Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) €248.8m 100 % · 2 cases
- Korea Fair Trade Commission (KFTC) €283,216 0 % · 2 cases
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 1 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 2 | €241.1m |
| Q3 2026 | 1 | €7.95m |
| Q4 2026 | 0 | – |
4 cases
10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee €240.8m
A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.
When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.
Offboarding: revoking access and keys
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
- Liability of senior managers
- The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
- Published
- 11 Jun 2026
Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.
- PIPC, 심의·의결서 제2026-011-075호 (쿠팡 주식회사), 10.06.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025-조이-0149 Enforcement database of an authority
- PIPC-Pressemitteilung vom 11.06.2026: 쿠팡 및 계열사의 개인정보 유출 및 침해 제재처분 의결 Press release of an authority
- PIPC press release (English), 17.06.2026: The PIPC Sanctions Coupang and CFS Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 €7.95m
Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.
Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.
Credential stuffing and password reuse
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
- Published
- 31 Aug 2026
Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.
- PIPC, 심의·의결서 제2026-017-107호 (㈜지에스리테일), 26.08.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0004 Enforcement database of an authority
- PIPC-Pressemitteilung vom 31.08.2026: ㈜지에스리테일 유출사고에 대해 과징금 128억 3,600만 원, 과태료 300만 원 부과 Press release of an authority
- PIPC press release (English), 03.09.2026: The PIPC Sanctions GS Retail and Three Other Businesses Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
9 Jun 2026 Coupang Corp.Coupang advertised a one-off coupon price as a permanent 'WOW Member Price' €283,216
From 26 August 2020 to 15 May 2022, Coupang advertised a 'WOW Member Price' below the regular selling price in its online shop without disclosing that it included a coupon redeemable only once by new members of its paid WOW subscription. The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) treated the omission of this information as deceptive advertising, issued a corrective order and imposed a fine of KRW 500 million, the statutory maximum fixed-amount fine.
Member prices may only be advertised in the way customers actually receive them repeatedly; one-off discounts must be clearly labelled.
Transparent pricing of membership discounts
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 3 Abs. 1 Nr. 2 Act on Fair Labeling and Advertising (täuschende Werbung)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 9 Jun 2026
Original amount 500,000,000 KRW, converted at the ECB reference rate of 9 Jun 2026.
- KFTC press release (EN), 10 Jun 2026: Sanctions Against Coupang Corp. for Deceptive Advertising of Its 'WOW Member Price' Press release of an authority
- KFTC-Pressemitteilung (KO), 09.06.2026: 와우회원가 광고 관련, 쿠팡(주)의 표시광고법 위반행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF): Art. 3 Abs. 1 Nr. 2 표시광고법, 과징금 5억 원 Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 May 2025 Musinsa Co., Ltd., Shinsung Tongsang Co., Ltd., E-Land World Co., Ltd., ITX Korea Co., Ltd.Greenwashing on leather products: KFTC warns four fashion chains, including ZARA operator Reprimand or warning
The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) found that Musinsa, Shinsung Tongsang, E-Land World and ITX Korea (operator of ZARA in Korea) had advertised leather products, including those made of synthetic materials, with blanket environmental terms such as 'eco' without sufficient evidence, and treated this as false, exaggerated and misleading advertising under the Labeling and Advertising Act. Because all four admitted the violations and corrected them voluntarily, it limited itself to warnings, issued between 2 April and 8 May 2025 (Shinsung Tongsang 2 April, Musinsa 10 April, E-Land World and ITX Korea 8 May); according to the KFTC it was the first sanctioned greenwashing case in the fashion sector.
Environmental claims such as 'eco' need a specific, substantiated reference to the whole product, otherwise they count as misleading.
Substantiated environmental claims in advertising and product labelling
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Art. 3 Abs. 1 Nr. 1 Act on Fair Labeling and Advertising (Labeling and Advertising Act; falsche oder übertriebene Werbung)
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- All four companies admitted the violations and corrected them voluntarily; the KFTC therefore limited itself to warnings.
- Published
- 15 May 2025
- KFTC press release (EN), 15 May 2025: Sanctions Imposed on Four Fashion SPA Business Operators for Violations of the Act on Fair Labeling and Advertising in Relation to Eco-friendliness Press release of an authority
- KFTC-Pressemitteilung (KO), 15.05.2025: 4개 패션 SPA브랜드 사업자의 부당한 광고행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF): Verwarnung (경고) der vier Unternehmen mit Datum je Unternehmen, Art. 3 Abs. 1 Nr. 1 표시광고법 Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link