Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- 23andMe, Inc. 1 case 7 % · €2.74m
- Azienda Sanitaria Universitaria Friuli Centrale (ASUFC) 1 case 7 % · €24,000
- Fachärztliche Ordination (Kardiologie, anonymisiert) 1 case 7 % · €1,000
- Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal Health 1 case 7 % ·
- Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi) 1 case 7 % ·
- Gesundheitsdienstleister (in der Entscheidung anonymisiert) 1 case 7 % · €1,274
- Hôpital Privé de la Loire 1 case 7 % · €500,000
- Kræftens Bekæmpelse 1 case 7 % · €10,057
- Nura OÜ 1 case 7 % ·
- SC Hayat Dent SRL 1 case 7 % · €1,999
- 4 more4 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 2 | €192,000 |
| Q4 2024 | 2 | €15,057 |
| Q1 2025 | 0 | — |
| Q2 2025 | 3 | €2.76m |
| Q3 2025 | 2 | €3,669 |
| Q4 2025 | 1 | — |
| Q1 2026 | 3 | €3,273 |
| Q2 2026 | 1 | — |
| Q3 2026 | 3 | €549,000 |
17 cases
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment Order
The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.
Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.
Consent and transparency for health data; cooperation with the supervisory authority
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data processors
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus isikuandmete kaitse asjas nr 2.1-1/24/397-890-38 (Fullgevity OÜ), 16.04.2026 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR €1,999
The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.
Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.
Taking patient data when leaving; cooperation with the supervisory authority
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 20 Feb 2026
Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.
- ANSPDCP – Comunicat de presă 20.02.2026 (SC Hayat Dent SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Other
Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.
Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.
Unauthorised viewing of patient records (snooping)
- Authority / court
- Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
- Published
- 18 Feb 2026
- Investigation reveals 71 snooping incidents by 36 healthcare workers following Lapu Lapu Day tragedy Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN €2,669
For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.
This also applies in small practices and companies: management cannot be its own data protection officer.
Role and independence of the data protection officer; release of patient records
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- An independent external data protection officer was appointed in July 2024.
- Published
- 29 Sep 2025
Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.
- Prezes firmy nie może być jednocześnie IOD. Kara dla spółki Specer Press release of an authority
- Decyzja DKN.5131.7.2025 z 12 września 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Aug 2025 Fachärztliche Ordination (Kardiologie, anonymisiert)Cardiologist pays 1,000 EUR for unauthorised ELGA access to a former employee's data €1,000
On 1 August 2024, a doctor accessed e-prescriptions and medication data of a former employee twelve times in the ELGA electronic health record without any treatment relationship. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 1,000 EUR (plus 100 EUR in costs); confession and a clean record were mitigating factors.
Access to health records is only permitted where there is a treatment relationship – and it is logged.
Access to health data only where there is a treatment relationship
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 1, Art. 9 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- No previous record, negligence, full cooperation and confession.
- Datenschutzbehörde, Straferkenntnis 2025-0.625.944 vom 21.08.2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data €2.74m
From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.
Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- negligent
- Published
- 17 Jun 2025
Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.
- 23andMe fined for failing to protect UK users' genetic data Press release of an authority
- ICO Penalty Notice: 23andMe, Inc. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine overturned
In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).
Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.
Tracking pixels on sensitive websites
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- DSGVO Art. 9, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Healthcare
- Published
- 4 Jun 2025
Amount in EUR; no ECB reference rate is available for this currency.
- Finlex – Tietosuojavaltuutettu 27.5.2025 (verkkoapteekin seurantateknologiat) Decision of an authority
- Tietosuojavaltuutettu – Hallinto-oikeudelta päätös Yliopiston Apteekille määrätystä seuraamusmaksusta (2.6.2026) Press release of an authority
- Helsingin hallinto-oikeus – kumosi Yliopiston Apteekille määrätyn 1,1 miljoonan euron seuraamusmaksun (01.06.2026) Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO €20,000
Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.
Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.
Implementing rectification requests promptly
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- IDPC Decision CDP/COMP/282/2024 Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer €5,000
A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.
Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection
- Legal basis
- Art. 37, Art. 38 Abs. 6 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 50 to 249
- Liability of senior managers
- The managing director was also appointed as data protection officer – an impermissible conflict of interest.
- DSB Straferkenntnis GZ 2024-0.641.771 vom 16.10.2024 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops €10,057
The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).
Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.
Encryption of mobile devices and phishing defence (multi-factor authentication)
- Authority / court
- Københavns Byret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Repeat case
- yes
Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.
- Datatilsynet – Kræftens Bekæmpelse indstillet til bøde (Opdatering zum Verfahrensausgang) Press release of an authority
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 Court decision
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 (Status: Endelig) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Sep 2024 VSIA "Paula Stradiņa klīniskā universitātes slimnīca"Pauls Stradiņš Clinical University Hospital refuses information to data protection authority – 2,000 EUR €2,000
The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined several complaints against the state hospital, including about the processing of patient and health data by a physician assistant and about an unanswered access request. Because the hospital did not provide the requested information, the authority imposed 2,000 EUR for breach of the duty to cooperate.
Hospitals need logged access to patient records and a central office that responds to supervisory requests on time.
Access to patient data only where related to treatment
- Authority / court
- Datu valsts inspekcija (DVI)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- DVI Lēmums Par soda piemērošanu (Paula Stradiņa klīniskā universitātes slimnīca), 18.09.2024 Decision of an authority
- Datu valsts inspekcija – Lēmumi (Liste der veröffentlichten Entscheidungen) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup €190,000
In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.
Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.
Notification of data breaches within 72 hours
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 13 Sep 2024
- Izdane nove upravne novčane kazne u ukupnom iznosu od 270.700 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link