Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,833 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Office of the Australian Information Commissioner (OAIC) – 0 % · 2 cases
What for?
by topicWho?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | – |
| Q4 2025 | 1 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
2 cases
17 Oct 2025 Vinomofo Pty LtdVinomofo: privacy breach after unauthorised data access during a data migration Order
In 2022, during a large data migration project, the online wine retailer suffered unauthorised access to a database holding data on around 928,760 customers and members (identity, contact and financial information). The Privacy Commissioner found that Vinomofo had not taken reasonable steps to protect the data, although it had been aware of deficiencies in its security governance at least two years before the incident, and ordered it not to repeat these practices, together with specified remedial steps.
Data migrations to the cloud need their own security concept, and known weaknesses in security governance must not be put off.
Data security in migration projects and cloud services; privacy culture and training
Missing or inadequate training played a role in the decision.
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- APP 11.1 (Privacy Act 1988 (Cth))
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 29 Oct 2025
- OAIC: Vinomofo did not protect personal information from security risks, Privacy Commissioner finds (29 October 2025) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Vinomofo Pty Ltd (Privacy) [2025] AICmr 175 (17 October 2025) Enforcement database of an authority
Checked against the official source on 3 Oct 2026 · Direct link
Report an error
26 Aug 2025 Kmart Australia LimitedKmart: facial recognition used against refund fraud breached the Privacy Act Order
From June 2020 to July 2022, Kmart Australia used facial recognition in 28 stores to record the face of every person who came in and of every customer at the returns counters, with the aim of uncovering refund fraud, without informing them or obtaining their consent. The Privacy Commissioner rejected the exception for addressing unlawful activity, because the indiscriminate collection of sensitive biometric information was disproportionate given less intrusive alternatives and its limited benefit, and ordered that the conduct must not be continued or repeated. The decision is currently under review before the Administrative Review Tribunal; hearings are scheduled for early 2027. The decision is not final.
Before deploying facial recognition, organisations must assess and document whether less intrusive means would suffice and whether the intrusion into the privacy of everyone captured is proportionate.
Facial recognition in retail: proportionality, notice and consent
- Authority / court
- Office of the Australian Information Commissioner (OAIC)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Privacy Act 1988 (Cth), APP 1.3, 1.4, 3.3, 3.4, 5.1, 5.2
- Action
- Order
- Status of proceedings
- under appeal
- Sector
- Retail and e-commerce
- Mitigating circumstances
- Kmart stopped using the system in July 2022 when the investigation began and cooperated with the regulator throughout.
- Published
- 18 Sep 2025
- OAIC: Kmart’s use of facial recognition to tackle refund fraud unlawful, Privacy Commissioner finds (18.09.2025) Press release of an authority
- OAIC: Privacy determinations – Commissioner Initiated Investigation into Kmart Australia Limited (Privacy) [2025] AICmr 155 (26 August 2025) Enforcement database of an authority
- OAIC: Privacy Commissioner publishes updated guidance on facial recognition in retail spaces (29.07.2026) Press release of an authority
Checked against the official source on 3 Oct 2026 · Direct link