Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Google LLC €1.19bn 80 % · 1 case
- SK Telecom Co., Ltd. €83.2m 6 % · 1 case
- Orange SA €50m 3 % · 1 case
- Vodafone GmbH €45m 3 % · 1 case
- Free Mobile SAS und Free SAS €42m 3 % · 1 case
- KT Corporation €32.7m 2 % · 1 case
- Anonymised companies €16.8m 1 % · 10 cases
- TIM S.p.A. €9.52m 1 % · 1 case
- Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt) €4.5m 0 % · 1 case
- Advanced Computer Software Group Ltd €3.68m 0 % · 1 case
- 33 more€10.2m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 1 | €32.7m |
| Q4 2026 | 0 | – |
1 case
29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells €32.7m
Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.
Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.
Lost network devices and certificate management
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
- Published
- 30 Jul 2026
Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.
- PIPC, 심의·의결서 제2026-015-093호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, 심의·의결서 제2026-015-094호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0113-02 등 2건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 30.07.2026: ‘㈜KT의 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 07.08.2026: The PIPC Sanctions KT Corporation for Data Breaches Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link