Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Anonymised companies €14.7m 25 % · 11 cases
- Woori Card Co., Ltd. €8.51m 14 % · 1 case
- Banco Bilbao Vizcaya Argentaria, S.A. – Niederlassung Italien (BBVA Italia) €5.51m 9 % · 1 case
- Hyundai Marine & Fire Insurance Co., Ltd. €4.12m 7 % · 1 case
- Versicherer, Spanien (anonymisiert) €4m 7 % · 1 case
- Kakaopay Corp. €3.99m 7 % · 1 case
- Großbank, Spanien (anonymisiert) €3.5m 6 % · 1 case
- Experian Nederland B.V. €2.7m 5 % · 1 case
- S-Pankki Oyj €1.8m 3 % · 1 case
- ING Bank N.V., Sucursal en España €1.6m 3 % · 1 case
- 28 more€8.46m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 1 | €8.51m |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing €8.51m
From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.
Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.
Purpose limitation and data misuse by employees
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 27 Mar 2025
Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.
- PIPC, 심의·의결서 제2025-007-021호 (주식회사 우리카드), 26.03.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조일0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.03.2025: 개인정보를 목적 외로 이용한 ㈜우리카드에 과징금 134억 5,100만 원 부과 Press release of an authority
- PIPC press release (English), 28.03.2025: The PIPC Sanctions Woori Card Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link