Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,030 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

2cases from 1 jurisdiction
€248,152Total of monetary amounts
€208,955Largest single case: Marina Bay Sands Pte. Ltd.
€124,076Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Data Protection Commission (PDPC) €248,152 100 % · 2 cases

What for?

by action
  1. Fine €248,152 100 % · 2 cases

Who?

by sector

All sectors

  1. Other €208,955 84 % · 1 case
  2. Retail and e-commerce €39,197 16 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20251€39,197
Q3 20250–
Q4 20251€208,955
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

2 cases

28 Oct 2025 Marina Bay Sands Pte. Ltd.Marina Bay Sands: 315,000 SGD after configuration error in middleware migration SingaporeData breaches and data security €208,955

When API configurations were manually transferred to a new middleware platform (September 2022 to March 2023), a single employee in sole charge omitted an app identifier, so token verification did not apply to the web page of the ArtScience Friends museum programme for at least six months; an attacker exploited this in October 2023 and retrieved data on 665,495 members of the Sands Rewards Lifestyle loyalty programme, which was then offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that the resort had negligently breached the Protection Obligation by relying on this one employee without independent checks or automation. It reduced the provisionally intended 450,000 SGD to 315,000 SGD after the company's representations; no directions were issued because remediation had already been carried out.

What organisations can take from it

Security-critical configuration steps when migrating large data sets must not depend on a single person without independent checks or automation.

Relevance to training and awareness

Human error in manual IT changes: four-eyes principle and automation

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Section 24 Personal Data Protection Act 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Repeat case
no
Mitigating circumstances
Otherwise adequate security arrangements, containment on the day of discovery, admission under the Expedited Decision Procedure, cooperation and voluntary notification of all affected individuals.
Published
28 Oct 2025

Original amount 315,000 SGD, converted at the ECB reference rate of 28 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

20 Jun 2025 Goldheart Jewelry Pte. Ltd.Goldheart Jewelry: 58,000 SGD over security patch applied eleven months late SingaporeData breaches and data security €39,197

The jeweller applied a patch released in February 2022 for a known vulnerability (CVE-2022-24086) in the Magento platform of its online shop only in January 2023; through the gap an attacker extracted the customer database with data on 41,379 individuals and posted it on an online forum in May 2023. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a negligent breach of the Protection Obligation because the company relied entirely on its maintenance vendor for patching without directing or monitoring it, and rejected the argument that the vendor had been a data intermediary. Alongside 58,000 SGD (provisionally 64,000 SGD; the finding on credentials stored in plain text was dropped after representations) it directed an external security audit of access controls and the remediation of any gaps.

What organisations can take from it

A company that outsources the maintenance of its web shop remains responsible for patching and must assign responsibilities and monitor implementation.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data breaches and data security
Legal basis
Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Prompt remediation once the incident was known, admission under the Expedited Decision Procedure and cooperation.
Published
8 Jan 2026

Original amount 58,000 SGD, converted at the ECB reference rate of 20 Jun 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial