Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,828 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Office of the Australian Information Commissioner (OAIC) €3.28m 100 % · 7 cases
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | – |
| Q4 2025 | 2 | €3.28m |
| Q1 2026 | 1 | – |
| Q2 2026 | 2 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
7 cases
11 Jun 2026 Monash IVF Pty LtdMonash IVF: tracking pixels on fertility website used without consent Order
Monash IVF collected sensitive information about visitors to its fertility treatment website through third-party tracking pixels. The Privacy Commissioner held that following the visitors of health-related websites and afterwards showing them targeted adverts on social networks amounts to collecting sensitive data, which requires consent, and found breaches of APP 3.3, 5.1, 5.2 and 7.1. Monash IVF must not continue or repeat the conduct and must implement specified remedial steps; a parallel determination against the telehealth provider Medmate Australia was made on the same day.
Anyone using tracking pixels on health websites needs visitors' consent and must know which data flows to advertising platforms.
Tracking pixels and advertising tools on websites with sensitive content
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Privacy Act 1988 (Cth), APP 3.3, 5.1, 5.2, 7.1
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 24 Jun 2026
- OAIC: Privacy Commissioner finds privacy breaches in third-party tracking pixel investigation (24.06.2026) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026) Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
1 Apr 2026 IRE Pty Ltd (InspectRealEstate, Plattform 2Apply)2Apply operator IRE: order over excessive and unfair collection of renters’ data Order
The Privacy Commissioner found that the rental application platform 2Apply collected more personal information than necessary from March 2020 to March 2025, such as gender, student status, citizenship, visa expiry and previous living arrangements, and did so unfairly through design techniques such as “confirmshaming”, biased framing and bundled consent. The determination requires IRE to stop this collection within 60 days, engage an independent reviewer and report to the OAIC within twelve months on implementing the recommendations.
Online forms may only request necessary data and must not push users into disclosure through design tricks.
Data minimisation and fair design of online forms (dark patterns)
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- APP 3.2 und APP 3.5 (Privacy Act 1988 (Cth)); Feststellungen nach s 52(1A)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Mitigating circumstances
- IRE adapted its collection practices during the investigation without admitting a breach.
- Published
- 22 Apr 2026
- OAIC: RentTech platforms must stop unfair and excessive personal information collection, says Privacy Commissioner (22 April 2026) Press release of an authority
- Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026) Decision of an authority
- OAIC: Privacy determinations Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
20 Mar 2026 Singtel Optus Pty LtdOptus: unlisted numbers of 41,278 customers published in the phone directory Order
Singtel Optus asked customers who ported their number to Optus whether they wanted to appear in the phone directory, but between October 2015 and September 2019 it did not act on requests for an unlisted number, so that 41,278 affected customers remained published in the White Pages. The Privacy Commissioner found a breach of APP 11.1 because Optus did not remove a risk of errors it had been aware of throughout the period with reasonable steps such as regular system reconciliations, and declared that the company must not repeat this conduct. The regulator intends to decide on compensation separately in a representative complaint concerning the same conduct.
Known sources of error in legacy systems and in disclosures to third parties must be eliminated through regular reconciliations rather than tolerated for years.
Reliably implementing customers' privacy choices across systems and service providers
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Privacy Act 1988 (Cth) s 13(1), APP 11.1; Erklärung nach s 52(1A)(a)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 11 Jun 2026
- Commissioner Initiated Investigation into Singtel Optus Pty Ltd (Privacy) [2026] AICmr 22 (20 March 2026) Decision of an authority
- OAIC: Privacy Commissioner finds against Optus in White Pages breach (11.06.2026) Press release of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
17 Oct 2025 Vinomofo Pty LtdVinomofo: privacy breach after unauthorised data access during a data migration Order
In 2022, during a large data migration project, the online wine retailer suffered unauthorised access to a database holding data on around 928,760 customers and members (identity, contact and financial information). The Privacy Commissioner found that Vinomofo had not taken reasonable steps to protect the data, although it had been aware of deficiencies in its security governance at least two years before the incident, and ordered it not to repeat these practices, together with specified remedial steps.
Data migrations to the cloud need their own security concept, and known weaknesses in security governance must not be put off.
Data security in migration projects and cloud services; privacy culture and training
Missing or inadequate training played a role in the decision.
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- APP 11.1 (Privacy Act 1988 (Cth))
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 29 Oct 2025
- OAIC: Vinomofo did not protect personal information from security risks, Privacy Commissioner finds (29 October 2025) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025) Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
8 Oct 2025 Australian Clinical Labs LimitedAustralian Clinical Labs: 5.8 million AUD civil penalty after Medlab Pathology data breach €3.28m
On the application of the Australian Information Commissioner, the Federal Court of Australia imposed the first civil penalties under the Privacy Act 1988: Australian Clinical Labs (ACL) had failed to adequately protect the personal information held on the IT systems of its Medlab Pathology business; in a cyberattack in February 2022, data of more than 223,000 people was taken from those systems. The penalty of 5.8 million AUD in total comprises 4.2 million AUD for the inadequate security measures (APP 11.1), 800,000 AUD because ACL did not assess reasonably and promptly whether a notifiable data breach had occurred, and 800,000 AUD for the late notification to the Commissioner. ACL admitted the contraventions; liability and the penalty were allegedly based on joint submissions by the parties.
When a business unit's IT systems are integrated into an organisation's own environment, they must be adequately protected from the outset, and attacks must be promptly assessed for a notification duty.
Securing integrated IT systems, assessing and notifying data breaches promptly
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Privacy Act 1988 (Cth) s 13G(a) i. V. m. APP 11.1; s 26WH(2); s 26WK(2)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- Cooperation with the investigation, an ongoing programme to uplift cyber security, apologies and admission of liability.
- Liability of senior managers
- The court found that the most senior management was involved in the decisions on integrating the Medlab systems and on assessing the attack.
- Published
- 9 Oct 2025
Original amount 5,800,000 AUD, converted at the ECB reference rate of 8 Oct 2025.
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
26 Aug 2025 Kmart Australia LimitedKmart: facial recognition used against refund fraud breached the Privacy Act Order
From June 2020 to July 2022, Kmart Australia used facial recognition in 28 stores to record the face of every person who came in and of every customer at the returns counters, with the aim of uncovering refund fraud, without informing them or obtaining their consent. The Privacy Commissioner rejected the exception for addressing unlawful activity, because the indiscriminate collection of sensitive biometric information was disproportionate given less intrusive alternatives and its limited benefit, and ordered that the conduct must not be continued or repeated. The decision is currently under review before the Administrative Review Tribunal; hearings are scheduled for early 2027. The decision is not final.
Before deploying facial recognition, organisations must assess and document whether less intrusive means would suffice and whether the intrusion into the privacy of everyone captured is proportionate.
Facial recognition in retail: proportionality, notice and consent
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Privacy Act 1988 (Cth), APP 1.3, 1.4, 3.3, 3.4, 5.1, 5.2
- Action
- Order
- Status of proceedings
- under appeal
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Kmart stopped using the system in July 2022 when the investigation began and cooperated with the regulator throughout.
- Published
- 18 Sep 2025
- OAIC: Kmart’s use of facial recognition to tackle refund fraud unlawful, Privacy Commissioner finds (18.09.2025) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Kmart Australia Limited (Privacy) [2025] AICmr 155 (26 August 2025) Enforcement database of an authority
- OAIC: Privacy Commissioner publishes updated guidance on facial recognition in retail spaces (29.07.2026) Press release of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
17 Dec 2024 Meta Platforms, Inc.Meta: 50 million AUD payment programme for Australians affected by Cambridge Analytica Other
To end the civil penalty proceedings pending before the Federal Court since March 2020, the Australian Information Commissioner accepted an enforceable undertaking from Meta Platforms under which Meta sets up a payment programme of 50 million AUD for Australian Facebook users whose data may have been disclosed to the app “This is Your Digital Life”. The regulator said Meta had allegedly committed serious or repeated breaches of APP 6.1 and 11.1; the undertaking was given without any admission of liability, and the proceedings were withdrawn. Unused funds go to the Commonwealth budget; Meta also contributed to the regulator's legal costs.
Platforms must control which data third-party apps can access about users and their contacts.
Controlling third-party app access to data through interfaces
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Regulatory Powers (Standard Provisions) Act 2014 (Cth) s 114; Vorwurf: Privacy Act 1988 (Cth) s 13G i. V. m. APP 6.1 und 11.1
- Action
- Other
- Status of proceedings
- final
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Mitigating circumstances
- According to the undertaking, Meta no longer allows third-party apps to access data of Facebook friends who have not installed and authorised the app themselves, has reduced the data fields available, introduced more granular permissions and regularly checks app developers.
- Published
- 17 Dec 2024
- OAIC: Landmark settlement of $50m from Meta for Australian users impacted by Cambridge Analytica incident (17.12.2024) Press release of an authority
- OAIC: Meta Platforms, Inc.: enforceable undertaking (17 December 2024) Official register or notice
Checked against the official source on 3 Oct 2026 · Direct link