Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,838 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€3.28mTotal of monetary amounts
€3.28mLargest single case: Australian Clinical Labs Limited
€3.28mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Office of the Australian Information Commissioner (OAIC) €3.28m 100 % · 1 case

What for?

by area of law

All areas of law

  1. Data protection €3.28m 100 % · 1 case

Who?

by company
  1. Australian Clinical Labs Limited €3.28m 89 % · 1 case
  2. LiveBetter Services Limited €412,314 11 % · 1 case
  3. Monash IVF Pty Ltd – 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20251€3.28m
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

8 Oct 2025 Australian Clinical Labs LimitedAustralian Clinical Labs: 5.8 million AUD civil penalty after Medlab Pathology data breach AustraliaData breaches and data security €3.28m

On the application of the Australian Information Commissioner, the Federal Court of Australia imposed the first civil penalties under the Privacy Act 1988: Australian Clinical Labs (ACL) had failed to adequately protect the personal information held on the IT systems of its Medlab Pathology business; in a cyberattack in February 2022, data of more than 223,000 people was taken from those systems. The penalty of 5.8 million AUD in total comprises 4.2 million AUD for the inadequate security measures (APP 11.1), 800,000 AUD because ACL did not assess reasonably and promptly whether a notifiable data breach had occurred, and 800,000 AUD for the late notification to the Commissioner. ACL admitted the contraventions; liability and the penalty were allegedly based on joint submissions by the parties.

What organisations can take from it

When a business unit's IT systems are integrated into an organisation's own environment, they must be adequately protected from the outset, and attacks must be promptly assessed for a notification duty.

Relevance to training and awareness

Securing integrated IT systems, assessing and notifying data breaches promptly

Authority / court
Office of the Australian Information Commissioner (OAIC)
Area of law
Data protection · Data breaches and data security
Legal basis
Privacy Act 1988 (Cth) s 13G(a) i. V. m. APP 11.1; s 26WH(2); s 26WK(2)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Culpability
negligent
Mitigating circumstances
Cooperation with the investigation, an ongoing programme to uplift cyber security, apologies and admission of liability.
Liability of senior managers
The court found that the most senior management was involved in the decisions on integrating the Medlab systems and on assessing the attack.
Published
9 Oct 2025

Original amount 5,800,000 AUD, converted at the ECB reference rate of 8 Oct 2025.

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial