Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 3 jurisdictions
€21,274Total of monetary amounts (2 cases with an amount)
€10,637Median per case with an amount

Click a bar to drill down one level.

Where?

by region

All jurisdictions

  1. EU €21,274 100 % · 3 cases

What for?

by action
  1. Fine €21,274 100 % · 2 cases
  2. Order — 0 % · 1 case

Who?

by company
  1. Gesundheitsdienstleister (in der Entscheidung anonymisiert) €1,274 100 % · 1 case
  2. Nura OÜ — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20251€20,000
Q3 20250—
Q4 20251—
Q1 20261€1,274
Q2 20260—
Q3 20260—

3 cases

20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis HungaryData subject rights and transparency €1,274

A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.

What organisations can take from it

Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.

Relevance to training and awareness

Access to health data and access requests

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
20 Mar 2026

Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients EstoniaData subject rights and transparency Order

Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.

What organisations can take from it

Access requests concerning health data require a fixed procedure with deadlines – in small practices too.

Relevance to training and awareness

Handling access requests from patients

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO MaltaData subject rights and transparency €20,000

Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.

What organisations can take from it

Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.

Relevance to training and awareness

Implementing rectification requests promptly

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial