Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

16cases from 15 jurisdictions
€3.53mTotal of monetary amounts (12 cases with an amount)
€2.74mLargest single case: 23andMe, Inc.
€15,029Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20242€192,000
Q4 20242€15,057
Q1 20250—
Q2 20253€2.76m
Q3 20251€2,669
Q4 20251—
Q1 20263€3,273
Q2 20261—
Q3 20263€549,000

16 cases

5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data United KingdomData breaches and data security €2.74m

From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.

What organisations can take from it

Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
negligent
Published
17 Jun 2025

Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record ItalyEmployee data €24,000

Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).

What organisations can take from it

Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.

Relevance to training and awareness

Purpose limitation when accessing patient records

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment EstoniaData processors Order

The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.

What organisations can take from it

Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.

Relevance to training and awareness

Consent and transparency for health data; cooperation with the supervisory authority

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data processors
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis HungaryData subject rights and transparency €1,274

A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.

What organisations can take from it

Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.

Relevance to training and awareness

Access to health data and access requests

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
20 Mar 2026

Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR RomaniaData protection €1,999

The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.

What organisations can take from it

Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.

Relevance to training and awareness

Taking patient data when leaving; cooperation with the supervisory authority

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
20 Feb 2026

Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Canada, BCData breaches and data security Other

Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.

What organisations can take from it

Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.

Relevance to training and awareness

Unauthorised viewing of patient records (snooping)

Authority / court
Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
Area of law
Data protection · Data breaches and data security
Legal basis
Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
Action
Other
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients EstoniaData subject rights and transparency Order

Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.

What organisations can take from it

Access requests concerning health data require a fixed procedure with deadlines – in small practices too.

Relevance to training and awareness

Handling access requests from patients

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN PolandData protection €2,669

For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.

What organisations can take from it

This also applies in small practices and companies: management cannot be its own data protection officer.

Relevance to training and awareness

Role and independence of the data protection officer; release of patient records

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
An independent external data protection officer was appointed in July 2024.
Published
29 Sep 2025

Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine FinlandCookies and tracking overturned

In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).

What organisations can take from it

Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.

Relevance to training and awareness

Tracking pixels on sensitive websites

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
Area of law
Data protection · Cookies and tracking
Legal basis
DSGVO Art. 9, Art. 25, Art. 32
Action
Fine
Status of proceedings
overturned
Sector
Healthcare
Published
4 Jun 2025

Amount in EUR; no ECB reference rate is available for this currency.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO MaltaData subject rights and transparency €20,000

Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.

What organisations can take from it

Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.

Relevance to training and awareness

Implementing rectification requests promptly

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer AustriaData protection €5,000

A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.

What organisations can take from it

Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection
Legal basis
Art. 37, Art. 38 Abs. 6 DSGVO
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
50 to 249
Liability of senior managers
The managing director was also appointed as data protection officer – an impermissible conflict of interest.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops DenmarkData breaches and data security €10,057

The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).

What organisations can take from it

Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.

Relevance to training and awareness

Encryption of mobile devices and phishing defence (multi-factor authentication)

Authority / court
Københavns Byret (auf Anzeige der Datatilsynet)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
Action
Fine
Status of proceedings
final
Sector
Healthcare
Repeat case
yes

Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Sep 2024 VSIA "Paula Stradiņa klīniskā universitātes slimnīca"Pauls Stradiņš Clinical University Hospital refuses information to data protection authority – 2,000 EUR LatviaData protection €2,000

The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined several complaints against the state hospital, including about the processing of patient and health data by a physician assistant and about an unanswered access request. Because the hospital did not provide the requested information, the authority imposed 2,000 EUR for breach of the duty to cooperate.

What organisations can take from it

Hospitals need logged access to patient records and a central office that responds to supervisory requests on time.

Relevance to training and awareness

Access to patient data only where related to treatment

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup CroatiaData breaches and data security €190,000

In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.

What organisations can take from it

Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.

Relevance to training and awareness

Notification of data breaches within 72 hours

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
13 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial