Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
—Total of monetary amounts (0 cases with an amount)
—Largest single case
—Median per case with an amount

Click a bar to drill down one level.

Where?

by level
  1. Federal level — 0 % · 1 case
  2. Provinces — 0 % · 1 case

What for?

by action
  1. Other — 0 % · 2 cases

Who?

by sector

All sectors

  1. Healthcare — 0 % · 1 case
  2. Public sector — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20261—
Q2 20261—
Q3 20260—

2 cases

7 May 2026 Canada Revenue Agency (CRA)Privacy Commissioner: Canada's tax authority CRA must strengthen protection against account takeovers CanadaData breaches and data security Other

Since 2020, the Canada Revenue Agency (CRA) has experienced more than 42,000 individual breaches in which unauthorised persons accessed tax accounts or changed data in order to redirect benefits. In a special report to Parliament, the Privacy Commissioner of Canada criticised, among other things, the delayed introduction of mandatory MFA and incomplete incident recording, and made nine recommendations, eight of which were accepted in full and one in part.

What organisations can take from it

Online accounts with payment functions need mandatory strong authentication and complete recording of incidents.

Authority / court
Office of the Privacy Commissioner of Canada (OPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act (Kanada)
Action
Other
Status of proceedings
unknown
Sector
Public sector
Employees
10,000 or more
Published
7 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Feb 2026 Fraser Health Authority, Provincial Health Services Authority, Vancouver Coastal HealthBritish Columbia: 36 hospital staff accessed records of Lapu-Lapu Day victims without authorisation Canada, BCData breaches and data security Other

Following the tragedy at the Lapu-Lapu Day festival in 2025, 36 employees of three health authorities accessed patient data of 16 admitted persons without authorisation in 71 instances. Those affected were not informed without undue delay; the Information and Privacy Commissioner for British Columbia (OIPC BC) made nine recommendations, including automated access monitoring and deterrent disciplinary measures.

What organisations can take from it

Curiosity is no reason for access: monitor access to the records of high-profile cases in real time and sanction breaches noticeably.

Relevance to training and awareness

Unauthorised viewing of patient records (snooping)

Authority / court
Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
Area of law
Data protection · Data breaches and data security
Legal basis
Freedom of Information and Protection of Privacy Act (FIPPA) BC, s. 25.1
Action
Other
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Appropriate safeguards were in place; the authorities responded quickly and accepted all recommendations.
Published
18 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial