Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €25,000 100 % · 2 cases
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €1,000 |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 1 | €24,000 |
2 cases
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Aug 2025 Fachärztliche Ordination (Kardiologie, anonymisiert)Cardiologist pays 1,000 EUR for unauthorised ELGA access to a former employee's data €1,000
On 1 August 2024, a doctor accessed e-prescriptions and medication data of a former employee twelve times in the ELGA electronic health record without any treatment relationship. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 1,000 EUR (plus 100 EUR in costs); confession and a clean record were mitigating factors.
Access to health records is only permitted where there is a treatment relationship – and it is logged.
Access to health data only where there is a treatment relationship
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 1, Art. 9 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- No previous record, negligence, full cooperation and confession.
- Datenschutzbehörde, Straferkenntnis 2025-0.625.944 vom 21.08.2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link