Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Anonymised companies 27 cases 29 % · €803.7m
- Meta 3 cases 3 % · €997.7m
- Google 2 cases 2 % · €2.95bn
- Meta Platforms Ireland Limited 2 cases 2 % · €251m
- Meta Platforms, Inc. 2 cases 2 % · €14.4m
- A*** GmbH (Werbeagentur, im Bescheid pseudonymisiert) 1 case 1 % · €870
- Agoda Company Pte. Ltd. 1 case 1 % · €1.39m
- Airbnb 1 case 1 % · €64.1m
- Autobutler ApS 1 case 1 % · €938,174
- BT, IMG, ITV, BBC (Sky Kronzeuge) 1 case 1 % · €5.06m
- 51 more51 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €278,912 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers €278,912
In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.
Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.
Malware on workstations and detection of unusual access
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
- Liability of senior managers
- The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
- Published
- 23 Oct 2025
Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.
- PIPC, 심의·의결서 제2025-022-256호 (인크루트(주)), 22.10.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.10.2025: 취업 준비생 개인정보를 유출한 인크루트에 과징금 4.6억원 부과 Press release of an authority
- PIPC press release (English), 24.10.2025: The PIPC Sanctions Incruit over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link