Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by countryWhat for?
by area of lawAll areas of law
Who?
by company- Azienda Sanitaria Universitaria Friuli Centrale (ASUFC) 1 case 5 % · €24,000
- Balt USA LLC (Balt-Gruppe) 1 case 5 % · €1.77m
- Doctolib 1 case 5 % · €4.67m
- Fachärztliche Ordination (Kardiologie, anonymisiert) 1 case 5 % · €1,000
- Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi) 1 case 5 % ·
- Gesundheitsdienstleister (in der Entscheidung anonymisiert) 1 case 5 % · €1,274
- Hôpital Privé de la Loire 1 case 5 % · €500,000
- Kræftens Bekæmpelse 1 case 5 % · €10,057
- Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratórií 1 case 5 % · €14.6m
- Nura OÜ 1 case 5 % ·
- 10 more10 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €43,000 |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 2 | €192,000 |
| Q4 2024 | 2 | €15,057 |
| Q1 2025 | 1 | €4,722 |
| Q2 2025 | 2 | €20,000 |
| Q3 2025 | 3 | €3,669 |
| Q4 2025 | 2 | €4.67m |
| Q1 2026 | 5 | €9.57m |
| Q2 2026 | 3 | €14.6m |
| Q3 2026 | 3 | €549,000 |
24 cases
3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record €24,000
Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).
Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.
Purpose limitation when accessing patient records
- Authority / court
- Garante per la protezione dei dati personali
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 11 Sep 2026
- Newsletter del 11 settembre 2026 – Garante privacy Press release of an authority
- Garante privacy, azienda sanitaria di Udine sanzionata per 24mila euro Press release of an authority
- Garante – Provvedimento n. 616 del 3 settembre 2026 [10293994] (ASUFC) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients €500,000
In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).
External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.
Access security and attack detection in hospitals
- Authority / court
- Commission nationale de l'informatique et des libertés (CNIL)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 32, Art. 34
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 3 Sep 2026
- Sanction : amende de 500 000 euros à l'encontre de l'Hôpital Privé de la Loire Press release of an authority
- Délibération SAN-2026-009 du 21 juillet 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online €25,000
From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).
Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.
Publication of documents containing health data
- Authority / court
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Επιβολή προστίμου σε νοσοκομείο (Απόφαση 13/2026) Decision of an authority
- Απόφαση 13/2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition €52,097
On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.
Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Competition law
- Legal basis
- Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
- Published
- 2 Jul 2026
- КЗК Публичен електронен регистър – Производство (Решение № 591 от 25.06.2026; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Apr 2026 Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratóriíLaboratory cartel: 14.6 million EUR and procurement bans against diagnostic laboratories €14.6m
Four laboratories and their association coordinated negotiations on prices with health insurers, coordinated in tenders, exchanged sensitive information and allocated customers. At first instance, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 14,551,800 EUR and three-year procurement bans; Unilabs received a substantially reduced fine as leniency applicant and under a settlement.
Common negotiating positions towards payers via an association are a cartel – association meetings need minutes and a review of the agenda.
Information exchange among competitors and association work
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- Unilabs: leniency reduction (50%) and settlement (a further 30%).
- Published
- 12 May 2026
- KARTELY: PMÚ odhalil kartel laboratórií a uložil pokuty takmer 15 miliónov eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment Order
The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.
Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.
Consent and transparency for health data; cooperation with the supervisory authority
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data processors
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus isikuandmete kaitse asjas nr 2.1-1/24/397-890-38 (Fullgevity OÜ), 16.04.2026 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis €1,274
A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.
Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.
Access to health data and access requests
- Authority / court
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 20 Mar 2026
Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.
- NAIH-273-7/2026 – Jogalap nélküli hozzáférés az EESZT rendszeréhez Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician €1.77m
In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.
Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.
Benefits to hospital physicians, integration of acquired companies
- Authority / court
- Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
- Area of law
- Bribery and corruption · Bribery of public officials
- Legal basis
- Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 250 to 999
- Culpability
- intentional
- Mitigating circumstances
- Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
- Liability of senior managers
- The CJIP does not address the criminal liability of natural persons.
- Published
- 19 Mar 2026
- Communiqué de presse du procureur de la République financier – CJIP BALT USA Press release of an authority
- Ministère de la Justice – Conventions judiciaires d'intérêt public (Liste) Official register or notice
- CJIP Société BALT USA LLC (17.03.2026) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR €1,999
The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.
Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.
Taking patient data when leaving; cooperation with the supervisory authority
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 20 Feb 2026
Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.
- ANSPDCP – Comunicat de presă 20.02.2026 (SC Hayat Dent SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Feb 2026 X Betriebsgesellschaft m.b.H. (Krankenhausbetreiberin, im Erkenntnis anonymisiert)Tyrolean hospital operator: VwGH upholds time clock data in rest period violations Fine
The Bezirkshauptmannschaft (district administrative authority) penalised the managing director of a Tyrolean hospital operator because in September 2022 physicians had not been granted sufficient rest periods after extended shifts and maximum duty hours had been exceeded; the Regional Administrative Court set aside several counts because the time clock data were said to have been incorrect. On an official appeal on points of law (Amtsrevision) by the Minister of Labour, the Verwaltungsgerichtshof (Austrian Supreme Administrative Court, VwGH) partly set aside that ruling: witness statements alone are not sufficient to rebut time clock records.
Time recording data count as evidence – anyone who considers them wrong needs a second control system, not just witnesses.
Working time recording and rest periods in hospitals
- Authority / court
- Verwaltungsgerichtshof (VwGH); Strafbehörde: Bezirkshauptmannschaft Innsbruck
- Area of law
- Health and safety and employment law · Working time
- Legal basis
- §§ 4 Abs. 4 Z 1, 7 Abs. 3, 11 Abs. 1, 12 Abs. 1 Krankenanstalten-Arbeitszeitgesetz (KA-AZG); § 9 VStG
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Liability of senior managers
- Fines imposed on the managing director under commercial law; liability of the company under § 9(7) VStG.
- VwGH, Erkenntnis vom 12.02.2026, Ra 2025/11/0035 (RIS) Court decision
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2026 PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs)Pharmaceutical cartel uncovered thanks to whistleblower: 7.8 million EUR against PHOENIX and TRANSMEDIC €7.8m
The two companies colluded in tenders of the General Health Insurance Company for the supply of medicines (2017–2020). For the first time, a cartel was uncovered on the basis of information from a whistleblower; the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 7,595,200 EUR and a one-year procurement ban on PHOENIX and 201,800 EUR and a three-year procurement ban on TRANSMEDIC (first instance).
Whistleblowers receive a reward in Slovakia – internal reporting channels should be faster than the route to the authority.
Bid rigging in public tenders; whistleblowing channels
- Authority / court
- Protimonopolný úrad Slovenskej republiky (PMÚ SR)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- intentional
- Mitigating circumstances
- PHOENIX: settlement with a 30% fine reduction and a shortened procurement ban.
- Published
- 24 Feb 2026
- KARTELY: PMÚ aj vďaka whistleblowerovi odhalil kartel v dodávkach liekov a uložil pokuty takmer 7,8 milióna eur Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Nov 2025 DoctolibFrance: 4.665 million EUR against Doctolib for abuse in doctor appointment booking €4.67m
Doctolib tied doctors with exclusivity clauses, bundled telemedicine with the appointment booking subscription and in 2018 acquired its main competitor MonDocteur in order to eliminate it (decision 25-D-06). Fines: 4.615 million EUR for exclusivity and tying, 50,000 EUR for the acquisition.
Platforms with high market shares should have exclusivity clauses, bundled offers and acquisitions of rivals reviewed under competition law.
- Authority / court
- Autorité de la concurrence
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 102 AEUV, Art. L.420-2 Code de commerce
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
- Culpability
- intentional
- Published
- 6 Nov 2025
- L'Autorité de la concurrence sanctionne Doctolib à hauteur de 4 665 000 euros Press release of an authority
- Décision 25-D-06 relative à des pratiques mises en œuvre dans le secteur de la prise de rendez-vous médicaux en ligne Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients Order
Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.
Access requests concerning health data require a fixed procedure with deadlines – in small practices too.
Handling access requests from patients
- Authority / court
- Andmekaitse Inspektsioon (AKI)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- § 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Healthcare
- Ettekirjutus-hoiatus nr 2.1-1/25/737-1585-20 (Nura OÜ), 13.10.2025 Decision of an authority
- Andmekaitse Inspektsioon – veröffentlichte Ettekirjutused (Liste) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN €2,669
For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.
This also applies in small practices and companies: management cannot be its own data protection officer.
Role and independence of the data protection officer; release of patient records
- Authority / court
- Prezes Urzędu Ochrony Danych Osobowych (UODO)
- Area of law
- Data protection
- Legal basis
- Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Mitigating circumstances
- An independent external data protection officer was appointed in July 2024.
- Published
- 29 Sep 2025
Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.
- Prezes firmy nie może być jednocześnie IOD. Kara dla spółki Specer Press release of an authority
- Decyzja DKN.5131.7.2025 z 12 września 2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
21 Aug 2025 Fachärztliche Ordination (Kardiologie, anonymisiert)Cardiologist pays 1,000 EUR for unauthorised ELGA access to a former employee's data €1,000
On 1 August 2024, a doctor accessed e-prescriptions and medication data of a former employee twelve times in the ELGA electronic health record without any treatment relationship. The Austrian Data Protection Authority (Datenschutzbehörde, DSB) imposed 1,000 EUR (plus 100 EUR in costs); confession and a clean record were mitigating factors.
Access to health records is only permitted where there is a treatment relationship – and it is logged.
Access to health data only where there is a treatment relationship
- Authority / court
- Datenschutzbehörde
- Area of law
- Data protection · Employee data
- Legal basis
- DSGVO Art. 5 Abs. 1 lit. a und b, Art. 6 Abs. 1, Art. 9 Abs. 1 und 2
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Culpability
- negligent
- Mitigating circumstances
- No previous record, negligence, full cooperation and confession.
- Datenschutzbehörde, Straferkenntnis 2025-0.625.944 vom 21.08.2025 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
31 Jul 2025 BGH: no before-and-after images for nose and chin correction with hyaluronic acid Order
A practice for aesthetic treatments advertised hyaluronic acid filler injections for the nose and chin on its website and on Instagram using before-and-after images. In an action brought by a consumer advice centre (Verbraucherzentrale), the BGH upheld the injunction issued by the Higher Regional Court of Hamm (OLG Hamm): such procedures are deemed to be surgical cosmetic procedures, for which this kind of advertising is prohibited.
Instagram posts are also advertising – the strict limits of the law on advertising for medicinal products and treatments (Heilmittelwerberecht) apply to aesthetic procedures.
Social media advertising for healthcare services
- Authority / court
- Bundesgerichtshof (I. Zivilsenat), Az. I ZR 170/24
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- § 11 Abs. 1 Satz 3 Nr. 1, § 1 Abs. 1 Nr. 2 Buchst. c HWG; UKlaG
- Action
- Order
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 31 Jul 2025
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine overturned
In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).
Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.
Tracking pixels on sensitive websites
- Authority / court
- Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
- Area of law
- Data protection · Cookies and tracking
- Legal basis
- DSGVO Art. 9, Art. 25, Art. 32
- Action
- Fine
- Status of proceedings
- overturned
- Sector
- Healthcare
- Published
- 4 Jun 2025
Amount in EUR; no ECB reference rate is available for this currency.
- Finlex – Tietosuojavaltuutettu 27.5.2025 (verkkoapteekin seurantateknologiat) Decision of an authority
- Tietosuojavaltuutettu – Hallinto-oikeudelta päätös Yliopiston Apteekille määrätystä seuraamusmaksusta (2.6.2026) Press release of an authority
- Helsingin hallinto-oikeus – kumosi Yliopiston Apteekille määrätyn 1,1 miljoonan euron seuraamusmaksun (01.06.2026) Court press release
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO €20,000
Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.
Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.
Implementing rectification requests promptly
- Authority / court
- Information and Data Protection Commissioner (IDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- IDPC Decision CDP/COMP/282/2024 Decision of an authority
- Data Protection Decisions – IDPC Enforcement database of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Feb 2025 Медицински център „Люлин Мед“ ООДMC Lyulin Med presented practice as branch of the Military Medical Academy – 9,236 leva €4,722
Following a tip-off from the Military Medical Academy (VMA), the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that the centre presented its gynaecological practice as a VMA branch with signs reading ‘МЦ „ЛЮЛИН МЕД“ АГ – ВМА ФИЛИАЛ’ and corresponding online information. For misleading conduct (Art. 31 ZZK – Bulgarian Protection of Competition Act) it imposed 0.4% of 2023 turnover, i.e. 9,236 leva. An appeal has been lodged against the decision.
Cooperation with renowned institutions must not be presented as affiliation on signage and in online profiles.
- Authority / court
- Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 31 ZZK (Irreführung)
- Action
- Fine
- Status of proceedings
- under appeal
- Sector
- Healthcare
Original amount 9,236 BGN, converted at the ECB reference rate of 6 Feb 2025.
- КЗК Публичен електронен регистър – Производство (Решение № 131 от 06.02.2025; Volltext als PDF im Register) Official register or notice
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer €5,000
A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.
Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.
- Authority / court
- Datenschutzbehörde (DSB)
- Area of law
- Data protection
- Legal basis
- Art. 37, Art. 38 Abs. 6 DSGVO
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Employees
- 50 to 249
- Liability of senior managers
- The managing director was also appointed as data protection officer – an impermissible conflict of interest.
- DSB Straferkenntnis GZ 2024-0.641.771 vom 16.10.2024 (RIS) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link