Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) €141,669 100 % · 1 case
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 1 | €141,669 |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
8 Jan 2025 National Court Administration (법원행정처)Court administration: 213 million KRW after theft of 1,014 GB of case files €141,669
Through a port between the internal and external networks that had been opened for convenience, attackers entered the e-litigation server of the National Court Administration and took 1,014 GB of case documents; the 4.7 GB that were recovered contained data on 17,998 people, including resident registration numbers. The authority criticised unencrypted documents, unchanged, easily guessed initial passwords on administrator accounts, missing security software on one server and a report only in December 2023, although there had been indications of the leak since April 2023. It imposed a penalty surcharge of 207,000,000 KRW and an administrative fine of 6,000,000 KRW (213,000,000 KRW in total), recommended disciplinary action and improvements and is publishing the imposition of the administrative fine on its website for one year.
Public bodies too must change initial passwords, close unnecessary network crossings and report a detected data leak without delay.
Initial passwords and timely incident reporting
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 24(3), Art. 24-2(2), Art. 29, Art. 34(1) und (3); Sanktion nach Art. 34-2 a. F.
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Culpability
- negligent
- Mitigating circumstances
- After an increase of 20%, the amount was reduced by 25%, taking into account protective efforts such as an ISMS certification (2020–2023).
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 9 Jan 2025
Original amount 213,000,000 KRW, converted at the ECB reference rate of 8 Jan 2025.
- PIPC, 심의·의결서 제2025-001-001호 (법원행정처), 08.01.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2023조총0053 Enforcement database of an authority
- PIPC-Pressemitteilung vom 09.01.2025: 주민등록번호 유출과 안전조치 의무 위반한 법원행정처 제재 Press release of an authority
- PIPC press release (English), 10.01.2025: PIPC Sanctions National Court Administration Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link