Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by topicWho?
by company- Google LLC €1.19bn 80 % · 1 case
- SK Telecom Co., Ltd. €83.2m 6 % · 1 case
- Orange SA €50m 3 % · 1 case
- Vodafone GmbH €45m 3 % · 1 case
- Free Mobile SAS und Free SAS €42m 3 % · 1 case
- KT Corporation €32.7m 2 % · 1 case
- Anonymised companies €16.8m 1 % · 10 cases
- TIM S.p.A. €9.52m 1 % · 1 case
- Betreiber elektronischer Kommunikationsnetze und -dienste (in der Mitteilung nicht namentlich genannt) €4.5m 0 % · 1 case
- Advanced Computer Software Group Ltd €3.68m 0 % · 1 case
- 33 more€10.2m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €5,786 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
29 Dec 2025 SESAMi (Singapore) Pte Ltd; Abecha Pte LtdSESAMi: 8,750 SGD after ransomware attack on network drive shared with its subsidiary €5,786
In August 2024 an attacker encrypted a network drive shared by SESAMi and its subsidiary Abecha holding payment data (including full credit card numbers and bank account details) of around 20,471 customers of the subsidiary's fuel fleet discount programme and of up to 18,837 individuals from registrations for SESAMi's B2B platform; exfiltration could not be established. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) classified SESAMi, which ran the network for the subsidiary without a written contract, as a data intermediary in that respect and found a negligent breach of the Protection Obligation by SESAMi (including outdated firewall and VPN firmware, no patch management and unenforced password and MFA rules), and likewise by Abecha, which as controller had taken no steps to ensure adequate security at SESAMi. SESAMi received 8,750 SGD and directions, while Abecha, as the controller, received directions only, including setting out roles and data protection duties within the group in writing.
Even within a group, processing data for another group company requires a written allocation of roles and duties, and the responsible company must actively demand adequate security from its service provider.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation); Section 4(3) PDPA (Pflichten bei Einsatz eines Data Intermediary); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Cooperation, prompt and effective remediation, admission under the Expedited Decision Procedure; for Abecha also lower culpability owing to its limited autonomy as a wholly owned subsidiary, one of the reasons for not imposing a fine on it.
- Published
- 26 Feb 2026
Original amount 8,750 SGD, converted at the ECB reference rate of 29 Dec 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by SESAMi (Singapore) Pte Ltd and Abecha Pte Ltd (veröffentlicht 26.02.2026) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 1, SESAMi (Singapore) Pte Ltd / Abecha Pte Ltd, Case No. DP-2408-C2786 (29.12.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link