Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
–Total of monetary amounts (0 cases with an amount)
–Largest single case
–Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20261–
Q3 20260–
Q4 20260–

1 case

1 Apr 2026 The Management Corporation – Strata Title Plan No. 4869 (Riverfront Residences)MCST 4869: directions over lack of data protection instructions to managing agent SingaporeData processors Order

The management corporation of the Riverfront Residences condominium had not designated a data protection officer until March 2025, had no data protection policies of its own and had given its managing agent, which acted for it as a data intermediary, no instructions on handling personal data; in April 2025 an employee of the managing agent mistakenly sent the names, addresses and maintenance fee details of two owners to another owner. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found breaches of the Accountability Obligation and the Protection Obligation; by contrast, it found no breach in the circulation of a requisition for an extraordinary general meeting bearing the names and signatures of 303 owners, because strata management law prevailed. It directed the corporation to introduce, within 90 days, policies and procedures for the processing of data by the managing agent and to communicate them to it; the managing agent itself had given a voluntary undertaking.

What organisations can take from it

Anyone who outsources management to a service provider remains responsible and needs their own data protection officer, their own policies and specific instructions to the provider.

Relevance to training and awareness

Check recipients before sending, protect sensitive attachments and give service providers clear instructions

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Sections 11(3) und 12(a) PDPA 2012 (Accountability Obligation); Section 24 i. V. m. Section 4(3) PDPA (Protection Obligation bei Einsatz eines Data Intermediary)
Action
Order
Status of proceedings
unknown
Sector
Construction and real estate
Published
7 May 2026

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial