Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Becton, Dickinson and Company (BD) €166.7m 51 % · 1 case
- Access DX Laboratory, LLC €31.7m 10 % · 1 case
- DaVita Inc. €31.6m 10 % · 1 case
- Advanced Pathology Solutions PLLC und APS MSO LLC €25.9m 8 % · 1 case
- Medirex s. r. o.; KLINICKÁ BIOCHÉMIA s.r.o.; Unilabs Slovensko, s. r. o.; synlab slovakia s. r. o.; Asociácia laboratórií €14.6m 4 % · 1 case
- Innovasis Inc. €11.1m 3 % · 1 case
- NeoGenomics Laboratories Inc. €8.59m 3 % · 1 case
- PHOENIX Zdravotnícke zásobovanie, a.s.; TRANSMEDIC SLOVAKIA, s.r.o. (in Konkurs) €7.8m 2 % · 1 case
- Modern Nuclear Inc. €7.12m 2 % · 1 case
- New York-Presbyterian Hudson Valley Hospital €5.79m 2 % · 1 case
- 26 more€18m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 1 | €2.74m |
| Q3 2025 | 0 | — |
| Q4 2025 | 0 | — |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
1 case
5 Jun 2025 23andMe, Inc.ICO: £2.31 million against 23andMe after credential stuffing targeting genetic data €2.74m
From April to September 2023, attackers used reused credentials to access data on 155,592 people in the United Kingdom, including ancestry, family trees and health information. There was no MFA, no secure password rules and no effective monitoring; despite anomalies in July 2023, the full investigation only began in October. Joint investigation by the UK Information Commissioner's Office (ICO) with the Privacy Commissioner of Canada.
Companies that manage genetic or health data must protect customer accounts against credential stuffing with MFA and investigate warning signs immediately.
- Authority / court
- Information Commissioner's Office (ICO)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- UK GDPR Art. 5 Abs. 1 lit. f, Art. 32 Abs. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Culpability
- negligent
- Published
- 17 Jun 2025
Original amount 2,310,000 GBP, converted at the ECB reference rate of 5 Jun 2025.
- 23andMe fined for failing to protect UK users' genetic data Press release of an authority
- ICO Penalty Notice: 23andMe, Inc. Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link