Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by action- Fine €3.47m 100 % · 5 cases
- Other — 0 % · 1 case
Who?
by company- 23andMe, Inc. €2.74m 84 % · 1 case
- Hôpital Privé de la Loire €500,000 15 % · 1 case
- Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios) €25,000 1 % · 1 case
- Kræftens Bekæmpelse €10,057 0 % · 1 case
- Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal Health — 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 1 | €190,000 |
| Q4 2024 | 1 | €10,057 |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €2.74m |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 1 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 2 | €525,000 |
6 cases
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Other
Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.
Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.
Unauthorised viewing of patient records (snooping)
- Authority / court
- Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
- Action
- Other
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
- Published
- 18 Feb 2026
- Investigation reveals 71 snooping incidents by 36 healthcare workers following Lapu Lapu Day tragedy Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data €2.74m
From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.
Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- negligent
- Published
- 17 Jun 2025
Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.
- 23andMe fined for failing to protect UK users' genetic data Press release of an authority
- ICO Penalty Notice: 23andMe, Inc. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops €10,057
The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).
Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.
Encryption of mobile devices and phishing defence (multi-factor authentication)
- Authority / court
- Københavns Byret (auf Anzeige der Datatilsynet)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Repeat case
- yes
Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.
- Datatilsynet – Kræftens Bekæmpelse indstillet til bøde (Opdatering zum Verfahrensausgang) Press release of an authority
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 Court decision
- Domsdatabasen – Københavns Byret SS-7513/2023-KBH, Dom 01.10.2024 (Status: Endelig) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup €190,000
In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.
Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.
Notification of data breaches within 72 hours
- Authority / court
- Agencija za zaštitu osobnih podataka (AZOP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 13 Sep 2024
- Izdane nove upravne novčane kazne u ukupnom iznosu od 270.700 eura Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link