Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Anonymised companies 28 cases 20 % · €565.8m
- AliExpress 2 cases 1 % · €550m
- Coupang Corp. 2 cases 1 % · €241.1m
- "MAXIMA Latvija" SIA 1 case 1 % · €1.87m
- „Билла България“ ЕООД (Billa Bulgaria) 1 case 1 % · €207,555
- „Кауфланд България ЕООД енд Ко“ КД 1 case 1 % · €255,650
- 1-800-Flowers.com, Inc. 1 case 1 % · €328,429
- 13859380 Canada Inc. (Crane Supply) 1 case 1 % ·
- Adidas (Sportartikelhersteller) 1 case 1 % ·
- Adidas America Inc. 1 case 1 % · €207,249
- 103 more103 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 1 | €39,197 |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
20 Jun 2025 Goldheart Jewelry Pte. Ltd.Goldheart Jewelry: 58,000 SGD over security patch applied eleven months late €39,197
The jeweller applied a patch released in February 2022 for a known vulnerability (CVE-2022-24086) in the Magento platform of its online shop only in January 2023; through the gap an attacker extracted the customer database with data on 41,379 individuals and posted it on an online forum in May 2023. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a negligent breach of the Protection Obligation because the company relied entirely on its maintenance vendor for patching without directing or monitoring it, and rejected the argument that the vendor had been a data intermediary. Alongside 58,000 SGD (provisionally 64,000 SGD; the finding on credentials stored in plain text was dropped after representations) it directed an external security audit of access controls and the remediation of any gaps.
A company that outsources the maintenance of its web shop remains responsible for patching and must assign responsibilities and monitor implementation.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Mitigating circumstances
- Prompt remediation once the incident was known, admission under the Expedited Decision Procedure and cooperation.
- Published
- 8 Jan 2026
Original amount 58,000 SGD, converted at the ECB reference rate of 20 Jun 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Goldheart Jewelry Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC 4, Goldheart Jewelry Pte. Ltd., Case No. DP-2305-C1061 (20.06.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link