Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) €14.7m 100 % · 2 cases
What for?
by topicWho?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €14.4m |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €278,912 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
2 cases
22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers €278,912
In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.
Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.
Malware on workstations and detection of unusual access
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
- Liability of senior managers
- The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
- Published
- 23 Oct 2025
Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.
- PIPC, 심의·의결서 제2025-022-256호 (인크루트(주)), 22.10.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.10.2025: 취업 준비생 개인정보를 유출한 인크루트에 과징금 4.6억원 부과 Press release of an authority
- PIPC press release (English), 24.10.2025: The PIPC Sanctions Incruit over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
4 Nov 2024 Meta Platforms, Inc.Meta: 21.62 billion KRW for using sensitive data for advertising without consent €14.4m
Through Facebook profiles and usage behaviour, Meta Platforms, Inc. collected sensitive characteristics of around 980,000 users in Korea – such as religion, political views or same-sex marriage – and made advertising topics built on them available to around 4,000 advertisers without obtaining separate consent. Meta also refused access requests without a legitimate reason and left an unused account-recovery page online through which passwords were reset with forged ID documents and data on ten users was obtained. The authority imposed a penalty surcharge of 21,613,000,000 KRW and an administrative fine of 10,200,000 KRW (21,623,200,000 KRW in total) together with corrective orders.
Advertising audiences that reflect religion, political views or sexual orientation rest on sensitive data and require separate consent.
Sensitive data in advertising audiences
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 23(1), Art. 29, Art. 35(3)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 5 Nov 2024
Original amount 21,623,200,000 KRW, converted at the ECB reference rate of 4 Nov 2024.
- PIPC-Pressemitteilung vom 05.11.2024: 합법 처리근거 없이 민감정보를 수집·활용한 메타 제재 Press release of an authority
- PIPC-Pressemitteilung vom 05.11.2024 (PDF mit Sanktionstabelle) Press release of an authority
- PIPC press release (English), 07.11.2024: PIPC Sanctions against Meta for Collection and Use of Sensitive Data Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link