Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
€6.93mTotal of monetary amounts
€4.67mLargest single case: Doctolib
€1.77mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Autorité de la concurrence €4.67m 67 % · 1 case
  2. Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris €1.77m 25 % · 1 case
  3. Commission nationale de l'informatique et des libertés (CNIL) €500,000 7 % · 1 case

What for?

by area of law

All areas of law

  1. Competition law €4.67m 67 % · 1 case
  2. Bribery and corruption €1.77m 25 % · 1 case
  3. Data protection €500,000 7 % · 1 case

Who?

by company
  1. Doctolib €4.67m 67 % · 1 case
  2. Balt USA LLC (Balt-Gruppe) €1.77m 25 % · 1 case
  3. Hôpital Privé de la Loire €500,000 7 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20251€4.67m
Q1 20261€1.77m
Q2 20260—
Q3 20261€500,000

3 cases

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician FranceBribery of public officials €1.77m

In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.

What organisations can take from it

Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.

Relevance to training and awareness

Benefits to hospital physicians, integration of acquired companies

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
250 to 999
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Nov 2025 DoctolibFrance: 4.665 million EUR against Doctolib for abuse in doctor appointment booking FranceAbuse of market power €4.67m

Doctolib tied doctors with exclusivity clauses, bundled telemedicine with the appointment booking subscription and in 2018 acquired its main competitor MonDocteur in order to eliminate it (decision 25-D-06). Fines: 4.615 million EUR for exclusivity and tying, 50,000 EUR for the acquisition.

What organisations can take from it

Platforms with high market shares should have exclusivity clauses, bundled offers and acquisitions of rivals reviewed under competition law.

Authority / court
Autorité de la concurrence
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV, Art. L.420-2 Code de commerce
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Culpability
intentional
Published
6 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial