Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€8.51mTotal of monetary amounts
€8.51mLargest single case: Woori Card Co., Ltd.
€8.51mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20251€8.51m
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing South KoreaMarketing and consent €8.51m

From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.

What organisations can take from it

Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.

Relevance to training and awareness

Purpose limitation and data misuse by employees

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
Liability of senior managers
Measures against individuals are not set out here.
Published
27 Mar 2025

Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial