Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Anonymised companies €5.17m 28 % · 10 cases
- IQVIA Operations France €5m 27 % · 1 case
- Australian Clinical Labs Limited €3.28m 18 % · 1 case
- 23andMe, Inc. €2.74m 15 % · 1 case
- IDCQ Hospitales y Sanidad, S.L.U. €1.2m 7 % · 1 case
- Hôpital Privé de la Loire €500,000 3 % · 1 case
- Health Service Executive (HSE) €300,000 2 % · 1 case
- Krankenhaus (anonymisiert) €50,000 0 % · 1 case
- Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios) €25,000 0 % · 1 case
- Azienda Sanitaria Universitaria Friuli Centrale (ASUFC) €24,000 0 % · 1 case
- 10 more€11,004
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €50,000 |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
17 Dec 2024 Krankenhaus (anonymisiert)Hospital after ransomware: fine cut by court from €200,000 to €50,000 €50,000
Following a ransomware attack in 2021 – the second after an attack in 2019 – the Litigation Chamber found that a Belgian hospital had, among other things, no data protection impact assessment, no effective information security policy, no adequate procedure for security updates of its software and no genuine training and awareness programme for staff. On 17 December 2024 it imposed a fine of 200,000 EUR, ordered remedial measures and rejected the argument that, as a public body, the hospital could not be fined. On 3 September 2025 the Market Court partially annulled the decision and reduced the fine to 50,000 EUR; the data protection authority has lodged an appeal in cassation against that judgment. The decision is not final. The amount and the facts have not been confirmed against the primary source.
A single phishing training session or the participation of a few employees in exercises does not replace regular data protection and security training for all hospital staff.
Security awareness and data protection training for all hospital staff
Missing or inadequate training played a role in the decision.
- Authority / court
- Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA) – Chambre Contentieuse
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5 Abs. 1 lit. f, Art. 24, Art. 32 und Art. 35 Abs. 3 DSGVO; Art. 58 Abs. 2 lit. d und i sowie Art. 83 DSGVO; Art. 100 § 1 9° und 13° sowie Art. 101 LCA
- Action
- Fine
- Status of proceedings
- reduced
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- The Chamber reduced the starting amount of 390,000 EUR to 200,000 EUR, mainly because of the hospital's financial difficulties, the Covid-19 crisis as a mitigating circumstance and a reassessed duration of the infringement.
Checked against the official source on 4 Oct 2026 · Direct link