Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
—Total of monetary amounts (0 cases with an amount)
—Largest single case
—Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20251—
Q4 20250—
Q1 20262—
Q2 20261—
Q3 20260—

4 cases

7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers CanadaData breaches and data security Other

Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.

What organisations can take from it

Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act (Kanada)
Action
Other
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
7 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2026 Loblaw Companies LimitedOPC: Loblaw must change retention of PC Optimum data after account deletion CanadaData subject rights and transparency Other

During a wave of boycotts in 2024, Loblaw did not process deletion requests in time and retained purchase and usage data from the loyalty programme (more than 17 million members) even after accounts were closed, without demonstrating effective anonymisation. Loblaw undertook to the Office of the Privacy Commissioner of Canada (OPC) to have the anonymisation independently reviewed and to carry out annual deletions.

What organisations can take from it

Companies that continue to use data as anonymous after account deletion must be able to demonstrate the re-identification risk – IP addresses are often enough to link data to a person.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
PIPEDA
Action
Other
Status of proceedings
unknown
Sector
Retail and e-commerce
Employees
10,000 or more
Published
5 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Canada, BCData breaches and data security Other

Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.

What organisations can take from it

Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.

Relevance to training and awareness

Unauthorised viewing of patient records (snooping)

Authority / court
Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
Area of law
Data protection · Data breaches and data security
Legal basis
Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
Action
Other
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Sep 2025 TikTok Pte. Ltd.Canadian regulators: TikTok inadequately protected children's data CanadaMarketing and consent Other

The joint investigation by the Office of the Privacy Commissioner of Canada and the supervisory authorities of Québec, British Columbia and Alberta found that every year hundreds of thousands of children used the platform despite the minimum age of 13, and that TikTok processed data without valid consent, including for profiling and advertising. TikTok undertook to improve age verification and make privacy notices easier to understand, and already during the investigation largely stopped targeted advertising to under-18s (except by broad categories such as language and approximate location).

What organisations can take from it

Age limits in the terms of use are not enough – platforms need effective age verification and child-appropriate transparency.

Authority / court
Office of the Privacy Commissioner of Canada gemeinsam mit den Aufsichten von Québec, British Columbia und Alberta
Area of law
Data protection · Marketing and consent
Legal basis
PIPEDA und Datenschutzgesetze für den Privatsektor von Québec, British Columbia und Alberta
Action
Other
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
23 Sep 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial