Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,030 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Data Protection Commission (PDPC) €40,972 100 % · 5 cases
What for?
by action- Fine €40,972 100 % · 4 cases
- Order – 0 % · 1 case
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 1 | €11,851 |
| Q3 2025 | 1 | €11,664 |
| Q4 2025 | 1 | €5,786 |
| Q1 2026 | 1 | €11,671 |
| Q2 2026 | 1 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
5 cases
1 Apr 2026 The Management Corporation – Strata Title Plan No. 4869 (Riverfront Residences)MCST 4869: directions over lack of data protection instructions to managing agent Order
The management corporation of the Riverfront Residences condominium had not designated a data protection officer until March 2025, had no data protection policies of its own and had given its managing agent, which acted for it as a data intermediary, no instructions on handling personal data; in April 2025 an employee of the managing agent mistakenly sent the names, addresses and maintenance fee details of two owners to another owner. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found breaches of the Accountability Obligation and the Protection Obligation; by contrast, it found no breach in the circulation of a requisition for an extraordinary general meeting bearing the names and signatures of 303 owners, because strata management law prevailed. It directed the corporation to introduce, within 90 days, policies and procedures for the processing of data by the managing agent and to communicate them to it; the managing agent itself had given a voluntary undertaking.
Anyone who outsources management to a service provider remains responsible and needs their own data protection officer, their own policies and specific instructions to the provider.
Check recipients before sending, protect sensitive attachments and give service providers clear instructions
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Sections 11(3) und 12(a) PDPA 2012 (Accountability Obligation); Section 24 i. V. m. Section 4(3) PDPA (Protection Obligation bei Einsatz eines Data Intermediary)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Published
- 7 May 2026
- PDPC – Enforcement Decisions: Breach of the Accountability and Protection Obligations by MCST 4869 (veröffentlicht 07.05.2026) Enforcement database of an authority
- PDPC – Decision [2026] SGPDPC 1, The Management Corporation – Strata Title Plan No. 4869, Case No. DP-2503-C3469 (01.04.2026), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 Jan 2026 People Central Pte. Ltd.People Central: 17,500 SGD after attack on HR cloud holding data on 95,000 employees €11,671
The provider of cloud-based HR software received an extortion email in April 2024; an attacker had deleted databases on its AWS servers and likely exfiltrated data, and data allegedly taken was offered for sale on the dark web – data on 95,000 employees of its clients (including identity number, salary, bank account and religion) and on 24,765 emergency contacts and children was put at risk. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation because, despite the HR data entrusted to it by clients, the provider had no web application firewall against existing SQL injection vulnerabilities, remote desktop access open to the internet without two-factor authentication, and vulnerability scans only every two years. It imposed 17,500 SGD, payable in twelve monthly instalments in view of the company's cash flow, and directed among other things a web application firewall, annual penetration tests, two-factor authentication and encryption of all personal data fields.
Cloud providers processing sensitive HR data for clients must secure remote access and have their applications tested regularly for vulnerabilities.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach; payment in instalments in view of cash flow, while a waiver was refused.
- Published
- 8 Jan 2026
Original amount 17,500 SGD, converted at the ECB reference rate of 8 Jan 2026.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by People Central Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 4, People Central Pte. Ltd., Case No. DP-2405-C2330, PDF (ohne Datum) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
29 Dec 2025 SESAMi (Singapore) Pte Ltd; Abecha Pte LtdSESAMi: 8,750 SGD after ransomware attack on network drive shared with its subsidiary €5,786
In August 2024 an attacker encrypted a network drive shared by SESAMi and its subsidiary Abecha holding payment data (including full credit card numbers and bank account details) of around 20,471 customers of the subsidiary's fuel fleet discount programme and of up to 18,837 individuals from registrations for SESAMi's B2B platform; exfiltration could not be established. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) classified SESAMi, which ran the network for the subsidiary without a written contract, as a data intermediary in that respect and found a negligent breach of the Protection Obligation by SESAMi (including outdated firewall and VPN firmware, no patch management and unenforced password and MFA rules), and likewise by Abecha, which as controller had taken no steps to ensure adequate security at SESAMi. SESAMi received 8,750 SGD and directions, while Abecha, as the controller, received directions only, including setting out roles and data protection duties within the group in writing.
Even within a group, processing data for another group company requires a written allocation of roles and duties, and the responsible company must actively demand adequate security from its service provider.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation); Section 4(3) PDPA (Pflichten bei Einsatz eines Data Intermediary); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Cooperation, prompt and effective remediation, admission under the Expedited Decision Procedure; for Abecha also lower culpability owing to its limited autonomy as a wholly owned subsidiary, one of the reasons for not imposing a fine on it.
- Published
- 26 Feb 2026
Original amount 8,750 SGD, converted at the ECB reference rate of 29 Dec 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by SESAMi (Singapore) Pte Ltd and Abecha Pte Ltd (veröffentlicht 26.02.2026) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 1, SESAMi (Singapore) Pte Ltd / Abecha Pte Ltd, Case No. DP-2408-C2786 (29.12.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
3 Jul 2025 Ezynetic Pte. Ltd.Ezynetic: 17,500 SGD after ransomware at IT service provider for moneylenders €11,664
The SaaS provider operates a system for licensed moneylenders that is linked to the Moneylenders Credit Bureau and into which its clients enter data on loan applicants and borrowers; in June 2024 an attacker used a vulnerable web application to take over the SQL server's system administrator account, which was protected only by an easily guessed password, deleted databases and exfiltrated data on 190,589 individuals including credit report data, which was offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation (inadequate access control, no vulnerability assessments or penetration tests) and, given the company's role as a provider processing client data entrusted to it, considered a fine of 17,500 SGD appropriate; it rejected the request for a waiver or reduction. In addition, the company must obtain the Cyber Trust mark certification of the Cyber Security Agency of Singapore (CSA) for its new network within nine months.
Privileged default accounts such as a database server administrator must be disabled or secured with strong passwords and additional controls, and systems must be tested regularly for vulnerabilities.
Strong passwords and protection of privileged administrator accounts
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
- Published
- 3 Jul 2025
Original amount 17,500 SGD, converted at the ECB reference rate of 3 Jul 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Ezynetic (veröffentlicht 03.07.2025) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 2, Ezynetic Pte. Ltd., Case No. DP-2406-C2585, PDF (ohne Datum) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
7 Apr 2025 Singapore Data Hub Pte LtdSingapore Data Hub: 17,500 SGD after SQL injection attacks on point-of-sale software €11,851
The provider of point-of-sale and CRM software for small and medium-sized enterprises reported two attacks in 2024 in which perpetrators used SQL injection, among other methods, to extract files with data on a total of 698,112 individuals, including health information (skin conditions and treatments) of 9,122 individuals; the data was likely posted on a hacking forum. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) stressed that the SaaS provider holds large volumes of data on behalf of its clients and found a breach of the Protection Obligation: publicly accessible servers, no network firewall, no security testing before releases, unsupported operating system and PHP versions, and credentials left unprotected in source code and configuration files. Alongside 17,500 SGD it directed a package of measures ranging from network segmentation and patch management to vulnerability assessments and penetration tests at least once a year.
SaaS providers holding customer data on a large scale must test new releases for security vulnerabilities before going live and consistently update or decommission legacy systems.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
- Published
- 8 Jan 2026
Original amount 17,500 SGD, converted at the ECB reference rate of 7 Apr 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Singapore Data Hub Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC 2, Singapore Data Hub Pte Ltd, Case No. DP-2406-C2514 (07.04.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link