Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Coupang Corp. €240.8m 57 % · 1 case
- Infinite Styles Services Co. Limited (Shein) €150m 36 % · 1 case
- Anonymised companies €7.96m 2 % · 6 cases
- GS Retail Co., Ltd. €7.95m 2 % · 1 case
- Einzelhandelskette mit Kundenprogramm (anonymisiert) €3.5m 1 % · 1 case
- Centros Comerciales Carrefour, S.A. €3.2m 1 % · 1 case
- Elkjøp Nordic AS, Elkjøp Norge AS €1.85m 0 % · 1 case
- Sprinter Megacentros del Deporte, S.L. €1.56m 0 % · 1 case
- Tractor Supply Company €1.16m 0 % · 1 case
- Verkkokauppa.com Oyj €792,639 0 % · 1 case
- 20 more€1.04m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 1 | €7.95m |
| Q4 2026 | 0 | – |
1 case
26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 €7.95m
Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.
Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.
Credential stuffing and password reuse
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
- Published
- 31 Aug 2026
Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.
- PIPC, 심의·의결서 제2026-017-107호 (㈜지에스리테일), 26.08.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0004 Enforcement database of an authority
- PIPC-Pressemitteilung vom 31.08.2026: ㈜지에스리테일 유출사고에 대해 과징금 128억 3,600만 원, 과태료 300만 원 부과 Press release of an authority
- PIPC press release (English), 03.09.2026: The PIPC Sanctions GS Retail and Three Other Businesses Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link