Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
–Total of monetary amounts (0 cases with an amount)
–Largest single case
–Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Information Protection Commission (PIPC, 개인정보보호위원회) – 0 % · 1 case

What for?

by action
  1. Order – 0 % · 1 case

Who?

by sector

All sectors

  1. Food and agriculture – 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20251–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

26 Nov 2025 Starbucks CorporationStarbucks: order over inadequate oversight of audit provider in Korea South KoreaData processors Order

Starbucks Corporation had suppliers in Korea audited under its Ethical Sourcing Program by Elevate Hong Kong Holdings Limited, did not conclude a processing contract containing all statutory terms and did not supervise the provider adequately; Elevate processed unnecessarily large amounts of data on supplier employees, such as personnel files, wage and working-time records, and transferred them out of the businesses. The authority ordered Starbucks to award such work only under a written contract with all mandatory terms and to train and supervise the provider, and recommended data minimisation; a separate order was issued against Elevate.

What organisations can take from it

Supply chain audits process personal data too – the commissioning company needs a complete processing contract and must check that the audit provider collects no more than necessary.

Relevance to training and awareness

Data processing in supplier audits

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data processors
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 26(1) und (4)
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Employees
10,000 or more
Published
27 Nov 2025

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial