Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,016 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) €396.1m 100 % · 11 cases
- Financial Supervisory Service (FSS) €45,990 0 % · 1 case
What for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 2 | €18.6m |
| Q1 2025 | 3 | €12.6m |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | €83.2m |
| Q4 2025 | 2 | €278,912 |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €240.8m |
| Q3 2026 | 3 | €40.7m |
| Q4 2026 | 0 | – |
12 cases
17 Sep 2026 PFC Technologies Co., Ltd. (vormals PeopleFund Company)P2P lending platform shared customer data without consent: FSS sanctions PFC €45,990
According to the sanctions disclosure of the Financial Supervisory Service (FSS, Korea's financial supervisor), the online lending platform PFC Technologies transferred the resident registration numbers of 8,497 customers to a third party without their consent on 28 September 2022 in order to calculate the error rate of a new service for mortgage customers, and received credit information on the same customers from that third party, likewise without consent (such as the address and official value of their properties); in addition, when the inspection began it had not implemented password rules against easily guessed numbers. The sanction of 17 September 2026 comprises an institutional warning, an administrative fine (과태료) of KRW 24 million and a penalty surcharge (과징금) of KRW 49 million, KRW 73 million in total.
Even for internal tests and quality measurements, customer data may only be passed to third parties with consent or a clear legal basis.
Consent for sharing credit data and password rules
- Authority / court
- Financial Supervisory Service (FSS)
- Area of law
- Data protection
- Legal basis
- Art. 19, 32 und 34 Credit Information Use and Protection Act; Art. 16, 28 und 29 Durchführungsverordnung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 17 Sep 2026
Original amount 73,000,000 KRW, converted at the ECB reference rate of 17 Sep 2026.
- FSS 제재내용 공개 (Sanktionsveröffentlichung), 피에프씨테크놀로지스 주식회사, 17.09.2026 Enforcement database of an authority
- FSS-PDF: 피에프씨테크놀로지스 제재내용 공개안 Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 €7.95m
Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.
Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.
Credential stuffing and password reuse
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
- Published
- 31 Aug 2026
Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.
- PIPC, 심의·의결서 제2026-017-107호 (㈜지에스리테일), 26.08.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0004 Enforcement database of an authority
- PIPC-Pressemitteilung vom 31.08.2026: ㈜지에스리테일 유출사고에 대해 과징금 128억 3,600만 원, 과태료 300만 원 부과 Press release of an authority
- PIPC press release (English), 03.09.2026: The PIPC Sanctions GS Retail and Three Other Businesses Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells €32.7m
Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.
Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.
Lost network devices and certificate management
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
- Published
- 30 Jul 2026
Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.
- PIPC, 심의·의결서 제2026-015-093호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, 심의·의결서 제2026-015-094호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0113-02 등 2건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 30.07.2026: ‘㈜KT의 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 07.08.2026: The PIPC Sanctions KT Corporation for Data Breaches Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee €240.8m
A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.
When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.
Offboarding: revoking access and keys
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
- Liability of senior managers
- The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
- Published
- 11 Jun 2026
Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.
- PIPC, 심의·의결서 제2026-011-075호 (쿠팡 주식회사), 10.06.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025-조이-0149 Enforcement database of an authority
- PIPC-Pressemitteilung vom 11.06.2026: 쿠팡 및 계열사의 개인정보 유출 및 침해 제재처분 의결 Press release of an authority
- PIPC press release (English), 17.06.2026: The PIPC Sanctions Coupang and CFS Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Nov 2025 Starbucks CorporationStarbucks: order over inadequate oversight of audit provider in Korea Order
Starbucks Corporation had suppliers in Korea audited under its Ethical Sourcing Program by Elevate Hong Kong Holdings Limited, did not conclude a processing contract containing all statutory terms and did not supervise the provider adequately; Elevate processed unnecessarily large amounts of data on supplier employees, such as personnel files, wage and working-time records, and transferred them out of the businesses. The authority ordered Starbucks to award such work only under a written contract with all mandatory terms and to train and supervise the provider, and recommended data minimisation; a separate order was issued against Elevate.
Supply chain audits process personal data too – the commissioning company needs a complete processing contract and must check that the audit provider collects no more than necessary.
Data processing in supplier audits
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data processors
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 26(1) und (4)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Employees
- 10,000 or more
- Published
- 27 Nov 2025
- PIPC, 심의·의결서 제2025-024-301호 (Starbucks Corporation), 26.11.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2023조일0035 등 3건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.11.2025: 개인정보를 과다 수집‧처리한 스타벅스 본사(미국), 엘리베이트(홍콩)에 시정명령 Press release of an authority
- PIPC press release (English), 03.12.2025: The PIPC Issues Correction Orders on Starbucks and Elevate Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers €278,912
In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.
Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.
Malware on workstations and detection of unusual access
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
- Liability of senior managers
- The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
- Published
- 23 Oct 2025
Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.
- PIPC, 심의·의결서 제2025-022-256호 (인크루트(주)), 22.10.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.10.2025: 취업 준비생 개인정보를 유출한 인크루트에 과징금 4.6억원 부과 Press release of an authority
- PIPC press release (English), 24.10.2025: The PIPC Sanctions Incruit over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers €83.2m
Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.
Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.
Undetected malware in core systems
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
- Liability of senior managers
- There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
- Published
- 28 Aug 2025
Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.
- PIPC, 심의·의결서 제2025-018-243호 (에스케이텔레콤 주식회사), 27.08.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0056 Enforcement database of an authority
- PIPC-Pressemitteilung vom 28.08.2025: ‘SK텔레콤 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 03.09.2025: The PIPC Sanctions SKT over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing €8.51m
From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.
Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.
Purpose limitation and data misuse by employees
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 27 Mar 2025
Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.
- PIPC, 심의·의결서 제2025-007-021호 (주식회사 우리카드), 26.03.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조일0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.03.2025: 개인정보를 목적 외로 이용한 ㈜우리카드에 과징금 134억 5,100만 원 부과 Press release of an authority
- PIPC press release (English), 28.03.2025: The PIPC Sanctions Woori Card Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
22 Jan 2025 Kakaopay Corp.Kakao Pay: 5.968 billion KRW for transferring user data to Alipay without consent €3.99m
Kakaopay Corp. transferred data on all users three times in 2018 and, from June 2019 to May 2024, data on around 40 million users every day without consent to Alipay in Singapore, which used it to calculate for Apple a score for the likelihood of insufficient funds on bundled App Store payments (NSF score). The authority treated this as an unlawful transfer abroad, imposed a penalty surcharge of 5,968,000,000 KRW and ordered remediation and publication of the decision on the company’s website. In separate decisions on the same day Apple received a penalty surcharge of 2,405,000,000 KRW and an administrative fine of 2,200,000 KRW, and Alipay was ordered to delete the scoring model.
Anyone passing customer data to a partner’s foreign service provider must check whether this is a transfer requiring consent and limit the data to what is necessary.
Data sharing with partners’ foreign service providers
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · International data transfers
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 28-8(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 30% for completed remediation, cooperation and ISMS-P certification; increase of 50% because the infringement lasted more than two years (June 2019 to May 2024).
- Published
- 23 Jan 2025
Original amount 5,968,000,000 KRW, converted at the ECB reference rate of 22 Jan 2025.
- PIPC, 심의·의결서 제2025-001-002호 (㈜카카오페이), 22.01.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조삼0005 등 3건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.01.2025: 개인정보 무단 국외 이전한 카카오페이·애플에 과징금·과태료 부과 Press release of an authority
- PIPC press release (English), 31.01.2025: The PIPC Sanctions Kakao Pay and Apple Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 Jan 2025 National Court Administration (법원행정처)Court administration: 213 million KRW after theft of 1,014 GB of case files €141,669
Through a port between the internal and external networks that had been opened for convenience, attackers entered the e-litigation server of the National Court Administration and took 1,014 GB of case documents; the 4.7 GB that were recovered contained data on 17,998 people, including resident registration numbers. The authority criticised unencrypted documents, unchanged, easily guessed initial passwords on administrator accounts, missing security software on one server and a report only in December 2023, although there had been indications of the leak since April 2023. It imposed a penalty surcharge of 207,000,000 KRW and an administrative fine of 6,000,000 KRW (213,000,000 KRW in total), recommended disciplinary action and improvements and is publishing the imposition of the administrative fine on its website for one year.
Public bodies too must change initial passwords, close unnecessary network crossings and report a detected data leak without delay.
Initial passwords and timely incident reporting
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 24(3), Art. 24-2(2), Art. 29, Art. 34(1) und (3); Sanktion nach Art. 34-2 a. F.
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- After an increase of 20%, the amount was reduced by 25%, taking into account protective efforts such as an ISMS certification (2020–2023).
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 9 Jan 2025
Original amount 213,000,000 KRW, converted at the ECB reference rate of 8 Jan 2025.
- PIPC, 심의·의결서 제2025-001-001호 (법원행정처), 08.01.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2023조총0053 Enforcement database of an authority
- PIPC-Pressemitteilung vom 09.01.2025: 주민등록번호 유출과 안전조치 의무 위반한 법원행정처 제재 Press release of an authority
- PIPC press release (English), 10.01.2025: PIPC Sanctions National Court Administration Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
11 Dec 2024 Hyundai Marine & Fire Insurance Co., Ltd.Hyundai Marine & Fire: 6.198 billion KRW for manipulative consent pop-up €4.12m
Hyundai Marine & Fire Insurance showed users of its online car insurance premium calculator who had declined consent to product marketing a further pop-up, swapped the effect of its buttons in July 2022 and mentioned neither the processing of data nor the mandatory information in it; the consents obtained in this way were invalid, and other insurers copied the pattern. The authority imposed a penalty surcharge of 6,198,000,000 KRW and ordered lawful consent, deletion of data from abandoned premium calculations and stronger internal controls with independent powers for the chief privacy officer. In the same session eleven further direct insurers were sanctioned, including AXA General Insurance (2,715,000,000 KRW) and Hana Insurance (273,000,000 KRW). The amount and the facts have not been confirmed against the primary source.
A refusal that is turned into consent by a second pop-up is not valid consent – consent flows belong with the data protection officer before launch.
Dark patterns in marketing consent
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 39-3(1), Art. 31(2), Art. 21(1); Sanktion nach Art. 39-15(1) Nr. 6 a. F.
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- no
- Mitigating circumstances
- Reduction of 50% because no penalty had been imposed in the preceding three years, a further 30% for reasons including cooperation with the investigation and finally 40% following the Commission’s deliberations; increase of 25% because the infringement lasted from July 2022 to September 2023.
- Liability of senior managers
- Marketing and direct sales were able to design the consent flow without any involvement of the chief privacy officer (CPO); the authority found a breach of former Art. 31(2) and ordered that the CPO be given independent powers.
- Published
- 12 Dec 2024
Original amount 6,198,000,000 KRW, converted at the ECB reference rate of 11 Dec 2024.
- PIPC, 심의·의결서 제2024-021-251호 (현대해상화재보험㈜), 11.12.2024 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 202308조일0074~0085 (제2024-021-249~260호) Enforcement database of an authority
- PIPC-Pressemitteilung vom 12.12.2024: 다이렉트 자동차보험 판매 12개 손해보험사 제재처분 Press release of an authority
- PIPC press release (English), 13.12.2024: PIPC Sanctions Twelve General Insurance Companies Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
4 Nov 2024 Meta Platforms, Inc.Meta: 21.62 billion KRW for using sensitive data for advertising without consent €14.4m
Through Facebook profiles and usage behaviour, Meta Platforms, Inc. collected sensitive characteristics of around 980,000 users in Korea – such as religion, political views or same-sex marriage – and made advertising topics built on them available to around 4,000 advertisers without obtaining separate consent. Meta also refused access requests without a legitimate reason and left an unused account-recovery page online through which passwords were reset with forged ID documents and data on ten users was obtained. The authority imposed a penalty surcharge of 21,613,000,000 KRW and an administrative fine of 10,200,000 KRW (21,623,200,000 KRW in total) together with corrective orders.
Advertising audiences that reflect religion, political views or sexual orientation rest on sensitive data and require separate consent.
Sensitive data in advertising audiences
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 23(1), Art. 29, Art. 35(3)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 5 Nov 2024
Original amount 21,623,200,000 KRW, converted at the ECB reference rate of 4 Nov 2024.
- PIPC-Pressemitteilung vom 05.11.2024: 합법 처리근거 없이 민감정보를 수집·활용한 메타 제재 Press release of an authority
- PIPC-Pressemitteilung vom 05.11.2024 (PDF mit Sanktionstabelle) Press release of an authority
- PIPC press release (English), 07.11.2024: PIPC Sanctions against Meta for Collection and Use of Sensitive Data Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link