Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
€16.7mTotal of monetary amounts
€8.51mLargest single case: Woori Card Co., Ltd.
€4.06mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Information Protection Commission (PIPC, 개인정보보호위원회) €16.6m 100 % · 3 cases
  2. Financial Supervisory Service (FSS) €45,990 0 % · 1 case

What for?

by topic
  1. Marketing and consent €12.6m 76 % · 2 cases
  2. International data transfers €3.99m 24 % · 1 case
  3. no topic €45,990 0 % · 1 case

Who?

by company
  1. Woori Card Co., Ltd. €8.51m 51 % · 1 case
  2. Hyundai Marine & Fire Insurance Co., Ltd. €4.12m 25 % · 1 case
  3. Kakaopay Corp. €3.99m 24 % · 1 case
  4. PFC Technologies Co., Ltd. (vormals PeopleFund Company) €45,990 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20241€4.12m
Q1 20252€12.5m
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20261€45,990
Q4 20260–

4 cases

17 Sep 2026 PFC Technologies Co., Ltd. (vormals PeopleFund Company)P2P lending platform shared customer data without consent: FSS sanctions PFC South KoreaData protection €45,990

According to the sanctions disclosure of the Financial Supervisory Service (FSS, Korea's financial supervisor), the online lending platform PFC Technologies transferred the resident registration numbers of 8,497 customers to a third party without their consent on 28 September 2022 in order to calculate the error rate of a new service for mortgage customers, and received credit information on the same customers from that third party, likewise without consent (such as the address and official value of their properties); in addition, when the inspection began it had not implemented password rules against easily guessed numbers. The sanction of 17 September 2026 comprises an institutional warning, an administrative fine (과태료) of KRW 24 million and a penalty surcharge (과징금) of KRW 49 million, KRW 73 million in total.

What organisations can take from it

Even for internal tests and quality measurements, customer data may only be passed to third parties with consent or a clear legal basis.

Relevance to training and awareness

Consent for sharing credit data and password rules

Authority / court
Financial Supervisory Service (FSS)
Area of law
Data protection
Legal basis
Art. 19, 32 und 34 Credit Information Use and Protection Act; Art. 16, 28 und 29 Durchführungsverordnung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Measures against individuals are not set out here.
Published
17 Sep 2026

Original amount 73,000,000 KRW, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing South KoreaMarketing and consent €8.51m

From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.

What organisations can take from it

Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.

Relevance to training and awareness

Purpose limitation and data misuse by employees

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
Liability of senior managers
Measures against individuals are not set out here.
Published
27 Mar 2025

Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

22 Jan 2025 Kakaopay Corp.Kakao Pay: 5.968 billion KRW for transferring user data to Alipay without consent South KoreaInternational data transfers €3.99m

Kakaopay Corp. transferred data on all users three times in 2018 and, from June 2019 to May 2024, data on around 40 million users every day without consent to Alipay in Singapore, which used it to calculate for Apple a score for the likelihood of insufficient funds on bundled App Store payments (NSF score). The authority treated this as an unlawful transfer abroad, imposed a penalty surcharge of 5,968,000,000 KRW and ordered remediation and publication of the decision on the company’s website. In separate decisions on the same day Apple received a penalty surcharge of 2,405,000,000 KRW and an administrative fine of 2,200,000 KRW, and Alipay was ordered to delete the scoring model.

What organisations can take from it

Anyone passing customer data to a partner’s foreign service provider must check whether this is a transfer requiring consent and limit the data to what is necessary.

Relevance to training and awareness

Data sharing with partners’ foreign service providers

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · International data transfers
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 28-8(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 30% for completed remediation, cooperation and ISMS-P certification; increase of 50% because the infringement lasted more than two years (June 2019 to May 2024).
Published
23 Jan 2025

Original amount 5,968,000,000 KRW, converted at the ECB reference rate of 22 Jan 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

11 Dec 2024 Hyundai Marine & Fire Insurance Co., Ltd.Hyundai Marine & Fire: 6.198 billion KRW for manipulative consent pop-up South KoreaMarketing and consent €4.12m

Hyundai Marine & Fire Insurance showed users of its online car insurance premium calculator who had declined consent to product marketing a further pop-up, swapped the effect of its buttons in July 2022 and mentioned neither the processing of data nor the mandatory information in it; the consents obtained in this way were invalid, and other insurers copied the pattern. The authority imposed a penalty surcharge of 6,198,000,000 KRW and ordered lawful consent, deletion of data from abandoned premium calculations and stronger internal controls with independent powers for the chief privacy officer. In the same session eleven further direct insurers were sanctioned, including AXA General Insurance (2,715,000,000 KRW) and Hana Insurance (273,000,000 KRW). The amount and the facts have not been confirmed against the primary source.

What organisations can take from it

A refusal that is turned into consent by a second pop-up is not valid consent – consent flows belong with the data protection officer before launch.

Relevance to training and awareness

Dark patterns in marketing consent

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 39-3(1), Art. 31(2), Art. 21(1); Sanktion nach Art. 39-15(1) Nr. 6 a. F.
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
no
Mitigating circumstances
Reduction of 50% because no penalty had been imposed in the preceding three years, a further 30% for reasons including cooperation with the investigation and finally 40% following the Commission’s deliberations; increase of 25% because the infringement lasted from July 2022 to September 2023.
Liability of senior managers
Marketing and direct sales were able to design the consent flow without any involvement of the chief privacy officer (CPO); the authority found a breach of former Art. 31(2) and ordered that the CPO be given independent powers.
Published
12 Dec 2024

Original amount 6,198,000,000 KRW, converted at the ECB reference rate of 11 Dec 2024.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial