Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

6cases from 1 jurisdiction
€365mTotal of monetary amounts
€240.8mLargest single case: Coupang Corp.
€20.3mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Information Protection Commission (PIPC, 개인정보보호위원회) €365m 100 % · 6 cases

What for?

by action
  1. Fine €365m 100 % · 6 cases

Who?

by sector

All sectors

  1. Retail and e-commerce €248.8m 68 % · 2 cases
  2. Telecoms, IT and software €115.8m 32 % · 2 cases
  3. Media and online platforms €278,912 0 % · 1 case
  4. Public sector €141,669 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20251€141,669
Q2 20250–
Q3 20251€83.2m
Q4 20251€278,912
Q1 20260–
Q2 20261€240.8m
Q3 20262€40.6m
Q4 20260–

6 cases

26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 South KoreaData breaches and data security €7.95m

Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.

What organisations can take from it

Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.

Relevance to training and awareness

Credential stuffing and password reuse

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
Published
31 Aug 2026

Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells South KoreaData breaches and data security €32.7m

Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.

What organisations can take from it

Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.

Relevance to training and awareness

Lost network devices and certificate management

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
Published
30 Jul 2026

Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee South KoreaData breaches and data security €240.8m

A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.

What organisations can take from it

When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.

Relevance to training and awareness

Offboarding: revoking access and keys

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
Liability of senior managers
The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
Published
11 Jun 2026

Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers South KoreaData breaches and data security €278,912

In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.

What organisations can take from it

Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.

Relevance to training and awareness

Malware on workstations and detection of unusual access

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Mitigating circumstances
Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
Liability of senior managers
The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
Published
23 Oct 2025

Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers South KoreaData breaches and data security €83.2m

Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.

What organisations can take from it

Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.

Relevance to training and awareness

Undetected malware in core systems

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
Liability of senior managers
There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
Published
28 Aug 2025

Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 Jan 2025 National Court Administration (법원행정처)Court administration: 213 million KRW after theft of 1,014 GB of case files South KoreaData breaches and data security €141,669

Through a port between the internal and external networks that had been opened for convenience, attackers entered the e-litigation server of the National Court Administration and took 1,014 GB of case documents; the 4.7 GB that were recovered contained data on 17,998 people, including resident registration numbers. The authority criticised unencrypted documents, unchanged, easily guessed initial passwords on administrator accounts, missing security software on one server and a report only in December 2023, although there had been indications of the leak since April 2023. It imposed a penalty surcharge of 207,000,000 KRW and an administrative fine of 6,000,000 KRW (213,000,000 KRW in total), recommended disciplinary action and improvements and is publishing the imposition of the administrative fine on its website for one year.

What organisations can take from it

Public bodies too must change initial passwords, close unnecessary network crossings and report a detected data leak without delay.

Relevance to training and awareness

Initial passwords and timely incident reporting

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 24(3), Art. 24-2(2), Art. 29, Art. 34(1) und (3); Sanktion nach Art. 34-2 a. F.
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Culpability
negligent
Mitigating circumstances
After an increase of 20%, the amount was reduced by 25%, taking into account protective efforts such as an ISMS certification (2020–2023).
Liability of senior managers
Measures against individuals are not set out here.
Published
9 Jan 2025

Original amount 213,000,000 KRW, converted at the ECB reference rate of 8 Jan 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial