Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,030 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Data Protection Commission (PDPC) €31,252 100 % · 2 cases
What for?
by action- Fine €31,252 100 % · 1 case
- Order – 0 % · 1 case
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 1 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €31,252 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
2 cases
31 Oct 2025 Air Sino-Euro Associates Travel Pte. Ltd.Air Sino-Euro: 47,000 SGD – no data protection officer, no internal rules, data leak €31,252
After a cyberattack on the travel agency became public in December 2023, data on 336,759 individuals in its booking system was affected, in some cases including full images of identity cards, passports and birth certificates; part of the data was exfiltrated. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found negligent breaches of the Accountability Obligation – a data protection officer appointed only in April 2024, and apart from the customer-facing privacy policy no internal policies, no complaints process and no information to staff – and of the Protection Obligation, because there were no contracts with the IT vendors covering security tasks, no security reviews and no multi-factor authentication, and the server was still running the unsupported Windows Server 2012. It imposed 47,000 SGD, rejected objections based on COVID-19 losses and comparable cases, and directed among other things policies, security clauses in vendor contracts and a penetration test by a provider licensed by the Cyber Security Agency (CSA).
An outward-facing privacy policy is no substitute for a designated data protection officer or for internal rules that staff know and that apply in day-to-day work.
Internal data protection policies, communicating them to staff, and password rules
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); Section 24 PDPA (Protection Obligation); Section 48J(1)(a) PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Voluntary early admission of the breaches (treated as significantly mitigating) and prompt, effective remediation.
- Published
- 8 Jan 2026
Original amount 47,000 SGD, converted at the ECB reference rate of 31 Oct 2025.
- PDPC – Enforcement Decisions: Breach of the Accountability and Protection Obligations by Air Sino-Euro Associates Travel Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC [5], Air Sino-Euro Associates Travel Pte. Ltd., Case No. DP-2312-C1857 (31.10.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
19 May 2025 The Management Corporation – Strata Title Plan No. 4599 (The Scotts Tower)MCST 4599: directions after refused access request for CCTV footage Order
A person involved in a traffic accident next to the condominium requested access to the CCTV footage in April 2024; the security company could not save it for lack of administrator access, the system overwrote it after 17 days, and the management corporation then refused the request, citing other individuals' data and strata management law. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that a blanket refusal was not justified (other individuals could have been masked) but, as the footage no longer existed, made no finding on the access obligation, and found a negligent breach of the Accountability Obligation: no data protection officer, no data protection policy of its own (only the managing agent's) and no instructions to the managing agent and security company on handling access requests. It directed the corporation to introduce, within 60 days, policies and a procedure for access requests concerning CCTV footage and to pass them on to the managing agent and contractors.
Access requests for CCTV footage need a set procedure that secures the footage before it is automatically overwritten and masks other individuals instead of refusing outright.
Recognise access requests, secure the relevant data immediately and respond in time
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); geprüft auch Sections 21 und 22A PDPA (Auskunft, Aufbewahrung bei Ablehnung)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- The management corporation appointed a data protection officer after the incident.
- Published
- 7 Aug 2025
- PDPC – Enforcement Decisions: Breach of the Accountability Obligation by MCST 4599 (veröffentlicht 07.08.2025) Enforcement database of an authority
- PDPC – Decision 2025 SGPDPC 3, The Management Corporation – Strata Title Plan No. 4599, Case No. DP-2405-C2318 (19.05.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link