day lowest price as clearly as the discount itself.
Price information in discount advertising (30-day lowest price)
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 183/24
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 11 Abs. 1 PAngV; § 5a Abs. 1, § 5b Abs. 4 UWG
- Action
- Order
- Status of proceedings
- final
- Sector
- Retail and e-commerce
- Published
- 9 Oct 2025
- Unzulässige Werbung mit einer Preisermäßigung (Nr. 184/2025) Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Oct 2025 Zu Disain OÜZu Disain must delete personal data collected from the land register by script Order
The company had used an automated script to carry out mass queries in the electronic land register and stored data of natural persons without demonstrating a legal basis; it did not respond to requests from the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered erasure with proof or a statement of a legal basis with a balancing of interests; a penalty payment of 2,000 EUR was threatened.
Publicly accessible register data remain personal data – automated scraping requires its own legal basis.
Public registers are no licence for data collection
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 5 Abs. 1 lit. a, Art. 6 Abs. 1 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Other
- Ettekirjutus-hoiatus nr 2.1.-4/25/1239-2660-6 (Zu Disain OÜ), 06.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Sep 2025 HmbBfDI: 195,000 EUR against retailer over ignored data subject requests €195,000
A retail company (name not published) had advertising letters sent via service providers and, in several cases, failed for an extended period to respond in time to the data subject rights that recipients then asserted. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of 195,000 EUR; the measure was published in the interim report of 30 September 2025 (exact date of the decision not stated).
Companies that send advertising must have a working process for access and objection requests – even if the mailing is outsourced.
Timely handling of access requests
- Authority / court
- Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO (Betroffenenrechte)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 30 Sep 2025
- Zwischenbilanz 2025: HmbBfDI verhängt Bußgelder von insgesamt 775.000 Euro Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Sep 2025 „Смарт Софт“ ЕООДBidder Smart Soft denigrates competitor in letters to schools – 37,410 leva €19,128
During ongoing tenders for school equipment, Smart Soft sent dozens of identical letters to schools in the Plovdiv/Pazardzhik/Panagyurishte region containing untrue or distorted statements about its competitor Evroklas-konsult. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found damage to reputation (Art. 30 ZZK – Bulgarian Protection of Competition Act) over around two months and imposed 3% of 2024 turnover, i.e. 37,410 leva. An appeal has been lodged against the decision.
Have sales letters about competitors – especially to public contracting authorities – legally reviewed before they are sent.
Communication about competitors in sales
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 30 ZZK (Schädigung des guten Rufs eines Wettbewerbers)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
Original amount 37,410 BGN, converted at the ECB reference rate of 25 Sep 2025.
- КЗК Публичен електронен регистър – Производство (Решение № 869 от 25.09.2025; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Sep 2025 Nova Ljubljanska banka d. d.NLB: reprimand because PSD2 interface exposed 57 account numbers Reprimand or warning
After an update of the PSD2 interface for third-party providers in July 2023, the confidentiality of 57 IBAN accounts of bank customers was not ensured. The banking supervisor, Banka Slovenije (Bank of Slovenia), issued a reprimand to the bank and to the responsible IT development director for breaching the obligation to protect confidential data (final).
Every change to customer interfaces requires testing for data leakage before go-live – responsibility also lies with the manager in charge.
Security testing for software releases of interfaces
- Authority / court
- Banka Slovenije
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Art. 146, Art. 396 Abs. 1 Nr. 18 ZBan-3 (slowenisches Bankengesetz)
- Action
- Reprimand or warning
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Liability of senior managers
- Reprimand also issued to the responsible Director of IT Development (Dejan Pust).
- Razkritje informacij o izrečeni sankciji pravni in odgovorni osebi – Nova Ljubljanska banka d. d. Decision of an authority
- Banka Slovenije – Informacije o izrečenih ukrepih Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Sep 2025 Go West Invest SAGo West Invest: 10,000 EUR for outdated information note in tax shelter offering €10,000
From June 2021 to October 2024, the company, which raises tax shelter funds through public offerings, kept a public offering on its website with an information note from 2020 without publishing an updated note and filing it with the Autorité des services et marchés financiers (Belgian Financial Services and Markets Authority, FSMA); several dozen investors with an investment volume of under 5 million EUR were affected. The FSMA accepted a settlement of 10,000 EUR.
Investor information has an expiry date – a deadline calendar for mandatory documents prevents infringements.
- Authority / court
- Autorité des services et marchés financiers (FSMA)
- Area of law
- Capital markets and financial supervision · Disclosure and reporting obligations
- Legal basis
- Loi du 11 juillet 2018 (Loi Prospectus), Art. 10, 11
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 16 Sep 2025
- FSMA – Règlement transactionnel SA Go West Invest (16.09.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN €2,669
For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.
This also applies in small practices and companies: management cannot be its own data protection officer.
Role and independence of the data protection officer; release of patient records
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- An independent external data protection officer was appointed in July 2024.
- Published
- 29 Sep 2025
Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.
- Prezes firmy nie może być jednocześnie IOD. Kara dla spółki Specer Press release of an authority
- Decyzja DKN.5131.7.2025 z 12 września 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 S-Pankki OyjS-Pankki: 1.8 million EUR over security flaw in bank identification service €1.8m
After a new login function was introduced in the S-mobiili app in April 2022, a vulnerability in the identification service made it possible until August 2022 to access online banking and services requiring strong authentication using other customers’ credentials; misuse caused financial losses. The bank had introduced the function without sufficient risk analysis and testing; the sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.8 million EUR in addition to a reprimand, with a previous reprimand acting as an aggravating factor.
Before launch, new functions in authentication services require a risk analysis of all user paths and targeted security testing.
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio (Datenschutzbeauftragter, Sanktionsgremium)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, Art. 25 Abs. 1, Art. 32 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- yes
- Mitigating circumstances
- The fine imposed by the financial supervisory authority (7.67 million EUR) for the same facts was taken into account (fine around one third of the amount that would otherwise have been imposed); according to the bank, it compensated customers for direct losses.
- Published
- 10 Sep 2025
- Finlex – Tietosuojavaltuutettu 8.9.2025, TSV/3606/2024 (pankin tunnistuspalvelu) Decision of an authority
- Tietosuojavaltuutettu – S-Pankille seuraamusmaksu S-mobiilin tietoturvahaavoittuvuudesta (10.09.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
8 Sep 2025 SIA "ZZ Dats"IT service provider ZZ Dats pays 300,000 EUR after data leak as processor €300,000
Unknown persons accessed the system operator’s databases via several websites and obtained personal data. The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) initially imposed 400,000 EUR; in the objection procedure, the director set aside the allegation relating to the company’s role as controller because ZZ Dats was a processor, and set the fine at 300,000 EUR for insufficient security measures under Art. 32 GDPR. The company has brought an action.
Processors are also independently liable for the security of the systems they operate.
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2, Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Telecoms, IT and software
- DVI – Zusammenfassung der Entscheidung zu SIA „ZZ Dats“ (08.09.2025) Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Sep 2025 „Paysera LT“, UABPaysera took over e-money institution Contis without approval – 400,000 EUR €400,000
Paysera acquired 100% of the shares in UAB ‘Finansinės paslaugos „Contis“’ before the assessment period had expired and without a non-objection from the supervisory authority; in April 2025, the Lietuvos bankas (Bank of Lithuania, financial supervisor) objected to the acquisition owing to a lack of documents on reputation, financial soundness and money laundering risks. In addition, the annual financial statements and other reports were not approved and submitted on time. Fine of 400,000 EUR and obligation to remedy by 30 September 2025. Source: archived copy of the press release.
Complete acquisitions of holdings in supervised institutions only after approval – otherwise voting rights are suspended and fines loom.
- Authority / court
- Lietuvos bankas (Litauische Zentralbank, Finanzaufsicht)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Elektroninių pinigų ir elektroninių pinigų įstaigų įstatymas (Inhaberkontrolle, Berichtspflichten)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 5 Sep 2025
- Lietuvos bankas, Pranešimas 2025-09-05 (Archivkopie web.archive.org von lb.lt) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert)Austrian advertising agency: 870 EUR – alert about security gap dismissed as spam €870
Customer data (including names, e-mail addresses, dates of birth, telephone numbers) could be retrieved via an unprotected development server of the advertising agency. An employee took the first alert from an external party in January 2025 to be spam; only a second alert in February reached management, which closed the gap but only notified the incident on 2 May 2025 after being requested to do so by the Datenschutzbehörde (Austrian Data Protection Authority, DSB). The authority attributed the employee’s conduct to the company.
External alerts about security gaps need a clear intake channel – what ends up in spam still counts as known.
Recognising and escalating alerts about security gaps
Missing or inadequate training played a role in the decision.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 33 Abs. 1 iVm Art. 83 Abs. 4 lit. a DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- Culpability
- negligent
- Mitigating circumstances
- No previous infringements and cooperation in the proceedings; gap closed immediately after the second alert, employees trained subsequently.
- DSB, Straferkenntnis GZ 2025-0.699.550 vom 04.09.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Sep 2025 Einheitlicher Abwicklungsausschuss (Single Resolution Board, SRB)CJEU: pseudonymised data in disclosure to Deloitte – EDPS v SRB —
The Single Resolution Board (SRB) passed on pseudonymised comments from former Banco Popular shareholders to Deloitte without informing the data subjects; the European Data Protection Supervisor (EDPS) considered this an infringement of the duty to inform. The Court of Justice of the European Union (Case C-413/23 P) set aside the judgment of the General Court and clarified that the duty to inform is to be assessed from the controller's perspective at the time of collection; the case was referred back to the General Court.
Pseudonymisation does not release the controller from informing data subjects about the recipients of their data.
- Authority / court
- Gerichtshof der Europäischen Union, Rs. C-413/23 P
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Verordnung (EU) 2018/1725 (Informationspflicht)
- Status of proceedings
- under appeal
- Sector
- Public sector
- Published
- 4 Sep 2025
- Press Release No 107/25: Judgment of the Court in Case C-413/23 P EDPS v SRB Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
3 Sep 2025 SURYS SAS (Gruppe Imprimerie Nationale)Hologram manufacturer SURYS: CJIP of 18.4 million EUR in the Ukrainian passport case €18.4m
From 2013, SURYS supplied security holograms for Ukrainian passports to the state-owned company Polygraph via an interposed Estonian company; the investigation (following a request for mutual legal assistance from Ukraine's National Anti-Corruption Bureau, NABU) concerned misappropriation of public funds, bribery of foreign public officials and money laundering. Public interest fine of 18,363,007 EUR, plus 3,770,000 EUR in damages to the Ukrainian state and a three-year AFA compliance programme.
If a state customer insists on an interposed trader without any discernible added value, treat this as a red flag for misappropriation and bribery.
Interposed trading companies and sales agents
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); Bestechung ausländischer Amtsträger, Geldwäsche
- Action
- Fine
- Status of proceedings
- final
- Sector
- Other
- Employees
- 250 to 999
- Culpability
- intentional
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 3 Sep 2025
- Communiqué de presse du procureur de la République financier – CJIP SURYS Press release of an authority
- Convention judiciaire d'intérêt public – SURYS (08.07.2025) Decision of an authority
- Ministère de la Justice: Conventions judiciaires d'intérêt public (Verzeichnis) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Sep 2025 IDdesign A/SIDdesign: High Court raises GDPR fine to 1.5 million DKK – group turnover counts €200,986
The furniture retailer had stored data of around 385,000 customers in a legacy system without retention periods. The district court had imposed 100,000 DKK; following a referral to the CJEU on whether the fine is to be calculated on the basis of the turnover of the entire group, the High Court increased the fine to 1.5 million DKK.
Retention periods also apply to legacy systems in individual branches – and the group turnover counts when setting the fine.
- Authority / court
- Vestre Landsret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. e, Art. 83
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
Original amount 1,500,000 DKK, converted at the ECB reference rate of 2 Sep 2025.
- Datatilsynet – Møbelfirma indstillet til bøde (Opdatering zum Verfahrensausgang) Press release of an authority
- Domsdatabasen – Vestre Landsret SS-364/2021-VLR, Dom 02.09.2025 Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Sep 2025 Google LLC und Google Ireland LimitedGoogle: 325 million EUR – advertising cookies at account creation and ads in the Gmail inbox €325m
When creating a Google account, users were not sufficiently informed that advertising cookies were necessarily placed in the process; in addition, Google displayed advertisements between e-mails in Gmail without prior consent. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 200 million EUR on Google LLC and 125 million EUR on Google Ireland and ordered remedial action within six months, subject to a penalty payment of 100,000 EUR per day.
Do not tacitly tie advertising cookies to account creation – and advertising in the inbox counts as direct marketing requiring consent.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés; Art. L. 34-5 Code des postes et des communications électroniques
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Sep 2025 Infinite Styles Services Co. Limited (Shein)Shein: 150 million EUR – cookies without consent and despite rejection €150m
On shein.com, advertising cookies were placed without consent as soon as the site was accessed; in addition to an incomplete cookie banner, there was an advertising pop-up without an option to reject. After clicking ‘Reject all’ or withdrawing consent, cookies continued to be read. The Commission nationale de l’informatique et des libertés (French data protection authority, CNIL) imposed 150 million EUR.
A cookie banner must work technically: rejecting and withdrawing consent must actually stop cookies from being placed and read.
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 82 Loi Informatique et Libertés (Umsetzung von Art. 5 Abs. 3 ePrivacy-Richtlinie)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Sep 2025 SIA "SILTUMTEHSERVISS", SIA "Apkure IM", SIA "ADAPTERIS", SIA "Alpex", SIA "Infrakom"Bid-rigging cartel in pipeline construction contracts – five construction firms pay 513,508 EUR €513,508
From 2021 to 2024, two groups of construction companies coordinated in more than 30 public tenders for the construction and repair of utility pipelines: they exchanged sensitive information, determined winners and submitted sham bids. Prompted by information from the contracting entity Rīgas namu pārvaldnieks, the Konkurences padome (Latvian Competition Council) imposed a total of 513,508.08 EUR.
Jointly preparing bids with competitors – even where the work is later carried out jointly – is a cartel; tender teams must know this.
Competition law in tenders
- Authority / court
- Konkurences padome (Lettischer Wettbewerbsrat)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 11 Abs. 1 Konkurences likums
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Mitigating circumstances
- All companies except Infrakom concluded a settlement with the Competition Council, acknowledged the facts and waived an appeal; in return, a 10% fine reduction.
- Published
- 10 Sep 2025
- KP atklāj karteli inženierkomunikāciju būvdarbu iepirkumos (10.09.2025) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Sep 2025 Blacktower Financial Management (Cyprus) LtdCyprus: Blacktower Financial Management pays 70,000 EUR over conflicts of interest €70,000
For the period November 2020 to May 2025, the Cyprus Securities and Exchange Commission (CySEC) investigated the investment firm’s handling of conflicts of interest and its general conduct of business and information obligations towards clients. The proceedings ended with a settlement of 70,000 EUR, which the company has paid.
Conflicts of interest must be identified, documented and managed vis-à-vis clients – adviser training is the basis for this.
Recognising conflicts of interest in investment advice
- Authority / court
- Cyprus Securities and Exchange Commission (CySEC)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Art. 24(1), 25(1) Gesetz über Wertpapierdienstleistungen 2017; Art. 37(4) CySEC-Gesetz
- Action
- Other
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 17 Nov 2025
- CySEC Board Decision – Blacktower Financial Management (Cyprus) Ltd – Settlement €70.000 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
26 Aug 2025 Acqua Minerale San Benedetto S.p.A.AGCM: San Benedetto removes ‘CO2 neutral’ claim on Ecogreen bottles Other
Labels, the website and commercials for the Ecogreen line claimed that bottle production caused no greenhouse gas emissions and even had a positive effect on the environment. Following an intervention by Italy's competition and consumer protection authority (Autorità Garante della Concorrenza e del Mercato, AGCM) (moral suasion, case PS12596), the mineral water producer removed the claim ‘impatto zero CO2’ in mid-July 2025, revised nature motifs and added a QR code linking to sustainability information.
‘Zero emissions’ promises on packaging can hardly be substantiated; it is better to present specific reduction steps transparently.
Climate claims on packaging
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Codice del Consumo (unlautere Geschäftspraktiken), Verfahren PS12596
- Action
- Other
- Status of proceedings
- final
- Sector
- Food and agriculture
- Mitigating circumstances
- Voluntary amendment of all labels and advertising materials following the authority's intervention.
- Published
- 26 Aug 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Aug 2025 Varengold Bank AGBaFin: 3.3 million EUR fine and penalty payment against Varengold Bank €3.8m
By decision of 22 August 2025, Germany's Federal Financial Supervisory Authority (BaFin) imposed a fine of 3.3 million EUR because the bank systematically filed suspicious activity reports late from June 2023 to March 2025; in February 2025, a penalty payment of 500,000 EUR had already been imposed for failure to comply with a 2023 order concerning Iran-related transactions (total 3.8 million EUR). In addition, in July 2025 BaFin ordered comprehensive remediation of the deficiencies in money laundering prevention, with an action plan and reporting obligations.
Failing to implement a supervisory order risks penalty payments and a comprehensive package of measures in addition to the fine.
Suspicious activity reports and handling of high-risk transactions
- Authority / court
- Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- Bußgeld: § 56 Abs. 1 S. 1 Nr. 69, Abs. 3 GwG; Anordnung: § 51 Abs. 2 GwG, § 44 Abs. 1 KWG; Zwangsgeld: § 14 VwVG i. V. m. § 17 FinDAG; Bekanntmachung nach § 57 Abs. 1 GwG
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- yes
- Published
- 16 Sep 2025
- Varengold Bank AG: BaFin ordnet umfassende Mängelbeseitigung in der Geldwäscheprävention an und setzt Geldbuße fest Press release of an authority
- Bekanntmachungen zur Varengold Bank AG (§ 57 GwG) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Aug 2025 Portugal: 30,000 EUR for exclusive tying of banana growers on Madeira €30,000
A dominant company for the collection, distribution and marketing of Madeira bananas (name not given) required producers to sign exclusivity declarations. In a settlement procedure (PRC/2025/6), it ended the practice and paid 30,000 EUR (date = press release).
Dominant buyers must not tie suppliers through exclusivity clauses – even small regional markets are being watched.
- Authority / court
- Autoridade da Concorrência (AdC)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Lei da Concorrência (Lei n.º 19/2012), Art. 11.º; Art. 102 AEUV
- Action
- Fine
- Status of proceedings
- final
- Sector
- Food and agriculture
- Mitigating circumstances
- Settlement (transação), full cooperation, immediate cessation, short duration
- Published
- 13 Aug 2025
- AdC sanciona empresa por abuso de posição dominante na comercialização de banana da Madeira Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR €2,990
A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.
Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.
Identity verification and fraud detection in remote applications
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 12 Aug 2025
Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.
- ANSPDCP – Comunicat de presă 12.08.2025 (Asociația Casa de Ajutor Reciproc „FLEXICREDIT”) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2025 DSB: fine against news portal that ignored instruction on cookie banner €6,200
In 2023, the Austrian data protection authority (Datenschutzbehörde, DSB) had ordered a local news portal (a media GmbH & Co KG, name pseudonymised) by decision to offer, on the first layer of the cookie banner, an equivalent option to close it without consent. Because the company did not implement this from October 2024 until at least March 2025, the DSB imposed 6,200 EUR for failure to comply with an instruction; the penalty decision is final.
Implement orders of the supervisory authority on time – ignoring them risks a separate fine in addition to the original infringement.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Art. 58 Abs. 2 lit. d i. V. m. Art. 83 Abs. 6 DSGVO; Art. 7 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Media and online platforms
- DSB Straferkenntnis GZ 2025-0.276.820 vom 06.08.2025 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
4 Aug 2025 Infinite Styles Services Co. Ltd (Shein)AGCM: 1 million EUR fine against Shein for misleading environmental claims €1m
Italy's competition and consumer protection authority (Autorità Garante della Concorrenza e del Mercato, AGCM) objected to vague and in part false claims about circular design and recyclability, about the ‘green’ evoluSHEIN collection (only a small share of the range) and about emission targets, while emissions rose in 2023/2024. The ultra-fast-fashion model is subject to a heightened duty of care, the authority held; it imposed 1 million EUR (case PS12709).
Communicate climate targets and recycling promises only if they are specific, substantiated and consistent with actual developments.
Verifiable sustainability communication in online retail
- Authority / court
- Autorità Garante della Concorrenza e del Mercato (AGCM)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Codice del Consumo (unlautere Geschäftspraktiken), Verfahren PS12709
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Employees
- 10,000 or more
- Published
- 4 Aug 2025
- PS12709 - Italian Competition Authority: 1 million euros fine imposed on Shein for misleading and omissive green claims Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Jul 2025 BGH: no before-and-after images for nose and chin correction with hyaluronic acid Order
A practice for aesthetic treatments advertised hyaluronic acid filler injections for the nose and chin on its website and on Instagram using before-and-after images. In an action brought by a consumer advice centre (Verbraucherzentrale), the BGH upheld the injunction issued by the Higher Regional Court of Hamm (OLG Hamm): such procedures are deemed to be surgical cosmetic procedures, for which this kind of advertising is prohibited.
Instagram posts are also advertising – the strict limits of the law on advertising for medicinal products and treatments (Heilmittelwerberecht) apply to aesthetic procedures.
Social media advertising for healthcare services
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 170/24
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 11 Abs. 1 Satz 3 Nr. 1, § 1 Abs. 1 Nr. 2 Buchst. c HWG; UKlaG
- Action
- Order
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 31 Jul 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jul 2025 Tamro Eesti OÜTamro Eesti: order against unfair payment terms for food supplements Order
In consignment agreements, the pharmaceutical wholesaler had made payment to suppliers of food supplements dependent on subsequent resale (payment period over 30 days) and had reserved the right to hold suppliers liable for spoiled goods. The Konkurentsiamet (Estonian Competition Authority) found infringements of the act on unfair trading practices in the food supply chain and ordered amended contractual terms.
Purchasing terms in the food sector – including for food supplements – must comply with the 30-day payment period and the prohibition on shifting risk.
- Authority / court
- Konkurentsiamet (Estnische Wettbewerbsbehörde)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- § 4 Abs. 1 und 2, § 5 Abs. 2, § 7 Abs. 1 PTEKS (UTP-Richtlinie (EU) 2019/633)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Chemicals and pharmaceuticals
- Ettekirjutus Tamro Eesti OÜ-le ebaausate kaubandustavade kasutamise lõpetamiseks nr 11-4/2025-001, 25.07.2025 Decision of an authority
- Konkurentsiamet – Ausad kaubandustavad: juhtumid Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jul 2025 „Билла България“ ЕООД (Billa Bulgaria)Billa advertises oil containing 80% sunflower oil as olive oil – 405,936 leva €207,555
In June 2024, the retail chain advertised the product ‘Маслиново масло екстра върджин 20% – Basso Blend’ on its website, on radio, on television and online in such a way that olive oil was in the foreground, although the product consisted of 80% sunflower oil. The Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) opened proceedings of its own motion, considered the advertising misleading (Art. 32(1) in conjunction with Art. 33 ZZK – Bulgarian Protection of Competition Act) and imposed 0.032% of 2024 turnover, i.e. 405,936 leva.
Advertising must not highlight the share of a high-quality ingredient in a way that misleads customers about the composition – responsibility lies with the advertiser, not the agency.
Product advertising and labelling of composition
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 32 Abs. 1 i. V. m. Art. 33 ZZK
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
Original amount 405,936 BGN, converted at the ECB reference rate of 24 Jul 2025.
- КЗК Публичен електронен регистър – Производство (Решение № 691 от 24.07.2025; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Jul 2025 Slovenský pozemkový fondSlovak Land Fund: 6,000 EUR for late examination of a whistleblower report €6,000
The state land fund examined a report from September 2022 only after 128 days and, until November 2024, did not sufficiently inform employees about the reporting procedure, protection options and the responsible person. The Úrad na ochranu oznamovateľov (Slovak Whistleblower Protection Office) imposed 6,000 EUR.
Whistleblower reports are subject to statutory examination deadlines – anyone who misses them and does not publicise the procedure will be sanctioned.
Deadlines and transparency in the internal reporting system
- Authority / court
- Úrad na ochranu oznamovateľov (Slowakei)
- Area of law
- Whistleblower protection · Missing or inadequate reporting channel
- Legal basis
- § 10 Abs. 5 und 8, § 19 Gesetz Nr. 54/2019 über den Schutz von Hinweisgebern (UOO-277/2025)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Culpability
- negligent
- Rozhodnutie ÚOO z 24. 7. 2025, UOO-277/2025 (Slovenský pozemkový fond) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2025 ESTO ASData protection authority requires ESTO AS to stop creating accounts for non-customers Order
The instalment payment provider created customer profiles without a contract for persons who signed in via retailer checkouts, refused former customers the closure of their accounts and continued to send them transactional e-mails with advertising content. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered transparent information, valid consent, erasure options under Art. 17 GDPR and the separation of transactional and advertising e-mails; a penalty payment of 5,000 EUR is threatened for each item not fulfilled.
Customer accounts must not be created for non-customers ‘on the side’ – and erasure must work once the contract has ended.
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1, § 58 Abs. 1 IKS; Art. 58 Abs. 2 lit. d, Art. 4 Nr. 11, 5, 6, 7, 12–14, 17 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Ettekirjutus-hoiatus nr 2.1-1/24/1048-2575-22 (ESTO AS), 23.07.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jul 2025 Condor Courtiers & Conseillers S.à r.l.Condor Courtiers & Conseillers: licence withdrawn for using unlicensed introducers Other
Following an on-site inspection in 2024, the Commissariat aux Assurances (Luxembourg insurance supervisory authority, CAA) withdrew the broker’s licence (effective 15 September 2025): there was no effective management by approved managers, unlicensed ‘introducers’ were de facto selling insurance, and the broker’s licence, together with its sub-intermediary network, was improperly made available to third parties.
A distribution licence is not transferable – anyone who ‘rents it out’ to third parties or lets introducers sell risks having it withdrawn.
- Authority / court
- Commissariat aux Assurances (CAA)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Loi modifiée du 7 décembre 2015 sur le secteur des assurances, Art. 273, 274, 283, 286, 303
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 16 Sep 2025
- CAA – Sanction administrative CONDOR COURTIERS & CONSEILLERS S.à r.l. (16.09.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 Jul 2025 HEP-Toplinarstvo d.o.o.Croatia: 320,000 EUR against HEP-Toplinarstvo over plain-text passwords €320,000
The district heating company stored the passwords of almost 16,000 users of its customer portal ‘Moj račun’ in readable form and, when ‘forgot password’ was used, sent the old password by e-mail. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 320,000 EUR for lack of security measures and insufficient cooperation, as the company neither provided evidence of remediation nor disclosed all information (date = publication).
Never store passwords in plain text – and refusing to provide evidence to the supervisory authority increases the fine.
Secure password storage in software development
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 31, Art. 32 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Energy and utilities
- Published
- 22 Jul 2025
- Izrečene dvije upravne novčane kazne u iznosu od 370.000 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
10 Jul 2025 Poste Vita S.p.A.Poste Vita: 80,000 EUR – data breach notified only four months after customer’s alert €80,000
A fraudster impersonated a customer by e-mail and, between 2021 and 2023, obtained information and documents on three policies from the life insurer’s case handlers without his identity being verified. Although the customer alerted the company to the false e-mail address in September 2024, Poste Vita only notified the breach to the supervisory authority in January 2025.
Customer alerts about possible data leaks must go into the incident assessment immediately – not only after internal checks are completed.
Identity verification for customer requests by e-mail (social engineering)
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Art. 5 Abs. 1 lit. a und f, Art. 33 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Culpability
- negligent
- Mitigating circumstances
- Immediate blocking of further communication, internal investigation, criminal complaint and stricter identity verification.
- Garante privacy, Provvedimento del 10 luglio 2025 [10154110] Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link