Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,019 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Korea Fair Trade Commission (KFTC) €158.2m 73 % · 1 case
- Korea Financial Intelligence Unit (KoFIU) €42.1m 19 % · 2 cases
- Personal Information Protection Commission (PIPC, 개인정보보호위원회) €16.6m 8 % · 3 cases
- Financial Supervisory Service (FSS) €45,990 0 % · 1 case
What for?
by area of lawAll areas of law
Who?
by company- KB Kookmin Bank, Shinhan Bank, Woori Bank, Hana Bank €158.2m 73 % · 1 case
- Bithumb Co., Ltd. €21.5m 10 % · 1 case
- Dunamu Inc. €20.6m 9 % · 1 case
- Woori Card Co., Ltd. €8.51m 4 % · 1 case
- Hyundai Marine & Fire Insurance Co., Ltd. €4.12m 2 % · 1 case
- Kakaopay Corp. €3.99m 2 % · 1 case
- PFC Technologies Co., Ltd. (vormals PeopleFund Company) €45,990 0 % · 1 case
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €4.12m |
| Q1 2025 | 2 | €12.5m |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €20.6m |
| Q1 2026 | 2 | €179.7m |
| Q2 2026 | 0 | – |
| Q3 2026 | 1 | €45,990 |
| Q4 2026 | 0 | – |
7 cases
17 Sep 2026 PFC Technologies Co., Ltd. (vormals PeopleFund Company)P2P lending platform shared customer data without consent: FSS sanctions PFC €45,990
According to the sanctions disclosure of the Financial Supervisory Service (FSS, Korea's financial supervisor), the online lending platform PFC Technologies transferred the resident registration numbers of 8,497 customers to a third party without their consent on 28 September 2022 in order to calculate the error rate of a new service for mortgage customers, and received credit information on the same customers from that third party, likewise without consent (such as the address and official value of their properties); in addition, when the inspection began it had not implemented password rules against easily guessed numbers. The sanction of 17 September 2026 comprises an institutional warning, an administrative fine (과태료) of KRW 24 million and a penalty surcharge (과징금) of KRW 49 million, KRW 73 million in total.
Even for internal tests and quality measurements, customer data may only be passed to third parties with consent or a clear legal basis.
Consent for sharing credit data and password rules
- Authority / court
- Financial Supervisory Service (FSS)
- Area of law
- Data protection
- Legal basis
- Art. 19, 32 und 34 Credit Information Use and Protection Act; Art. 16, 28 und 29 Durchführungsverordnung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 17 Sep 2026
Original amount 73,000,000 KRW, converted at the ECB reference rate of 17 Sep 2026.
- FSS 제재내용 공개 (Sanktionsveröffentlichung), 피에프씨테크놀로지스 주식회사, 17.09.2026 Enforcement database of an authority
- FSS-PDF: 피에프씨테크놀로지스 제재내용 공개안 Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
17 Mar 2026 Bithumb Co., Ltd.Bithumb: partial suspension and KRW 36.9bn fine for anti-money laundering breaches €21.5m
The KoFIU (Korea Financial Intelligence Unit) found that the crypto exchange Bithumb had processed 45,772 transfers of crypto assets with 18 virtual asset service providers that had not complied with their reporting obligation between August 2022 and April 2025, and had breached customer identification duties and the associated transaction restrictions in large numbers; there were also shortcomings in suspicious transaction reporting, record keeping and the risk assessment of new products. On 17 March 2026 it ordered a six-month partial suspension of business (no transfers of crypto assets for new customers from 27 March to 26 September 2026) and imposed a fine of KRW 36,873.5 million. The amount and the facts have not been confirmed against the primary source.
Crypto exchanges must check counterparties for deposits and withdrawals against the register of reported providers before allowing transfers.
Counterparty checks and customer identification for crypto transfers
- Authority / court
- Korea Financial Intelligence Unit (KoFIU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 4, 5, 5-2, 5-4 und 8 Act on Reporting and Using Specified Financial Transaction Information; Art. 9, 10-6, 10-9 und 10-20 Durchführungsverordnung (Teilsperre wegen Art. 8 i. V. m. Art. 10-20 DVO: Geschäfte mit nicht gemeldeten Anbietern)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 17 Mar 2026
Original amount 36,873,500,000 KRW, converted at the ECB reference rate of 17 Mar 2026.
- KoFIU 제재공시, Detailseite Eintrag Nr. 119 (17.03.2026) mit PDF (주)빗썸 제재내용 공개안 Enforcement database of an authority
- KoFIU 제재공시 (Sanktionsveröffentlichungen), Eintrag Nr. 119 vom 17.03.2026: (주)빗썸 제재내용 공개안 (PDF), dazu Nr. 118 개선조치 요구사항 Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
21 Jan 2026 KB Kookmin Bank, Shinhan Bank, Woori Bank, Hana BankFour major banks exchanged loan-to-value ratios: KRW 272bn fine €158.2m
According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), the four banks exchanged their complete loan-to-value (LTV) ratios for mortgage lending over a long period, between 736 and 7,500 individual values per bank, and adjusted their own ratios accordingly; only conduct from December 2021, when the express prohibition of anti-competitive information exchange entered into force, was pursued. The KFTC issued cease-and-desist orders and fines totalling KRW 272,014 million (Kookmin KRW 69,747 million, Shinhan KRW 63,801 million, Woori KRW 51,535 million, Hana KRW 86,931 million), the first application of that provision.
Exchanging individual contract terms with competitors is a stand-alone competition law infringement even without price fixing.
Information exchange with competitors
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 40 Abs. 1 Nr. 9 MRFTA i. V. m. Art. 44 Abs. 2 Nr. 3 Durchführungsverordnung (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 21 Jan 2026
Original amount 272,014,000,000 KRW, converted at the ECB reference rate of 21 Jan 2026.
- KFTC press release (EN), 22 Jan 2026: KFTC Sanctions Four Major Commercial Banks for Collusive Information Exchange Press release of an authority
- KFTC-Pressemitteilung (KO), 21.01.2026: 4대 시중은행의 정보교환의 담합 행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Bußgeldtabelle je Bank und Rechtsgrundlage Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
9 Dec 2025 Dunamu Inc.Upbit operator Dunamu: KRW 35.2bn fine for customer due diligence failures €20.6m
The KoFIU (Korea Financial Intelligence Unit) found that Dunamu, operator of the crypto exchange Upbit, had failed to identify customers with due care in 5,324,165 cases between October 2021 and October 2024, for instance where identity documents could not be verified, were mere copies or photos, or where addresses were blank or implausible, and had nevertheless allowed transactions in 3,331,570 of these cases. In addition, it failed to file suspicious transaction reports on 15 customers linked to warrant applications by investigative authorities, and its monitoring system did not detect unusual patterns such as large crypto deposits followed by sale and withdrawal; KoFIU imposed a fine of KRW 35,215.6 million on 9 December 2025. The amount and the facts have not been confirmed against the primary source.
Digital onboarding processes need checks that reliably reject copies of identity documents and implausible addresses before trading is possible.
Customer identification (KYC) at crypto exchanges
- Authority / court
- Korea Financial Intelligence Unit (KoFIU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 4, 5, 5-2 und 8 Act on Reporting and Using Specified Financial Transaction Information; Art. 9, 10-4, 10-6 und 10-20 Durchführungsverordnung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 9 Dec 2025
Original amount 35,215,600,000 KRW, converted at the ECB reference rate of 9 Dec 2025.
- KoFIU 제재공시, Detailseite Eintrag Nr. 108 (09.12.2025) mit PDF 두나무(주) 제재내용 공개안 Enforcement database of an authority
- KoFIU 제재공시 (Sanktionsveröffentlichungen), Eintrag Nr. 108 vom 09.12.2025: 두나무(주) 제재내용 공개안 (PDF) Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing €8.51m
From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.
Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.
Purpose limitation and data misuse by employees
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 27 Mar 2025
Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.
- PIPC, 심의·의결서 제2025-007-021호 (주식회사 우리카드), 26.03.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조일0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.03.2025: 개인정보를 목적 외로 이용한 ㈜우리카드에 과징금 134억 5,100만 원 부과 Press release of an authority
- PIPC press release (English), 28.03.2025: The PIPC Sanctions Woori Card Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
22 Jan 2025 Kakaopay Corp.Kakao Pay: 5.968 billion KRW for transferring user data to Alipay without consent €3.99m
Kakaopay Corp. transferred data on all users three times in 2018 and, from June 2019 to May 2024, data on around 40 million users every day without consent to Alipay in Singapore, which used it to calculate for Apple a score for the likelihood of insufficient funds on bundled App Store payments (NSF score). The authority treated this as an unlawful transfer abroad, imposed a penalty surcharge of 5,968,000,000 KRW and ordered remediation and publication of the decision on the company’s website. In separate decisions on the same day Apple received a penalty surcharge of 2,405,000,000 KRW and an administrative fine of 2,200,000 KRW, and Alipay was ordered to delete the scoring model.
Anyone passing customer data to a partner’s foreign service provider must check whether this is a transfer requiring consent and limit the data to what is necessary.
Data sharing with partners’ foreign service providers
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · International data transfers
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 28-8(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 30% for completed remediation, cooperation and ISMS-P certification; increase of 50% because the infringement lasted more than two years (June 2019 to May 2024).
- Published
- 23 Jan 2025
Original amount 5,968,000,000 KRW, converted at the ECB reference rate of 22 Jan 2025.
- PIPC, 심의·의결서 제2025-001-002호 (㈜카카오페이), 22.01.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조삼0005 등 3건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.01.2025: 개인정보 무단 국외 이전한 카카오페이·애플에 과징금·과태료 부과 Press release of an authority
- PIPC press release (English), 31.01.2025: The PIPC Sanctions Kakao Pay and Apple Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
11 Dec 2024 Hyundai Marine & Fire Insurance Co., Ltd.Hyundai Marine & Fire: 6.198 billion KRW for manipulative consent pop-up €4.12m
Hyundai Marine & Fire Insurance showed users of its online car insurance premium calculator who had declined consent to product marketing a further pop-up, swapped the effect of its buttons in July 2022 and mentioned neither the processing of data nor the mandatory information in it; the consents obtained in this way were invalid, and other insurers copied the pattern. The authority imposed a penalty surcharge of 6,198,000,000 KRW and ordered lawful consent, deletion of data from abandoned premium calculations and stronger internal controls with independent powers for the chief privacy officer. In the same session eleven further direct insurers were sanctioned, including AXA General Insurance (2,715,000,000 KRW) and Hana Insurance (273,000,000 KRW). The amount and the facts have not been confirmed against the primary source.
A refusal that is turned into consent by a second pop-up is not valid consent – consent flows belong with the data protection officer before launch.
Dark patterns in marketing consent
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법, frühere Fassung) Art. 39-3(1), Art. 31(2), Art. 21(1); Sanktion nach Art. 39-15(1) Nr. 6 a. F.
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- no
- Mitigating circumstances
- Reduction of 50% because no penalty had been imposed in the preceding three years, a further 30% for reasons including cooperation with the investigation and finally 40% following the Commission’s deliberations; increase of 25% because the infringement lasted from July 2022 to September 2023.
- Liability of senior managers
- Marketing and direct sales were able to design the consent flow without any involvement of the chief privacy officer (CPO); the authority found a breach of former Art. 31(2) and ordered that the CPO be given independent powers.
- Published
- 12 Dec 2024
Original amount 6,198,000,000 KRW, converted at the ECB reference rate of 11 Dec 2024.
- PIPC, 심의·의결서 제2024-021-251호 (현대해상화재보험㈜), 11.12.2024 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 202308조일0074~0085 (제2024-021-249~260호) Enforcement database of an authority
- PIPC-Pressemitteilung vom 12.12.2024: 다이렉트 자동차보험 판매 12개 손해보험사 제재처분 Press release of an authority
- PIPC press release (English), 13.12.2024: PIPC Sanctions Twelve General Insurance Companies Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link