Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

6cases from 6 jurisdictions
€3.47mTotal of monetary amounts (5 cases with an amount)
€2.74mLargest single case: 23andMe, Inc.
€190,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€190,000
Q4 20241€10,057
Q1 20250—
Q2 20251€2.74m
Q3 20250—
Q4 20250—
Q1 20261—
Q2 20260—
Q3 20262€525,000

6 cases

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Canada, BCData breaches and data security Other

Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.

What organisations can take from it

Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.

Relevance to training and awareness

Unauthorised viewing of patient records (snooping)

Authority / court
Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
Area of law
Data protection · Data breaches and data security
Legal basis
Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
Action
Other
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data United KingdomData breaches and data security €2.74m

From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.

What organisations can take from it

Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.

Authority / court
Information Commissioner's Office (ICO)
Area of law
Data protection · Data breaches and data security
Legal basis
UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
negligent
Published
17 Jun 2025

Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops DenmarkData breaches and data security €10,057

The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).

What organisations can take from it

Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.

Relevance to training and awareness

Encryption of mobile devices and phishing defence (multi-factor authentication)

Authority / court
Københavns Byret (auf Anzeige der Datatilsynet)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
Action
Fine
Status of proceedings
final
Sector
Healthcare
Repeat case
yes

Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup CroatiaData breaches and data security €190,000

In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.

What organisations can take from it

Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.

Relevance to training and awareness

Notification of data breaches within 72 hours

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
13 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial