Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,838 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Office of the Australian Information Commissioner (OAIC) 2 cases 67 % · €3.28m
- SafeWork NSW 1 case 33 % · €412,314
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €3.28m |
| Q1 2026 | 0 | – |
| Q2 2026 | 2 | €412,314 |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
3 cases
11 Jun 2026 Monash IVF Pty LtdMonash IVF: tracking pixels on fertility website used without consent Order
Monash IVF collected sensitive information about visitors to its fertility treatment website through third-party tracking pixels. The Privacy Commissioner held that following the visitors of health-related websites and afterwards showing them targeted adverts on social networks amounts to collecting sensitive data, which requires consent, and found breaches of APP 3.3, 5.1, 5.2 and 7.1. Monash IVF must not continue or repeat the conduct and must implement specified remedial steps; a parallel determination against the telehealth provider Medmate Australia was made on the same day.
Anyone using tracking pixels on health websites needs visitors' consent and must know which data flows to advertising platforms.
Tracking pixels and advertising tools on websites with sensitive content
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- Privacy Act 1988 (Cth), APP 3.3, 5.1, 5.2, 7.1
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 24 Jun 2026
- OAIC: Privacy Commissioner finds privacy breaches in third-party tracking pixel investigation (24.06.2026) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026) Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
1 May 2026 LiveBetter Services LimitedLiveBetter Services: 675,000 AUD after fatal scalding of an NDIS participant €412,314
Following an investigation by SafeWork NSW, the District Court of NSW fined LiveBetter Services Limited 675,000 AUD for a breach of ss 32/19(2) of the Work Health and Safety Act 2011. In February 2022, a participant in the National Disability Insurance Scheme (NDIS) was placed in a bath with excessively hot water, suffered serious burns and died from her injuries.
When bathing people in care, water temperature must be limited by technical means and checked before every bath.
Preventing scalds in care and support services
- Authority / court
- SafeWork NSW
- Area of law
- Health and safety and employment law · Workplace safety and accidents
- Legal basis
- Work Health and Safety Act 2011 (NSW) ss 32/19(2)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
Original amount 675,000 AUD, converted at the ECB reference rate of 30 Apr 2026.
- SafeWork NSW: Prosecution summaries – May 2026 (LiveBetter Services Limited, 1 May 2026) Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
8 Oct 2025 Australian Clinical Labs LimitedAustralian Clinical Labs: 5.8 million AUD civil penalty after Medlab Pathology data breach €3.28m
On the application of the Australian Information Commissioner, the Federal Court of Australia imposed the first civil penalties under the Privacy Act 1988: Australian Clinical Labs (ACL) had failed to adequately protect the personal information held on the IT systems of its Medlab Pathology business; in a cyberattack in February 2022, data of more than 223,000 people was taken from those systems. The penalty of 5.8 million AUD in total comprises 4.2 million AUD for the inadequate security measures (APP 11.1), 800,000 AUD because ACL did not assess reasonably and promptly whether a notifiable data breach had occurred, and 800,000 AUD for the late notification to the Commissioner. ACL admitted the contraventions; liability and the penalty were allegedly based on joint submissions by the parties.
When a business unit's IT systems are integrated into an organisation's own environment, they must be adequately protected from the outset, and attacks must be promptly assessed for a notification duty.
Securing integrated IT systems, assessing and notifying data breaches promptly
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Privacy Act 1988 (Cth) s 13G(a) i. V. m. APP 11.1; s 26WH(2); s 26WK(2)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- Cooperation with the investigation, an ongoing programme to uplift cyber security, apologies and admission of liability.
- Liability of senior managers
- The court found that the most senior management was involved in the decisions on integrating the Medlab systems and on assessing the attack.
- Published
- 9 Oct 2025
Original amount 5,800,000 AUD, converted at the ECB reference rate of 8 Oct 2025.
Checked against the official source on 3 Oct 2026 · Direct link