Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,030 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

9cases from 1 jurisdiction
€320,376Total of monetary amounts (7 cases with an amount)
€208,955Largest single case: Marina Bay Sands Pte. Ltd.
€11,851Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20253€51,048
Q3 20251€11,664
Q4 20253€245,993
Q1 20261€11,671
Q2 20261–
Q3 20260–
Q4 20260–

9 cases

28 Oct 2025 Marina Bay Sands Pte. Ltd.Marina Bay Sands: 315,000 SGD after configuration error in middleware migration SingaporeData breaches and data security €208,955

When API configurations were manually transferred to a new middleware platform (September 2022 to March 2023), a single employee in sole charge omitted an app identifier, so token verification did not apply to the web page of the ArtScience Friends museum programme for at least six months; an attacker exploited this in October 2023 and retrieved data on 665,495 members of the Sands Rewards Lifestyle loyalty programme, which was then offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that the resort had negligently breached the Protection Obligation by relying on this one employee without independent checks or automation. It reduced the provisionally intended 450,000 SGD to 315,000 SGD after the company's representations; no directions were issued because remediation had already been carried out.

What organisations can take from it

Security-critical configuration steps when migrating large data sets must not depend on a single person without independent checks or automation.

Relevance to training and awareness

Human error in manual IT changes: four-eyes principle and automation

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Section 24 Personal Data Protection Act 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Repeat case
no
Mitigating circumstances
Otherwise adequate security arrangements, containment on the day of discovery, admission under the Expedited Decision Procedure, cooperation and voluntary notification of all affected individuals.
Published
28 Oct 2025

Original amount 315,000 SGD, converted at the ECB reference rate of 28 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

1 Apr 2026 The Management Corporation – Strata Title Plan No. 4869 (Riverfront Residences)MCST 4869: directions over lack of data protection instructions to managing agent SingaporeData processors Order

The management corporation of the Riverfront Residences condominium had not designated a data protection officer until March 2025, had no data protection policies of its own and had given its managing agent, which acted for it as a data intermediary, no instructions on handling personal data; in April 2025 an employee of the managing agent mistakenly sent the names, addresses and maintenance fee details of two owners to another owner. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found breaches of the Accountability Obligation and the Protection Obligation; by contrast, it found no breach in the circulation of a requisition for an extraordinary general meeting bearing the names and signatures of 303 owners, because strata management law prevailed. It directed the corporation to introduce, within 90 days, policies and procedures for the processing of data by the managing agent and to communicate them to it; the managing agent itself had given a voluntary undertaking.

What organisations can take from it

Anyone who outsources management to a service provider remains responsible and needs their own data protection officer, their own policies and specific instructions to the provider.

Relevance to training and awareness

Check recipients before sending, protect sensitive attachments and give service providers clear instructions

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Sections 11(3) und 12(a) PDPA 2012 (Accountability Obligation); Section 24 i. V. m. Section 4(3) PDPA (Protection Obligation bei Einsatz eines Data Intermediary)
Action
Order
Status of proceedings
unknown
Sector
Construction and real estate
Published
7 May 2026

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 Jan 2026 People Central Pte. Ltd.People Central: 17,500 SGD after attack on HR cloud holding data on 95,000 employees SingaporeData processors €11,671

The provider of cloud-based HR software received an extortion email in April 2024; an attacker had deleted databases on its AWS servers and likely exfiltrated data, and data allegedly taken was offered for sale on the dark web – data on 95,000 employees of its clients (including identity number, salary, bank account and religion) and on 24,765 emergency contacts and children was put at risk. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation because, despite the HR data entrusted to it by clients, the provider had no web application firewall against existing SQL injection vulnerabilities, remote desktop access open to the internet without two-factor authentication, and vulnerability scans only every two years. It imposed 17,500 SGD, payable in twelve monthly instalments in view of the company's cash flow, and directed among other things a web application firewall, annual penetration tests, two-factor authentication and encryption of all personal data fields.

What organisations can take from it

Cloud providers processing sensitive HR data for clients must secure remote access and have their applications tested regularly for vulnerabilities.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
no
Mitigating circumstances
Cooperation, admission under the Expedited Decision Procedure and first breach; payment in instalments in view of cash flow, while a waiver was refused.
Published
8 Jan 2026

Original amount 17,500 SGD, converted at the ECB reference rate of 8 Jan 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

29 Dec 2025 SESAMi (Singapore) Pte Ltd; Abecha Pte LtdSESAMi: 8,750 SGD after ransomware attack on network drive shared with its subsidiary SingaporeData processors €5,786

In August 2024 an attacker encrypted a network drive shared by SESAMi and its subsidiary Abecha holding payment data (including full credit card numbers and bank account details) of around 20,471 customers of the subsidiary's fuel fleet discount programme and of up to 18,837 individuals from registrations for SESAMi's B2B platform; exfiltration could not be established. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) classified SESAMi, which ran the network for the subsidiary without a written contract, as a data intermediary in that respect and found a negligent breach of the Protection Obligation by SESAMi (including outdated firewall and VPN firmware, no patch management and unenforced password and MFA rules), and likewise by Abecha, which as controller had taken no steps to ensure adequate security at SESAMi. SESAMi received 8,750 SGD and directions, while Abecha, as the controller, received directions only, including setting out roles and data protection duties within the group in writing.

What organisations can take from it

Even within a group, processing data for another group company requires a written allocation of roles and duties, and the responsible company must actively demand adequate security from its service provider.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24(a) PDPA 2012 (Protection Obligation); Section 4(3) PDPA (Pflichten bei Einsatz eines Data Intermediary); Section 48J PDPA (Financial Penalty)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Cooperation, prompt and effective remediation, admission under the Expedited Decision Procedure; for Abecha also lower culpability owing to its limited autonomy as a wholly owned subsidiary, one of the reasons for not imposing a fine on it.
Published
26 Feb 2026

Original amount 8,750 SGD, converted at the ECB reference rate of 29 Dec 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

31 Oct 2025 Air Sino-Euro Associates Travel Pte. Ltd.Air Sino-Euro: 47,000 SGD – no data protection officer, no internal rules, data leak SingaporeData subject rights and transparency €31,252

After a cyberattack on the travel agency became public in December 2023, data on 336,759 individuals in its booking system was affected, in some cases including full images of identity cards, passports and birth certificates; part of the data was exfiltrated. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found negligent breaches of the Accountability Obligation – a data protection officer appointed only in April 2024, and apart from the customer-facing privacy policy no internal policies, no complaints process and no information to staff – and of the Protection Obligation, because there were no contracts with the IT vendors covering security tasks, no security reviews and no multi-factor authentication, and the server was still running the unsupported Windows Server 2012. It imposed 47,000 SGD, rejected objections based on COVID-19 losses and comparable cases, and directed among other things policies, security clauses in vendor contracts and a penetration test by a provider licensed by the Cyber Security Agency (CSA).

What organisations can take from it

An outward-facing privacy policy is no substitute for a designated data protection officer or for internal rules that staff know and that apply in day-to-day work.

Relevance to training and awareness

Internal data protection policies, communicating them to staff, and password rules

Missing or inadequate training played a role in the decision.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); Section 24 PDPA (Protection Obligation); Section 48J(1)(a) PDPA (Financial Penalty); Section 48I PDPA (Directions)
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Mitigating circumstances
Voluntary early admission of the breaches (treated as significantly mitigating) and prompt, effective remediation.
Published
8 Jan 2026

Original amount 47,000 SGD, converted at the ECB reference rate of 31 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

3 Jul 2025 Ezynetic Pte. Ltd.Ezynetic: 17,500 SGD after ransomware at IT service provider for moneylenders SingaporeData processors €11,664

The SaaS provider operates a system for licensed moneylenders that is linked to the Moneylenders Credit Bureau and into which its clients enter data on loan applicants and borrowers; in June 2024 an attacker used a vulnerable web application to take over the SQL server's system administrator account, which was protected only by an easily guessed password, deleted databases and exfiltrated data on 190,589 individuals including credit report data, which was offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation (inadequate access control, no vulnerability assessments or penetration tests) and, given the company's role as a provider processing client data entrusted to it, considered a fine of 17,500 SGD appropriate; it rejected the request for a waiver or reduction. In addition, the company must obtain the Cyber Trust mark certification of the Cyber Security Agency of Singapore (CSA) for its new network within nine months.

What organisations can take from it

Privileged default accounts such as a database server administrator must be disabled or secured with strong passwords and additional controls, and systems must be tested regularly for vulnerabilities.

Relevance to training and awareness

Strong passwords and protection of privileged administrator accounts

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24(a) PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
no
Mitigating circumstances
Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
Published
3 Jul 2025

Original amount 17,500 SGD, converted at the ECB reference rate of 3 Jul 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

20 Jun 2025 Goldheart Jewelry Pte. Ltd.Goldheart Jewelry: 58,000 SGD over security patch applied eleven months late SingaporeData breaches and data security €39,197

The jeweller applied a patch released in February 2022 for a known vulnerability (CVE-2022-24086) in the Magento platform of its online shop only in January 2023; through the gap an attacker extracted the customer database with data on 41,379 individuals and posted it on an online forum in May 2023. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a negligent breach of the Protection Obligation because the company relied entirely on its maintenance vendor for patching without directing or monitoring it, and rejected the argument that the vendor had been a data intermediary. Alongside 58,000 SGD (provisionally 64,000 SGD; the finding on credentials stored in plain text was dropped after representations) it directed an external security audit of access controls and the remediation of any gaps.

What organisations can take from it

A company that outsources the maintenance of its web shop remains responsible for patching and must assign responsibilities and monitor implementation.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Prompt remediation once the incident was known, admission under the Expedited Decision Procedure and cooperation.
Published
8 Jan 2026

Original amount 58,000 SGD, converted at the ECB reference rate of 20 Jun 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

19 May 2025 The Management Corporation – Strata Title Plan No. 4599 (The Scotts Tower)MCST 4599: directions after refused access request for CCTV footage SingaporeData subject rights and transparency Order

A person involved in a traffic accident next to the condominium requested access to the CCTV footage in April 2024; the security company could not save it for lack of administrator access, the system overwrote it after 17 days, and the management corporation then refused the request, citing other individuals' data and strata management law. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that a blanket refusal was not justified (other individuals could have been masked) but, as the footage no longer existed, made no finding on the access obligation, and found a negligent breach of the Accountability Obligation: no data protection officer, no data protection policy of its own (only the managing agent's) and no instructions to the managing agent and security company on handling access requests. It directed the corporation to introduce, within 60 days, policies and a procedure for access requests concerning CCTV footage and to pass them on to the managing agent and contractors.

What organisations can take from it

Access requests for CCTV footage need a set procedure that secures the footage before it is automatically overwritten and masks other individuals instead of refusing outright.

Relevance to training and awareness

Recognise access requests, secure the relevant data immediately and respond in time

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); geprüft auch Sections 21 und 22A PDPA (Auskunft, Aufbewahrung bei Ablehnung)
Action
Order
Status of proceedings
unknown
Sector
Construction and real estate
Culpability
negligent
Mitigating circumstances
The management corporation appointed a data protection officer after the incident.
Published
7 Aug 2025

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

7 Apr 2025 Singapore Data Hub Pte LtdSingapore Data Hub: 17,500 SGD after SQL injection attacks on point-of-sale software SingaporeData processors €11,851

The provider of point-of-sale and CRM software for small and medium-sized enterprises reported two attacks in 2024 in which perpetrators used SQL injection, among other methods, to extract files with data on a total of 698,112 individuals, including health information (skin conditions and treatments) of 9,122 individuals; the data was likely posted on a hacking forum. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) stressed that the SaaS provider holds large volumes of data on behalf of its clients and found a breach of the Protection Obligation: publicly accessible servers, no network firewall, no security testing before releases, unsupported operating system and PHP versions, and credentials left unprotected in source code and configuration files. Alongside 17,500 SGD it directed a package of measures ranging from network segmentation and patch management to vulnerability assessments and penetration tests at least once a year.

What organisations can take from it

SaaS providers holding customer data on a large scale must test new releases for security vulnerabilities before going live and consistently update or decommission legacy systems.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24(a) PDPA 2012 (Protection Obligation)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
no
Mitigating circumstances
Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
Published
8 Jan 2026

Original amount 17,500 SGD, converted at the ECB reference rate of 7 Apr 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial