Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America and Asia-Pacific: 1,905 cases from 39 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Anonymised companies 21 cases 33 % · €56.6m
- 23andMe, Inc. 1 case 2 % · €2.74m
- Access DX Laboratory, LLC 1 case 2 % · €31.7m
- Advanced Pathology Solutions PLLC und APS MSO LLC 1 case 2 % · €25.9m
- Allin IP DX LLC 1 case 2 % · €843,519
- Ascension Health Alliance; AmSurg LLC / Ambulatory Topco LLC 1 case 2 % ·
- Associação da Irmandade da Santa Casa de Misericórdia de Pacaembu 1 case 2 % · €7.65m
- Attendo Suomi Oy 1 case 2 % · €1.5m
- Australian Clinical Labs Limited 1 case 2 % · €3.28m
- Azienda Sanitaria Universitaria Friuli Centrale (ASUFC) 1 case 2 % · €24,000
- 33 more33 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €300,000 |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Jun 2026 Health Service Executive (HSE)DPC: €300,000 fine against HSE after ransomware attack on hospital laboratory in Tullamore €300,000
In November 2018 attackers encrypted patient data in the laboratory information system of Midlands Regional Hospital Tullamore. The DPC found that the HSE had infringed Art. 5(1)(f), 28, 30, 32(1) and 34 GDPR (including insufficient security, deficient processor contracts and record of processing, and incomplete notification of affected persons), issued a reprimand, imposed €300,000 for the security failings (Art. 5(1)(f) and 32(1)) and ordered it to introduce specified policies and procedures for secure processing.
Laboratory and other specialist hospital systems also belong in security and supplier management; contracts with processors must contain the GDPR safeguards.
Ransomware protection of clinical systems
- Authority / court
- Data Protection Commission (DPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 5(1)(f), 28, 30, 32(1), 34 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- DPC: Inquiry into Midlands Regional Hospital Tullamore (IN-19-9-4) Decision of an authority
Checked against the official source on 2 Oct 2026 · Direct link