Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
€115.8mTotal of monetary amounts
€83.2mLargest single case: SK Telecom Co., Ltd.
€57.9mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Information Protection Commission (PIPC, 개인정보보호위원회) €115.8m 100 % · 2 cases

What for?

by topic
  1. Data breaches and data security €115.8m 100 % · 2 cases

Who?

by company
  1. SK Telecom Co., Ltd. €83.2m 72 % · 1 case
  2. KT Corporation €32.7m 28 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20251€83.2m
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20261€32.7m
Q4 20260–

2 cases

29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells South KoreaData breaches and data security €32.7m

Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.

What organisations can take from it

Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.

Relevance to training and awareness

Lost network devices and certificate management

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
Published
30 Jul 2026

Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers South KoreaData breaches and data security €83.2m

Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.

What organisations can take from it

Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.

Relevance to training and awareness

Undetected malware in core systems

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
Liability of senior managers
There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
Published
28 Aug 2025

Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial