Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) €27.1m 100 % · 3 cases
What for?
by action- Fine €27.1m 100 % · 3 cases
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 2 | €18.6m |
| Q1 2025 | 1 | €8.51m |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
3 cases
26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing €8.51m
From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.
Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.
Purpose limitation and data misuse by employees
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 27 Mar 2025
Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.
- PIPC, 심의·의결서 제2025-007-021호 (주식회사 우리카드), 26.03.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조일0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.03.2025: 개인정보를 목적 외로 이용한 ㈜우리카드에 과징금 134억 5,100만 원 부과 Press release of an authority
- PIPC press release (English), 28.03.2025: The PIPC Sanctions Woori Card Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
11 Dec 2024 Hyundai Marine & Fire Insurance Co., Ltd.Hyundai Marine & Fire: 6.198 billion KRW for manipulative consent pop-up €4.12m
Hyundai Marine & Fire Insurance showed users of its online car insurance premium calculator who had declined consent to product marketing a further pop-up, swapped the effect of its buttons in July 2022 and mentioned neither the processing of data nor the mandatory information in it; the consents obtained in this way were invalid, and other insurers copied the pattern. The authority imposed a penalty surcharge of 6,198,000,000 KRW and ordered lawful consent, deletion of data from abandoned premium calculations and stronger internal controls with independent powers for the chief privacy officer. In the same session eleven further direct insurers were sanctioned, including AXA General Insurance (2,715,000,000 KRW) and Hana Insurance (273,000,000 KRW). The amount and the facts have not been confirmed against the primary source.
A refusal that is turned into consent by a second pop-up is not valid consent – consent flows belong with the data protection officer before launch.
Dark patterns in marketing consent
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 39-3(1), Art. 31(2), Art. 21(1); Sanktion nach Art. 39-15(1) Nr. 6 a. F.
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- no
- Mitigating circumstances
- Reduction of 50% because no penalty had been imposed in the preceding three years, a further 30% for reasons including cooperation with the investigation and finally 40% following the Commission’s deliberations; increase of 25% because the infringement lasted from July 2022 to September 2023.
- Liability of senior managers
- Marketing and direct sales were able to design the consent flow without any involvement of the chief privacy officer (CPO); the authority found a breach of former Art. 31(2) and ordered that the CPO be given independent powers.
- Published
- 12 Dec 2024
Original amount 6,198,000,000 KRW, converted at the ECB reference rate of 11 Dec 2024.
- PIPC, 심의·의결서 제2024-021-251호 (현대해상화재보험㈜), 11.12.2024 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 202308조일0074~0085 (제2024-021-249~260호) Enforcement database of an authority
- PIPC-Pressemitteilung vom 12.12.2024: 다이렉트 자동차보험 판매 12개 손해보험사 제재처분 Press release of an authority
- PIPC press release (English), 13.12.2024: PIPC Sanctions Twelve General Insurance Companies Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
4 Nov 2024 Meta Platforms, Inc.Meta: 21.62 billion KRW for using sensitive data for advertising without consent €14.4m
Through Facebook profiles and usage behaviour, Meta Platforms, Inc. collected sensitive characteristics of around 980,000 users in Korea – such as religion, political views or same-sex marriage – and made advertising topics built on them available to around 4,000 advertisers without obtaining separate consent. Meta also refused access requests without a legitimate reason and left an unused account-recovery page online through which passwords were reset with forged ID documents and data on ten users was obtained. The authority imposed a penalty surcharge of 21,613,000,000 KRW and an administrative fine of 10,200,000 KRW (21,623,200,000 KRW in total) together with corrective orders.
Advertising audiences that reflect religion, political views or sexual orientation rest on sensitive data and require separate consent.
Sensitive data in advertising audiences
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 23(1), Art. 29, Art. 35(3)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Employees
- 10,000 or more
- Published
- 5 Nov 2024
Original amount 21,623,200,000 KRW, converted at the ECB reference rate of 4 Nov 2024.
- PIPC-Pressemitteilung vom 05.11.2024: 합법 처리근거 없이 민감정보를 수집·활용한 메타 제재 Press release of an authority
- PIPC-Pressemitteilung vom 05.11.2024 (PDF mit Sanktionstabelle) Press release of an authority
- PIPC press release (English), 07.11.2024: PIPC Sanctions against Meta for Collection and Use of Sensitive Data Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link