Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EUHealthcare Clear all filters
22cases from 17 jurisdictions
€29.7mTotal of monetary amounts (18 cases with an amount)
€24,500Median per case with an amount

Click a bar to drill down one level.

Where?

by country
  1. Slovakia €22.3m 75 % · 2 cases
  2. France €6.93m 23 % · 3 cases
  3. Croatia €190,000 1 % · 1 case
  4. Bulgaria €56,819 0 % · 2 cases
  5. Slovenia €43,000 0 % · 1 case
  6. Greece €25,000 0 % · 1 case
  7. Italy €24,000 0 % · 1 case
  8. Malta €20,000 0 % · 1 case
  9. Denmark €10,057 0 % · 1 case
  10. Austria €5,000 0 % · 1 case
  11. 7 more€7,942

What for?

by area of law

All areas of law

  1. Competition law €27.1m 91 % · 5 cases
  2. Bribery and corruption €1.77m 6 % · 1 case
  3. Data protection €781,999 3 % · 14 cases
  4. Consumer protection and online retail €4,722 0 % · 2 cases

Who?

by company
  1. Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratórií €14.6m 49 % · 1 case
  2. PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs) €7.8m 26 % · 1 case
  3. Doctolib €4.67m 16 % · 1 case
  4. Balt USA LLC (Balt-Gruppe) €1.77m 6 % · 1 case
  5. Hôpital Privé de la Loire €500,000 2 % · 1 case
  6. Самостоятелна медико-диагностична лаборатория „Лина“ ЕООД €52,097 0 % · 1 case
  7. Veterinarska zbornica Slovenije €43,000 0 % · 1 case
  8. Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios) €25,000 0 % · 1 case
  9. Azienda Sanitaria Universitaria Friuli Centrale (ASUFC) €24,000 0 % · 1 case
  10. Kræftens Bekæmpelse €10,057 0 % · 1 case
  11. 8 more€12,664

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€43,000
Q1 20240—
Q2 20240—
Q3 20242€192,000
Q4 20242€15,057
Q1 20251€4,722
Q2 20252€20,000
Q3 20252€2,669
Q4 20252€4.67m
Q1 20264€9.57m
Q2 20263€14.6m
Q3 20263€549,000

22 cases

3 Sep 2026 Azienda Sanitaria Universitaria Friuli Centrale (ASUFC)Garante: Udine hospital group pays 24,000 EUR for viewing a colleague's patient record ItalyEmployee data €24,000

Hospital staff opened a colleague's electronic health record to organise duty rosters during Covid rather than for treatment purposes. Technical barriers limiting access to treating staff were lacking; the Italian data protection authority (Garante per la protezione dei dati personali) imposed 24,000 EUR (Provvedimento No. 616).

What organisations can take from it

Patient records may only be opened for treatment – include this in training and secure it technically through role-based rights and logging.

Relevance to training and awareness

Purpose limitation when accessing patient records

Authority / court
Garante per la protezione dei dati personali
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. a, b, c, f, Art. 9, 25, 32 DSGVO; Art. 75 Codice privacy; Linee guida dossier sanitario
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
11 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

21 Jul 2026 Hôpital Privé de la LoireHôpital Privé de la Loire: 500,000 EUR after data exfiltration affecting over 520,000 patients FranceData breaches and data security €500,000

In summer 2025, an attacker gained access to the private hospital's electronic patient record system and obtained data on 524,867 patients and 202,246 trusted persons. There was no VPN or multi-factor authentication for external users, no appropriate access control and no detection of suspicious activity; the trusted persons were not notified. France's data protection authority (Commission nationale de l'informatique et des libertés, CNIL) imposed a fine of 500,000 EUR (SAN-2026-009).

What organisations can take from it

External access to patient records belongs behind multi-factor authentication and continuous monitoring for unusual access.

Relevance to training and awareness

Access security and attack detection in hospitals

Authority / court
Commission nationale de l'informatique et des libertés (CNIL)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32, Art. 34
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
3 Sep 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Jul 2026 Γενικό Νοσοκομείο Θεσσαλονίκης Γ. Γεννηματάς «Ο Άγιος Δημήτριος» (Allgemeines Krankenhaus Thessaloniki G. Gennimatas – Agios Dimitrios)Thessaloniki hospital: 25,000 EUR because surgery lists with diagnoses were online GreeceData breaches and data security €25,000

From May to the end of August 2024, the public hospital accidentally published on its website a surgery list containing patients' telephone numbers, illnesses and planned procedures; a member of the public found the document via Google. The Hellenic Data Protection Authority imposed a total of 25,000 EUR: 10,000 EUR for inadequate security, 2,000 EUR for the late notification, 10,000 EUR for failing to notify the data subjects and 3,000 EUR for missing contact details of the data protection officer (DPO).

What organisations can take from it

Every publication on the website needs an approval step that reliably intercepts documents containing health data – and after a data breach, data subjects must be informed.

Relevance to training and awareness

Publication of documents containing health data

Authority / court
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 5 Abs. 1 lit. f, 32 Abs. 1, 33 Abs. 1, 34 Abs. 1, 12, 13 i. V. m. 37 (Entscheidung 13/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Jun 2026 Самостоятелна медико-диагностична лаборатория „Лина“ ЕООДLaboratory Lina lures customers with free blood tests – 52,097 EUR for unfair competition BulgariaCompetition law €52,097

On application by its competitor Ramus, the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) established that the laboratory had offered packages of medical laboratory tests free of charge nationwide over extended periods (only against a fee of 2 leva for taking blood) – conduct shown by no other market participant outside joint campaigns. It found an infringement of the general clause of unfair competition law (Art. 29 ZZK – Bulgarian Protection of Competition Act) and imposed 0.3% of 2024 turnover, i.e. 52,096.55 EUR. Appeals have been lodged against the decision.

What organisations can take from it

Permanent free offers to win customers can be unfair if they deviate significantly from market practice and drive out competitors.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Competition law
Legal basis
Art. 29 ZZK (Generalklausel unlauterer Wettbewerb)
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Published
2 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Apr 2026 Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratóriíLaboratory cartel: 14.6 million EUR and procurement bans against diagnostic laboratories SlovakiaCartels and collusion €14.6m

Four laboratories and their association coordinated negotiations on prices with health insurers, coordinated in tenders, exchanged sensitive information and allocated customers. At first instance, the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 14,551,800 EUR and three-year procurement bans; Unilabs received a substantially reduced fine as leniency applicant and under a settlement.

What organisations can take from it

Common negotiating positions towards payers via an association are a cartel – association meetings need minutes and a review of the agenda.

Relevance to training and awareness

Information exchange among competitors and association work

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Kartellverbot)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
Unilabs: leniency reduction (50%) and settlement (a further 30%).
Published
12 May 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Apr 2026 Fullgevity OÜ (vormals OÜ Dr Mõttus Hambaravi)Fullgevity (dental clinic) must reorganise data processing in Invisalign treatment EstoniaData processors Order

The starting point was a complaint about incomplete disclosure of patient data; the clinic left several requests from the supervisory authority unanswered. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered it to revise its contracts with Align Technology (Invisalign) with regard to the GDPR roles (Art. 26/28 GDPR), to adapt the consent form and the privacy notices in accordance with Art. 7, 9, 13 and 14 GDPR and to publish them in Estonian; non-compliance is subject to a penalty payment of 1,000 EUR per item.

What organisations can take from it

Anyone passing patient data on to manufacturers or platforms must clarify roles, contracts and consents properly in advance – and respond to supervisory requests on time.

Relevance to training and awareness

Consent and transparency for health data; cooperation with the supervisory authority

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data processors
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. d DSGVO i. V. m. Art. 5 Abs. 1 lit. a, 7, 9, 13, 14, 26, 28 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Mar 2026 Gesundheitsdienstleister (in der Entscheidung anonymisiert)Hungarian GP practice: 500,000 HUF for 47 EESZT queries without legal basis HungaryData subject rights and transparency €1,274

A general practitioner who had no longer been treating the complainant since January 2023 accessed his health data (findings, prescriptions) on the national e-health platform EESZT a total of 47 times via his practice software until August 2024 and did not respond to an access request. The Hungarian data protection authority (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) found infringements of Art. 5(2), 6(1), 9(2), 12(2) and 15(1) GDPR, ordered compliance with the access request and imposed 500,000 HUF.

What organisations can take from it

Every access to electronic health records is logged and must be linked to treatment – even if it is triggered by practice staff.

Relevance to training and awareness

Access to health data and access requests

Authority / court
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Area of law
Data protection · Data subject rights and transparency
Legal basis
DSGVO Art. 5 Abs. 2, 6 Abs. 1, 9 Abs. 2, 12 Abs. 2, 15 Abs. 1 (NAIH-273-7/2026)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
20 Mar 2026

Original amount 500,000 HUF, converted at the ECB reference rate of 20 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Mar 2026 Balt USA LLC (Balt-Gruppe)Balt USA: CJIP in France over payments to a hospital physician FranceBribery of public officials €1.77m

In parallel with the US declination, the PNF concluded a CJIP with the US subsidiary of the French medical technology manufacturer for 1,765,493 EUR (after crediting the US disgorgement) and a three-year AFA compliance programme. The case arose from Balt SAS's voluntary self-disclosure of 22 May 2023 concerning offences committed by a former manager of the acquired company Blockade Medical.

What organisations can take from it

Acquisitions require anti-corruption due diligence on the target company – otherwise legacy misconduct by its management becomes a group risk.

Relevance to training and awareness

Benefits to hospital physicians, integration of acquired companies

Authority / court
Parquet national financier (PNF); Validierung durch den Präsidenten des Tribunal judiciaire de Paris
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
Art. 41-1-2 Code de procédure pénale (CJIP); aktive und passive Bestechung von Amtsträgern
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
250 to 999
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure to the PNF and the DOJ; coordinated resolution with crediting.
Liability of senior managers
The CJIP does not address the criminal liability of natural persons.
Published
19 Mar 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR RomaniaData protection €1,999

The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.

What organisations can take from it

Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.

Relevance to training and awareness

Taking patient data when leaving; cooperation with the supervisory authority

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
20 Feb 2026

Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2026 PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs)Pharmaceutical cartel uncovered thanks to whistleblower: 7.8 million EUR against PHOENIX and TRANSMEDIC SlovakiaCartels and collusion €7.8m

The two companies colluded in tenders of the General Health Insurance Company for the supply of medicines (2017–2020). For the first time, a cartel was uncovered on the basis of information from a whistleblower; the Protimonopolný úrad Slovenskej republiky (Antimonopoly Office of the Slovak Republic, PMÚ SR) imposed 7,595,200 EUR and a one-year procurement ban on PHOENIX and 201,800 EUR and a three-year procurement ban on TRANSMEDIC (first instance).

What organisations can take from it

Whistleblowers receive a reward in Slovakia – internal reporting channels should be faster than the route to the authority.

Relevance to training and awareness

Bid rigging in public tenders; whistleblowing channels

Authority / court
Protimonopolný úrad Slovenskej republiky (PMÚ SR)
Area of law
Competition law · Cartels and collusion
Legal basis
Slowakisches Wettbewerbsschutzgesetz (Submissionsabsprache)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional
Mitigating circumstances
PHOENIX: settlement with a 30% fine reduction and a shortened procurement ban.
Published
24 Feb 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Nov 2025 DoctolibFrance: 4.665 million EUR against Doctolib for abuse in doctor appointment booking FranceAbuse of market power €4.67m

Doctolib tied doctors with exclusivity clauses, bundled telemedicine with the appointment booking subscription and in 2018 acquired its main competitor MonDocteur in order to eliminate it (decision 25-D-06). Fines: 4.615 million EUR for exclusivity and tying, 50,000 EUR for the acquisition.

What organisations can take from it

Platforms with high market shares should have exclusivity clauses, bundled offers and acquisitions of rivals reviewed under competition law.

Authority / court
Autorité de la concurrence
Area of law
Competition law · Abuse of market power
Legal basis
Art. 102 AEUV, Art. L.420-2 Code de commerce
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare
Culpability
intentional
Published
6 Nov 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Oct 2025 Nura OÜNura OÜ must hand over scan files of their treatment to two patients EstoniaData subject rights and transparency Order

Despite access requests, two patients did not receive copies of their scan files at the end of treatment; the practice responded only sluggishly to enquiries and did not attend an appointment with the supervisory authority. The Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate, AKI) ordered disclosure under Art. 15(3) GDPR or a reasoned refusal and threatened a penalty payment of 2,000 EUR.

What organisations can take from it

Access requests concerning health data require a fixed procedure with deadlines – in small practices too.

Relevance to training and awareness

Handling access requests from patients

Authority / court
Andmekaitse Inspektsioon (AKI)
Area of law
Data protection · Data subject rights and transparency
Legal basis
§ 56 Abs. 1 IKS; Art. 58 Abs. 2 lit. c, Art. 12 Abs. 4, Art. 15 DSGVO
Action
Order
Status of proceedings
unknown
Sector
Healthcare

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Sep 2025 Specer sp. z o.o.Medical company Specer: CEO acting as data protection officer costs 11,365 PLN PolandData protection €2,669

For almost six years, the chair of the management board of the medical company was also its data protection officer; this came to light after a report that a patient had been handed documents relating to another person. Poland’s data protection authority (UODO) found a conflict of interest and imposed 11,365 PLN.

What organisations can take from it

This also applies in small practices and companies: management cannot be its own data protection officer.

Relevance to training and awareness

Role and independence of the data protection officer; release of patient records

Authority / court
Prezes Urzędu Ochrony Danych Osobowych (UODO)
Area of law
Data protection
Legal basis
Art. 38 Abs. 6 DSGVO (DKN.5131.7.2025)
Action
Fine
Status of proceedings
final
Sector
Healthcare
Mitigating circumstances
An independent external data protection officer was appointed in July 2024.
Published
29 Sep 2025

Original amount 11,365 PLN, converted at the ECB reference rate of 12 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

31 Jul 2025 BGH: no before-and-after images for nose and chin correction with hyaluronic acid GermanyMisleading advertising and pricing Order

A practice for aesthetic treatments advertised hyaluronic acid filler injections for the nose and chin on its website and on Instagram using before-and-after images. In an action brought by a consumer advice centre (Verbraucherzentrale), the BGH upheld the injunction issued by the Higher Regional Court of Hamm (OLG Hamm): such procedures are deemed to be surgical cosmetic procedures, for which this kind of advertising is prohibited.

What organisations can take from it

Instagram posts are also advertising – the strict limits of the law on advertising for medicinal products and treatments (Heilmittelwerberecht) apply to aesthetic procedures.

Relevance to training and awareness

Social media advertising for healthcare services

Authority / court
Bundesgerichtshof (I. Zivilsenat), Az. I ZR 170/24
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
§ 11 Abs. 1 Satz 3 Nr. 1, § 1 Abs. 1 Nr. 2 Buchst. c HWG; UKlaG
Action
Order
Status of proceedings
final
Sector
Healthcare
Published
31 Jul 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 May 2025 Yliopiston ApteekkiYliopiston Apteekki: 1.1 million EUR over tracking in online shop – court annuls fine FinlandCookies and tracking overturned

In 2018–2022, the online pharmacy transmitted purchase data, including data on prescription medicines, to the tracking providers via Google and Meta tracking. The sanctions board of the Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman) imposed 1.1 million EUR and a reprimand; on 1 June 2026 the Helsingin hallinto-oikeus (Helsinki Administrative Court) upheld the infringement but annulled the fine because it was unclear whether a fine may be imposed on the university pharmacy at all (not final).

What organisations can take from it

Tracking tools on health-related websites can easily transmit sensitive data – include marketing technology in the data protection review.

Relevance to training and awareness

Tracking pixels on sensitive websites

Authority / court
Tietosuojavaltuutetun toimisto – seuraamuskollegio; Helsingin hallinto-oikeus
Area of law
Data protection · Cookies and tracking
Legal basis
DSGVO Art. 9, Art. 25, Art. 32
Action
Fine
Status of proceedings
overturned
Sector
Healthcare
Published
4 Jun 2025

Amount in EUR; no ECB reference rate is available for this currency.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Apr 2025 Malta: 20,000 EUR against healthcare provider over electoral register data and missing DPO MaltaData subject rights and transparency €20,000

Despite being asked to do so, a healthcare provider (name redacted) did not correct a patient’s address, so that health reports were sent to third parties, and used address data from the electoral register without a legal basis. The Information and Data Protection Commissioner (IDPC) issued a reprimand, ordered rectification, erasure of the register data and the designation of a data protection officer, and imposed fines of 12,500, 5,000 and 2,500 EUR.

What organisations can take from it

Anyone processing health data on a large scale needs a data protection officer – and a reported incorrect address must be corrected immediately.

Relevance to training and awareness

Implementing rectification requests promptly

Authority / court
Information and Data Protection Commissioner (IDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 5 Abs. 1 lit. a und d, Art. 6 Abs. 1, Art. 14, 16, 37 Abs. 1 lit. c DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Feb 2025 Медицински център „Люлин Мед“ ООДMC Lyulin Med presented practice as branch of the Military Medical Academy – 9,236 leva BulgariaMisleading advertising and pricing €4,722

Following a tip-off from the Military Medical Academy (VMA), the Комисия за защита на конкуренцията (Bulgarian Commission for the Protection of Competition, KZK) found that the centre presented its gynaecological practice as a VMA branch with signs reading ‘МЦ „ЛЮЛИН МЕД“ АГ – ВМА ФИЛИАЛ’ and corresponding online information. For misleading conduct (Art. 31 ZZK – Bulgarian Protection of Competition Act) it imposed 0.4% of 2023 turnover, i.e. 9,236 leva. An appeal has been lodged against the decision.

What organisations can take from it

Cooperation with renowned institutions must not be presented as affiliation on signage and in online profiles.

Authority / court
Комисия за защита на конкуренцията (КЗК, Bulgarische Wettbewerbskommission)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 31 ZZK (Irreführung)
Action
Fine
Status of proceedings
under appeal
Sector
Healthcare

Original amount 9,236 BGN, converted at the ECB reference rate of 6 Feb 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Oct 2024 DSB: 5,000 EUR against Covid laboratory with managing director as data protection officer AustriaData protection €5,000

A limited company operating a diagnostic laboratory (name pseudonymised), which during the pandemic carried out up to 45,000 PCR analyses a day with around 200 employees, had appointed its managing director as data protection officer at the same time. Because of the resulting conflict of interest, the Austrian data protection authority (Datenschutzbehörde, DSB) imposed 5,000 EUR; the penalty decision is final.

What organisations can take from it

Whoever decides on the purposes and means of processing cannot monitor themselves as data protection officer.

Authority / court
Datenschutzbehörde (DSB)
Area of law
Data protection
Legal basis
Art. 37, Art. 38 Abs. 6 DSGVO
Action
Fine
Status of proceedings
final
Sector
Healthcare
Employees
50 to 249
Liability of senior managers
The managing director was also appointed as data protection officer – an impermissible conflict of interest.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Oct 2024 Kræftens BekæmpelseKræftens Bekæmpelse: 75,000 DKK after theft of unencrypted laptops DenmarkData breaches and data security €10,057

The cancer charity reported thefts of computers from its offices in Copenhagen and Aarhus as well as phishing attacks in 2019 and 2020; according to the Danish Data Protection Agency (Datatilsynet), at least 1,448 people were affected, some with health data. Although the organisation itself had considered multi-factor authentication necessary after an attack in 2018, this and encryption of the computers were lacking; Københavns Byret (Copenhagen City Court) issued a final judgment ordering it to pay 75,000 DKK (Datatilsynet’s recommendation and the prosecution’s request: 800,000 DKK).

What organisations can take from it

Encrypt mobile devices holding health data – repeated incidents without implementing one’s own measures weigh heavily.

Relevance to training and awareness

Encryption of mobile devices and phishing defence (multi-factor authentication)

Authority / court
Københavns Byret (auf Anzeige der Datatilsynet)
Area of law
Data protection · Data breaches and data security
Legal basis
DSGVO Art. 32 Abs. 1; databeskyttelsesloven § 41
Action
Fine
Status of proceedings
final
Sector
Healthcare
Repeat case
yes

Original amount 75,000 DKK, converted at the ECB reference rate of 1 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Sep 2024 VSIA "Paula Stradiņa klīniskā universitātes slimnīca"Pauls Stradiņš Clinical University Hospital refuses information to data protection authority – 2,000 EUR LatviaData protection €2,000

The Datu valsts inspekcija (Latvian Data State Inspectorate, DVI) examined several complaints against the state hospital, including about the processing of patient and health data by a physician assistant and about an unanswered access request. Because the hospital did not provide the requested information, the authority imposed 2,000 EUR for breach of the duty to cooperate.

What organisations can take from it

Hospitals need logged access to patient records and a central office that responds to supervisory requests on time.

Relevance to training and awareness

Access to patient data only where related to treatment

Authority / court
Datu valsts inspekcija (DVI)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
intentional

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

13 Sep 2024 Croatia: 190,000 EUR against specialist hospital after loss of X-ray images without backup CroatiaData breaches and data security €190,000

In 2019, a specialist hospital in the Rijeka area (name not published) irretrievably lost patients’ radiological images because it did not make backup copies, and did not report the incident although management had been informed. The Agencija za zaštitu osobnih podataka (Croatian Personal Data Protection Agency, AZOP) imposed 190,000 EUR, including for a missing data processing agreement, call recordings without a legal basis and failure to involve the data protection officer.

What organisations can take from it

Backups are not a cost factor but an obligation – and a known data loss must be notified within 72 hours.

Relevance to training and awareness

Notification of data breaches within 72 hours

Authority / court
Agencija za zaštitu osobnih podataka (AZOP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 5 Abs. 1 lit. e, Art. 6, 12, 13, 28 Abs. 3, 32 Abs. 1 lit. b, 33 Abs. 1, 38 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
13 Sep 2024

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Dec 2023 Veterinarska zbornica SlovenijeVeterinary chamber: 43,000 EUR for ban on discounts and advertising SloveniaCartels and collusion €43,000

Since 2015, the chamber’s professional code had prohibited its members from offering services below list price, at a discount or free of charge and from advertising prices and promotions – including online. As the first decision under the new act and in the first settlement procedure, the Javna agencija Republike Slovenije za varstvo konkurence (Slovenian Competition Protection Agency, AVK) imposed 43,000 EUR.

What organisations can take from it

Professional codes of chambers are decisions of associations of undertakings – price and advertising bans in them infringe competition law.

Authority / court
Javna agencija Republike Slovenije za varstvo konkurence (AVK)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 5 ZPOmK-2, Art. 101 AEUV (3062-13/2019)
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Mitigating circumstances
Settlement with acknowledgement of responsibility.
Published
22 Jan 2024
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial