Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€31,252Total of monetary amounts
€31,252Largest single case: Air Sino-Euro Associates Travel Pte. Ltd.
€31,252Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20251€31,252
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

31 Oct 2025 Air Sino-Euro Associates Travel Pte. Ltd.Air Sino-Euro: 47,000 SGD – no data protection officer, no internal rules, data leak SingaporeData subject rights and transparency €31,252

After a cyberattack on the travel agency became public in December 2023, data on 336,759 individuals in its booking system was affected, in some cases including full images of identity cards, passports and birth certificates; part of the data was exfiltrated. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found negligent breaches of the Accountability Obligation – a data protection officer appointed only in April 2024, and apart from the customer-facing privacy policy no internal policies, no complaints process and no information to staff – and of the Protection Obligation, because there were no contracts with the IT vendors covering security tasks, no security reviews and no multi-factor authentication, and the server was still running the unsupported Windows Server 2012. It imposed 47,000 SGD, rejected objections based on COVID-19 losses and comparable cases, and directed among other things policies, security clauses in vendor contracts and a penetration test by a provider licensed by the Cyber Security Agency (CSA).

What organisations can take from it

An outward-facing privacy policy is no substitute for a designated data protection officer or for internal rules that staff know and that apply in day-to-day work.

Relevance to training and awareness

Internal data protection policies, communicating them to staff, and password rules

Missing or inadequate training played a role in the decision.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); Section 24 PDPA (Protection Obligation); Section 48J(1)(a) PDPA (Financial Penalty); Section 48I PDPA (Directions)
Action
Fine
Status of proceedings
unknown
Sector
Other
Culpability
negligent
Mitigating circumstances
Voluntary early admission of the breaches (treated as significantly mitigating) and prompt, effective remediation.
Published
8 Jan 2026

Original amount 47,000 SGD, converted at the ECB reference rate of 31 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial