Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€141,669Total of monetary amounts
€141,669Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Information Protection Commission (PIPC, 개인정보보호위원회) €141,669 100 % · 1 case

What for?

by area of law

All areas of law

  1. Data protection €141,669 100 % · 1 case

Who?

by company
  1. National Court Administration (법원행정처) €141,669 100 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20251€141,669
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

8 Jan 2025 National Court Administration (법원행정처)Court administration: 213 million KRW after theft of 1,014 GB of case files South KoreaData breaches and data security €141,669

Through a port between the internal and external networks that had been opened for convenience, attackers entered the e-litigation server of the National Court Administration and took 1,014 GB of case documents; the 4.7 GB that were recovered contained data on 17,998 people, including resident registration numbers. The authority criticised unencrypted documents, unchanged, easily guessed initial passwords on administrator accounts, missing security software on one server and a report only in December 2023, although there had been indications of the leak since April 2023. It imposed a penalty surcharge of 207,000,000 KRW and an administrative fine of 6,000,000 KRW (213,000,000 KRW in total), recommended disciplinary action and improvements and is publishing the imposition of the administrative fine on its website for one year.

What organisations can take from it

Public bodies too must change initial passwords, close unnecessary network crossings and report a detected data leak without delay.

Relevance to training and awareness

Initial passwords and timely incident reporting

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 24(3), Art. 24-2(2), Art. 29, Art. 34(1) und (3); Sanktion nach Art. 34-2 a. F.
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Culpability
negligent
Mitigating circumstances
After an increase of 20%, the amount was reduced by 25%, taking into account protective efforts such as an ISMS certification (2020–2023).
Liability of senior managers
Measures against individuals are not set out here.
Published
9 Jan 2025

Original amount 213,000,000 KRW, converted at the ECB reference rate of 8 Jan 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial