Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Coupang Corp. €240.8m 57 % · 1 case
- Infinite Styles Services Co. Limited (Shein) €150m 36 % · 1 case
- Anonymised companies €7.96m 2 % · 6 cases
- GS Retail Co., Ltd. €7.95m 2 % · 1 case
- Einzelhandelskette mit Kundenprogramm (anonymisiert) €3.5m 1 % · 1 case
- Centros Comerciales Carrefour, S.A. €3.2m 1 % · 1 case
- Elkjøp Nordic AS, Elkjøp Norge AS €1.85m 0 % · 1 case
- Sprinter Megacentros del Deporte, S.L. €1.56m 0 % · 1 case
- Tractor Supply Company €1.16m 0 % · 1 case
- Verkkokauppa.com Oyj €792,639 0 % · 1 case
- 20 more€1.04m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €240.8m |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee €240.8m
A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.
When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.
Offboarding: revoking access and keys
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
- Liability of senior managers
- The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
- Published
- 11 Jun 2026
Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.
- PIPC, 심의·의결서 제2026-011-075호 (쿠팡 주식회사), 10.06.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025-조이-0149 Enforcement database of an authority
- PIPC-Pressemitteilung vom 11.06.2026: 쿠팡 및 계열사의 개인정보 유출 및 침해 제재처분 의결 Press release of an authority
- PIPC press release (English), 17.06.2026: The PIPC Sanctions Coupang and CFS Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link