Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America and Asia-Pacific: 1,846 cases from 39 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Anonymised companies €5.17m 28 % · 10 cases
- IQVIA Operations France €5m 27 % · 1 case
- Australian Clinical Labs Limited €3.28m 18 % · 1 case
- 23andMe, Inc. €2.74m 15 % · 1 case
- IDCQ Hospitales y Sanidad, S.L.U. €1.2m 7 % · 1 case
- Hôpital Privé de la Loire €500,000 3 % · 1 case
- Health Service Executive (HSE) €300,000 2 % · 1 case
- Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios) €25,000 0 % · 1 case
- Azienda Sanitaria Universitaria Friuli Centrale (ASUFC) €24,000 0 % · 1 case
- Specer sp. z o.o. €2,669 0 % · 1 case
- 8 more€3,273
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €300,000 |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Jun 2026 Health Service Executive (HSE)DPC: €300,000 fine against HSE after ransomware attack on hospital laboratory in Tullamore €300,000
In November 2018 attackers encrypted patient data in the laboratory information system of Midlands Regional Hospital Tullamore. The DPC found that the HSE had infringed Art. 5(1)(f), 28, 30, 32(1) and 34 GDPR (including insufficient security, deficient processor contracts and record of processing, and incomplete notification of affected persons), issued a reprimand, imposed €300,000 for the security failings (Art. 5(1)(f) and 32(1)) and ordered it to introduce specified policies and procedures for secure processing.
Laboratory and other specialist hospital systems also belong in security and supplier management; contracts with processors must contain the GDPR safeguards.
Ransomware protection of clinical systems
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5(1)(f), 28, 30, 32(1), 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- DPC: Inquiry into Midlands Regional Hospital Tullamore (IN-19-9-4) Decision of an authority
Checked against the official source on 2 Oct 2026 · Direct link