Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
€249mTotal of monetary amounts (3 cases with an amount)
€240.8mLargest single case: Coupang Corp.
€7.95mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Korea Fair Trade Commission (KFTC) 2 cases 50 % · €283,216
  2. Personal Information Protection Commission (PIPC, 개인정보보호위원회) 2 cases 50 % · €248.8m

What for?

by area of law

All areas of law

  1. Data protection 2 cases 50 % · €248.8m
  2. Environment and sustainability 1 case 25 % ·
  3. Consumer protection and online retail 1 case 25 % · €283,216

Who?

by company
  1. Coupang Corp. 2 cases 50 % · €241.1m
  2. GS Retail Co., Ltd. 1 case 25 % · €7.95m
  3. Musinsa Co., Ltd., Shinsung Tongsang Co., Ltd., E-Land World Co., Ltd., ITX Korea Co., Ltd. 1 case 25 % ·

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20251–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20262€241.1m
Q3 20261€7.95m
Q4 20260–

4 cases

26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 South KoreaData breaches and data security €7.95m

Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.

What organisations can take from it

Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.

Relevance to training and awareness

Credential stuffing and password reuse

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
Published
31 Aug 2026

Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee South KoreaData breaches and data security €240.8m

A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.

What organisations can take from it

When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.

Relevance to training and awareness

Offboarding: revoking access and keys

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
Liability of senior managers
The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
Published
11 Jun 2026

Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

9 Jun 2026 Coupang Corp.Coupang advertised a one-off coupon price as a permanent 'WOW Member Price' South KoreaMisleading advertising and pricing €283,216

From 26 August 2020 to 15 May 2022, Coupang advertised a 'WOW Member Price' below the regular selling price in its online shop without disclosing that it included a coupon redeemable only once by new members of its paid WOW subscription. The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) treated the omission of this information as deceptive advertising, issued a corrective order and imposed a fine of KRW 500 million, the statutory maximum fixed-amount fine.

What organisations can take from it

Member prices may only be advertised in the way customers actually receive them repeatedly; one-off discounts must be clearly labelled.

Relevance to training and awareness

Transparent pricing of membership discounts

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 3 Abs. 1 Nr. 2 Act on Fair Labeling and Advertising (täuschende Werbung)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
9 Jun 2026

Original amount 500,000,000 KRW, converted at the ECB reference rate of 9 Jun 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 May 2025 Musinsa Co., Ltd., Shinsung Tongsang Co., Ltd., E-Land World Co., Ltd., ITX Korea Co., Ltd.Greenwashing on leather products: KFTC warns four fashion chains, including ZARA operator South KoreaMisleading environmental and sustainability claims Reprimand or warning

The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) found that Musinsa, Shinsung Tongsang, E-Land World and ITX Korea (operator of ZARA in Korea) had advertised leather products, including those made of synthetic materials, with blanket environmental terms such as 'eco' without sufficient evidence, and treated this as false, exaggerated and misleading advertising under the Labeling and Advertising Act. Because all four admitted the violations and corrected them voluntarily, it limited itself to warnings, issued between 2 April and 8 May 2025 (Shinsung Tongsang 2 April, Musinsa 10 April, E-Land World and ITX Korea 8 May); according to the KFTC it was the first sanctioned greenwashing case in the fashion sector.

What organisations can take from it

Environmental claims such as 'eco' need a specific, substantiated reference to the whole product, otherwise they count as misleading.

Relevance to training and awareness

Substantiated environmental claims in advertising and product labelling

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Environment and sustainability · Misleading environmental and sustainability claims
Legal basis
Art. 3 Abs. 1 Nr. 1 Act on Fair Labeling and Advertising (Labeling and Advertising Act; falsche oder übertriebene Werbung)
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
All four companies admitted the violations and corrected them voluntarily; the KFTC therefore limited itself to warnings.
Published
15 May 2025

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial