Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,838 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
€3.28mTotal of monetary amounts (1 case with an amount)
€3.28mLargest single case: Australian Clinical Labs Limited
€3.28mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Office of the Australian Information Commissioner (OAIC) €3.28m 100 % · 4 cases

What for?

by action
  1. Fine €3.28m 100 % · 1 case
  2. Order – 0 % · 2 cases
  3. Other – 0 % · 1 case

Who?

by sector

All sectors

  1. Healthcare €3.28m 100 % · 1 case
  2. Retail and e-commerce – 0 % · 1 case
  3. Media and online platforms – 0 % · 1 case
  4. Telecoms, IT and software – 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20241–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20252€3.28m
Q1 20261–
Q2 20260–
Q3 20260–
Q4 20260–

4 cases

20 Mar 2026 Singtel Optus Pty LtdOptus: unlisted numbers of 41,278 customers published in the phone directory AustraliaData breaches and data security Order

Singtel Optus asked customers who ported their number to Optus whether they wanted to appear in the phone directory, but between October 2015 and September 2019 it did not act on requests for an unlisted number, so that 41,278 affected customers remained published in the White Pages. The Privacy Commissioner found a breach of APP 11.1 because Optus did not remove a risk of errors it had been aware of throughout the period with reasonable steps such as regular system reconciliations, and declared that the company must not repeat this conduct. The regulator intends to decide on compensation separately in a representative complaint concerning the same conduct.

What organisations can take from it

Known sources of error in legacy systems and in disclosures to third parties must be eliminated through regular reconciliations rather than tolerated for years.

Relevance to training and awareness

Reliably implementing customers' privacy choices across systems and service providers

Authority / court
Office of the Australian Information Commissioner (OAIC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act 1988 (Cth) s 13(1), APP 11.1; Erklärung nach s 52(1A)(a)
Action
Order
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
11 Jun 2026

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

17 Oct 2025 Vinomofo Pty LtdVinomofo: privacy breach after unauthorised data access during a data migration AustraliaData breaches and data security Order

In 2022, during a large data migration project, the online wine retailer suffered unauthorised access to a database holding data on around 928,760 customers and members (identity, contact and financial information). The Privacy Commissioner found that Vinomofo had not taken reasonable steps to protect the data, although it had been aware of deficiencies in its security governance at least two years before the incident, and ordered it not to repeat these practices, together with specified remedial steps.

What organisations can take from it

Data migrations to the cloud need their own security concept, and known weaknesses in security governance must not be put off.

Relevance to training and awareness

Data security in migration projects and cloud services; privacy culture and training

Missing or inadequate training played a role in the decision.

Authority / court
Office of the Australian Information Commissioner (OAIC)
Area of law
Data protection · Data breaches and data security
Legal basis
APP 11.1 (Privacy Act 1988 (Cth))
Action
Order
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
29 Oct 2025

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 Oct 2025 Australian Clinical Labs LimitedAustralian Clinical Labs: 5.8 million AUD civil penalty after Medlab Pathology data breach AustraliaData breaches and data security €3.28m

On the application of the Australian Information Commissioner, the Federal Court of Australia imposed the first civil penalties under the Privacy Act 1988: Australian Clinical Labs (ACL) had failed to adequately protect the personal information held on the IT systems of its Medlab Pathology business; in a cyberattack in February 2022, data of more than 223,000 people was taken from those systems. The penalty of 5.8 million AUD in total comprises 4.2 million AUD for the inadequate security measures (APP 11.1), 800,000 AUD because ACL did not assess reasonably and promptly whether a notifiable data breach had occurred, and 800,000 AUD for the late notification to the Commissioner. ACL admitted the contraventions; liability and the penalty were allegedly based on joint submissions by the parties.

What organisations can take from it

When a business unit's IT systems are integrated into an organisation's own environment, they must be adequately protected from the outset, and attacks must be promptly assessed for a notification duty.

Relevance to training and awareness

Securing integrated IT systems, assessing and notifying data breaches promptly

Authority / court
Office of the Australian Information Commissioner (OAIC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act 1988 (Cth) s 13G(a) i. V. m. APP 11.1; s 26WH(2); s 26WK(2)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Culpability
negligent
Mitigating circumstances
Cooperation with the investigation, an ongoing programme to uplift cyber security, apologies and admission of liability.
Liability of senior managers
The court found that the most senior management was involved in the decisions on integrating the Medlab systems and on assessing the attack.
Published
9 Oct 2025

Original amount 5,800,000 AUD, converted at the ECB reference rate of 8 Oct 2025.

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

17 Dec 2024 Meta Platforms, Inc.Meta: 50 million AUD payment programme for Australians affected by Cambridge Analytica AustraliaData breaches and data security Other

To end the civil penalty proceedings pending before the Federal Court since March 2020, the Australian Information Commissioner accepted an enforceable undertaking from Meta Platforms under which Meta sets up a payment programme of 50 million AUD for Australian Facebook users whose data may have been disclosed to the app “This is Your Digital Life”. The regulator said Meta had allegedly committed serious or repeated breaches of APP 6.1 and 11.1; the undertaking was given without any admission of liability, and the proceedings were withdrawn. Unused funds go to the Commonwealth budget; Meta also contributed to the regulator's legal costs.

What organisations can take from it

Platforms must control which data third-party apps can access about users and their contacts.

Relevance to training and awareness

Controlling third-party app access to data through interfaces

Authority / court
Office of the Australian Information Commissioner (OAIC)
Area of law
Data protection · Data breaches and data security
Legal basis
Regulatory Powers (Standard Provisions) Act 2014 (Cth) s 114; Vorwurf: Privacy Act 1988 (Cth) s 13G i. V. m. APP 6.1 und 11.1
Action
Other
Status of proceedings
final
Sector
Media and online platforms
Employees
10,000 or more
Mitigating circumstances
According to the undertaking, Meta no longer allows third-party apps to access data of Facebook friends who have not installed and authorised the app themselves, has reduced the data fields available, introduced more granular permissions and regularly checks app developers.
Published
17 Dec 2024

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial