Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America and Asia-Pacific: 1,874 cases from 39 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€5mTotal of monetary amounts
€5mLargest single case: IQVIA Operations France
€5mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20261€5m
Q3 20260–
Q4 20260–

1 case

26 May 2026 IQVIA Operations FranceCNIL: €5m fine for IQVIA Operations France over health data warehouses FranceData subject rights and transparency €5m

The CNIL (French data protection authority) fined IQVIA Operations France EUR 5,000,000 because, for two health data warehouses authorised by the CNIL (fed with data from around 14,000 pharmacies and several thousand medical practices), the company did not comply with the conditions of the authorisations, including log analysis, multi-factor authentication, patient information and the right to object. In addition, pharmacy customers were not informed of the transfer of their data, in-house studies were carried out without the required authorisation and the pharmacy software transmitted data even after a refusal (Art. 25 GDPR). The CNIL classified the data as pseudonymised rather than anonymous and ordered remedial action within six months, subject to a penalty payment of EUR 10,000 per day.

What organisations can take from it

Anyone working with authorised health data must implement the conditions of the authorisation technically as well and actively monitor how partners inform the individuals concerned.

Relevance to training and awareness

Conditions for processing health data

Authority / court
Commission nationale de l'informatique et des libertés (CNIL), formation restreinte
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 66 Loi n° 78-17 du 6 janvier 1978 (Loi Informatique et Libertés); Art. 14 und 25 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Culpability
negligent
Mitigating circumstances
The security shortcomings were remedied after the inspections.
Published
28 May 2026

Checked against the official source on 2 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial