Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,016 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

12cases from 1 jurisdiction
€396.1mTotal of monetary amounts (11 cases with an amount)
€240.8mLargest single case: Coupang Corp.
€7.95mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20242€18.6m
Q1 20253€12.6m
Q2 20250–
Q3 20251€83.2m
Q4 20252€278,912
Q1 20260–
Q2 20261€240.8m
Q3 20263€40.7m
Q4 20260–

12 cases

17 Sep 2026 PFC Technologies Co., Ltd. (vormals PeopleFund Company)P2P lending platform shared customer data without consent: FSS sanctions PFC South KoreaData protection €45,990

According to the sanctions disclosure of the Financial Supervisory Service (FSS, Korea's financial supervisor), the online lending platform PFC Technologies transferred the resident registration numbers of 8,497 customers to a third party without their consent on 28 September 2022 in order to calculate the error rate of a new service for mortgage customers, and received credit information on the same customers from that third party, likewise without consent (such as the address and official value of their properties); in addition, when the inspection began it had not implemented password rules against easily guessed numbers. The sanction of 17 September 2026 comprises an institutional warning, an administrative fine (과태료) of KRW 24 million and a penalty surcharge (과징금) of KRW 49 million, KRW 73 million in total.

What organisations can take from it

Even for internal tests and quality measurements, customer data may only be passed to third parties with consent or a clear legal basis.

Relevance to training and awareness

Consent for sharing credit data and password rules

Authority / court
Financial Supervisory Service (FSS)
Area of law
Data protection
Legal basis
Art. 19, 32 und 34 Credit Information Use and Protection Act; Art. 16, 28 und 29 Durchführungsverordnung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Measures against individuals are not set out here.
Published
17 Sep 2026

Original amount 73,000,000 KRW, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 South KoreaData breaches and data security €7.95m

Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.

What organisations can take from it

Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.

Relevance to training and awareness

Credential stuffing and password reuse

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
Published
31 Aug 2026

Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells South KoreaData breaches and data security €32.7m

Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.

What organisations can take from it

Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.

Relevance to training and awareness

Lost network devices and certificate management

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
Published
30 Jul 2026

Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee South KoreaData breaches and data security €240.8m

A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.

What organisations can take from it

When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.

Relevance to training and awareness

Offboarding: revoking access and keys

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
Liability of senior managers
The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
Published
11 Jun 2026

Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Nov 2025 Starbucks CorporationStarbucks: order over inadequate oversight of audit provider in Korea South KoreaData processors Order

Starbucks Corporation had suppliers in Korea audited under its Ethical Sourcing Program by Elevate Hong Kong Holdings Limited, did not conclude a processing contract containing all statutory terms and did not supervise the provider adequately; Elevate processed unnecessarily large amounts of data on supplier employees, such as personnel files, wage and working-time records, and transferred them out of the businesses. The authority ordered Starbucks to award such work only under a written contract with all mandatory terms and to train and supervise the provider, and recommended data minimisation; a separate order was issued against Elevate.

What organisations can take from it

Supply chain audits process personal data too – the commissioning company needs a complete processing contract and must check that the audit provider collects no more than necessary.

Relevance to training and awareness

Data processing in supplier audits

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data processors
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 26(1) und (4)
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Employees
10,000 or more
Published
27 Nov 2025

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers South KoreaData breaches and data security €278,912

In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.

What organisations can take from it

Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.

Relevance to training and awareness

Malware on workstations and detection of unusual access

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Mitigating circumstances
Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
Liability of senior managers
The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
Published
23 Oct 2025

Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers South KoreaData breaches and data security €83.2m

Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.

What organisations can take from it

Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.

Relevance to training and awareness

Undetected malware in core systems

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
Liability of senior managers
There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
Published
28 Aug 2025

Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing South KoreaMarketing and consent €8.51m

From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.

What organisations can take from it

Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.

Relevance to training and awareness

Purpose limitation and data misuse by employees

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
Liability of senior managers
Measures against individuals are not set out here.
Published
27 Mar 2025

Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

22 Jan 2025 Kakaopay Corp.Kakao Pay: 5.968 billion KRW for transferring user data to Alipay without consent South KoreaInternational data transfers €3.99m

Kakaopay Corp. transferred data on all users three times in 2018 and, from June 2019 to May 2024, data on around 40 million users every day without consent to Alipay in Singapore, which used it to calculate for Apple a score for the likelihood of insufficient funds on bundled App Store payments (NSF score). The authority treated this as an unlawful transfer abroad, imposed a penalty surcharge of 5,968,000,000 KRW and ordered remediation and publication of the decision on the company’s website. In separate decisions on the same day Apple received a penalty surcharge of 2,405,000,000 KRW and an administrative fine of 2,200,000 KRW, and Alipay was ordered to delete the scoring model.

What organisations can take from it

Anyone passing customer data to a partner’s foreign service provider must check whether this is a transfer requiring consent and limit the data to what is necessary.

Relevance to training and awareness

Data sharing with partners’ foreign service providers

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · International data transfers
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 28-8(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 30% for completed remediation, cooperation and ISMS-P certification; increase of 50% because the infringement lasted more than two years (June 2019 to May 2024).
Published
23 Jan 2025

Original amount 5,968,000,000 KRW, converted at the ECB reference rate of 22 Jan 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 Jan 2025 National Court Administration (법원행정처)Court administration: 213 million KRW after theft of 1,014 GB of case files South KoreaData breaches and data security €141,669

Through a port between the internal and external networks that had been opened for convenience, attackers entered the e-litigation server of the National Court Administration and took 1,014 GB of case documents; the 4.7 GB that were recovered contained data on 17,998 people, including resident registration numbers. The authority criticised unencrypted documents, unchanged, easily guessed initial passwords on administrator accounts, missing security software on one server and a report only in December 2023, although there had been indications of the leak since April 2023. It imposed a penalty surcharge of 207,000,000 KRW and an administrative fine of 6,000,000 KRW (213,000,000 KRW in total), recommended disciplinary action and improvements and is publishing the imposition of the administrative fine on its website for one year.

What organisations can take from it

Public bodies too must change initial passwords, close unnecessary network crossings and report a detected data leak without delay.

Relevance to training and awareness

Initial passwords and timely incident reporting

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 24(3), Art. 24-2(2), Art. 29, Art. 34(1) und (3); Sanktion nach Art. 34-2 a. F.
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Culpability
negligent
Mitigating circumstances
After an increase of 20%, the amount was reduced by 25%, taking into account protective efforts such as an ISMS certification (2020–2023).
Liability of senior managers
Measures against individuals are not set out here.
Published
9 Jan 2025

Original amount 213,000,000 KRW, converted at the ECB reference rate of 8 Jan 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

11 Dec 2024 Hyundai Marine & Fire Insurance Co., Ltd.Hyundai Marine & Fire: 6.198 billion KRW for manipulative consent pop-up South KoreaMarketing and consent €4.12m

Hyundai Marine & Fire Insurance showed users of its online car insurance premium calculator who had declined consent to product marketing a further pop-up, swapped the effect of its buttons in July 2022 and mentioned neither the processing of data nor the mandatory information in it; the consents obtained in this way were invalid, and other insurers copied the pattern. The authority imposed a penalty surcharge of 6,198,000,000 KRW and ordered lawful consent, deletion of data from abandoned premium calculations and stronger internal controls with independent powers for the chief privacy officer. In the same session eleven further direct insurers were sanctioned, including AXA General Insurance (2,715,000,000 KRW) and Hana Insurance (273,000,000 KRW). The amount and the facts have not been confirmed against the primary source.

What organisations can take from it

A refusal that is turned into consent by a second pop-up is not valid consent – consent flows belong with the data protection officer before launch.

Relevance to training and awareness

Dark patterns in marketing consent

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 39-3(1), Art. 31(2), Art. 21(1); Sanktion nach Art. 39-15(1) Nr. 6 a. F.
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
no
Mitigating circumstances
Reduction of 50% because no penalty had been imposed in the preceding three years, a further 30% for reasons including cooperation with the investigation and finally 40% following the Commission’s deliberations; increase of 25% because the infringement lasted from July 2022 to September 2023.
Liability of senior managers
Marketing and direct sales were able to design the consent flow without any involvement of the chief privacy officer (CPO); the authority found a breach of former Art. 31(2) and ordered that the CPO be given independent powers.
Published
12 Dec 2024

Original amount 6,198,000,000 KRW, converted at the ECB reference rate of 11 Dec 2024.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

4 Nov 2024 Meta Platforms, Inc.Meta: 21.62 billion KRW for using sensitive data for advertising without consent South KoreaMarketing and consent €14.4m

Through Facebook profiles and usage behaviour, Meta Platforms, Inc. collected sensitive characteristics of around 980,000 users in Korea – such as religion, political views or same-sex marriage – and made advertising topics built on them available to around 4,000 advertisers without obtaining separate consent. Meta also refused access requests without a legitimate reason and left an unused account-recovery page online through which passwords were reset with forged ID documents and data on ten users was obtained. The authority imposed a penalty surcharge of 21,613,000,000 KRW and an administrative fine of 10,200,000 KRW (21,623,200,000 KRW in total) together with corrective orders.

What organisations can take from it

Advertising audiences that reflect religion, political views or sexual orientation rest on sensitive data and require separate consent.

Relevance to training and awareness

Sensitive data in advertising audiences

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 23(1), Art. 29, Art. 35(3)
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Employees
10,000 or more
Published
5 Nov 2024

Original amount 21,623,200,000 KRW, converted at the ECB reference rate of 4 Nov 2024.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial