Clear proof.
Sourced compliance.
Independent research on EU regulation. Profiles of regulators, fine registries, ruling analysis — every claim cited to a primary source.
Living research.
Who is Tietosuojavaltuutettu: Finland's Data Protection Ombudsman
Tietosuojavaltuutetun toimisto is Finland's GDPR supervisory authority — one of the oldest in Europe (1987). What it does, how the collegial Sanctions Board works, why its head also chairs the EU's data-protection board (EDPB), and the €2.4M Posti fine that the Helsinki Administrative Court later annulled.
Regulator · GDPR · FranceWho is the CNIL: France's data protection authority, created decades before the GDPR
The CNIL is France's GDPR supervisory authority — born from the 1974 SAFARI scandal and created by the 1978 Loi Informatique et Libertés, decades before the GDPR. This guide covers what it does, its 18-member college and sanctions chamber, the landmark fines from Google's first €50M to a record €325M, who runs it, and its 2024 figures — every fact sourced.
Regulator · GDPR · PolandWho is the UODO: Poland's data regulator and one of the EU's busiest enforcers
The UODO is Poland's GDPR supervisory authority — the Personal Data Protection Office created in 2018 to replace the old GIODO inspectorate, and one of the most active fining regulators in the EU. What it does, who leads it after the 2024 change at the top, and the security-failure cases (Morele.net, Virgin Mobile) that define its enforcement. Every fact sourced.
Regulator · GDPR · LuxembourgWho is the CNPD: Luxembourg's data regulator behind the €746M Amazon fine
The CNPD is Luxembourg's GDPR supervisory authority — a small national regulator that issued the second-largest GDPR fine in history, €746 million against Amazon, because so many global companies base their EU operations in the Grand Duchy. What it is, how its collège is composed after the 2025 change, and why a tiny country's regulator carries outsized weight. Every fact sourced.
Regulator · GDPR · SwedenWho is the IMY: Sweden's data protection authority, heir to the world's first privacy law
IMY (Integritetsskyddsmyndigheten) is Sweden's GDPR supervisory authority — the modern name of Datainspektionen, founded in 1973 to enforce what is widely regarded as the world's first national data protection law. This guide covers what it does, the mandate that runs beyond the GDPR, who runs it after the 2024 leadership change, and the Google, Spotify and Klarna fines — every fact sourced.
Regulator · GDPR · RomaniaWho is the ANSPDCP: Romania's data regulator that fines often but small
The ANSPDCP is Romania's GDPR supervisory authority — one of the top three EU countries by number of fines, yet with some of the smallest amounts. What it is, who leads it, and the security-breach cases (Raiffeisen, UniCredit, and the famous hotel breakfast-list fine) that define a high-volume, low-value enforcement style. Every fact sourced.
EU regulation, broken down.
AI Act
Risk classification, prohibited practices, conformity assessment, sandbox programs, national AI authorities.
Open pillar → EU 2016/679GDPR
Data Protection Authorities by country, fine registries, court rulings, cookie & tracking enforcement.
Open pillar → EU 2023/1114MiCA
CASP licensing by member state, stablecoin rules, market abuse, registers of authorized issuers.
Open pillar → EU 2022/2554DORA
ICT risk frameworks, incident reporting, threat-led penetration testing, third-party oversight.
Open pillar →Every fact has a source.
No reconstruction from memory, no marketing fluff. Each claim — a fine amount, a fine date, the name of an official, the text of an article — links to a primary document: regulator publications, official journals, court decisions, EUR-Lex.