Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,929 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
–Total of monetary amounts (0 cases with an amount)
–Largest single case
–Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Privacy Commissioner for Personal Data (PCPD), Hongkong – 0 % · 1 case

What for?

by topic
  1. Data breaches and data security – 0 % · 1 case

Who?

by company
  1. Yau Yat Chuen Garden City Club Limited – 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20261–
Q3 20260–
Q4 20260–

1 case

23 Apr 2026 Yau Yat Chuen Garden City Club LimitedRansomware via remote maintenance access: enforcement notice against private club Hong KongData breaches and data security Order

In a ransomware attack on the membership management system of Yau Yat Chuen Garden City Club Limited, a private, non-profit recreational club, reported on 31 October 2025, data of 9,045 current and former members and supplementary card holders were affected, including identity card or passport numbers. The attacker exploited a known vulnerability in outdated remote access software of the external service provider and reached the server, which had been left logged in, without further authentication; antivirus software and firewall were outdated, and personal data had been kept longer than necessary. In its investigation report published on 23 April 2026 the PCPD (Privacy Commissioner for Personal Data, Hong Kong's data protection authority) found breaches of DPP 4(1) and DPP 2(2) and served an enforcement notice.

What organisations can take from it

Service providers' remote maintenance access belongs in an organisation's own security concept: current software, additional authentication and no servers left permanently logged in.

Relevance to training and awareness

Service providers' remote access, patch management and retention periods

Authority / court
Privacy Commissioner for Personal Data (PCPD), Hongkong
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Data (Privacy) Ordinance, Data Protection Principles 4(1) und 2(2); Enforcement Notice
Action
Order
Status of proceedings
unknown
Sector
Other
Published
23 Apr 2026

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial