Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€50,000Total of monetary amounts
€50,000Largest single case: Krankenhaus (anonymisiert)
€50,000Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20241€50,000
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

17 Dec 2024 Krankenhaus (anonymisiert)Hospital after ransomware: fine cut by court from €200,000 to €50,000 BelgiumData breaches and data security €50,000

Following a ransomware attack in 2021 – the second after an attack in 2019 – the Litigation Chamber found that a Belgian hospital had, among other things, no data protection impact assessment, no effective information security policy, no adequate procedure for security updates of its software and no genuine training and awareness programme for staff. On 17 December 2024 it imposed a fine of 200,000 EUR, ordered remedial measures and rejected the argument that, as a public body, the hospital could not be fined. On 3 September 2025 the Market Court partially annulled the decision and reduced the fine to 50,000 EUR; the data protection authority has lodged an appeal in cassation against that judgment. The decision is not final. The amount and the facts have not been confirmed against the primary source.

What organisations can take from it

A single phishing training session or the participation of a few employees in exercises does not replace regular data protection and security training for all hospital staff.

Relevance to training and awareness

Security awareness and data protection training for all hospital staff

Missing or inadequate training played a role in the decision.

Authority / court
Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA) – Chambre Contentieuse
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. f, Art. 24, Art. 32 und Art. 35 Abs. 3 DSGVO; Art. 58 Abs. 2 lit. d und i sowie Art. 83 DSGVO; Art. 100 § 1 9° und 13° sowie Art. 101 LCA
Action
Fine
Status of proceedings
reduced
Sector
Healthcare
Culpability
negligent
Mitigating circumstances
The Chamber reduced the starting amount of 390,000 EUR to 200,000 EUR, mainly because of the hospital's financial difficulties, the Covid-19 crisis as a mitigating circumstance and a reassessed duration of the infringement.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial