Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Anonymised companies 29 cases 19 % · €31m
- Callcenter (anonymisiert) 2 cases 1 % · €259,327
- „Техномат-Меркурий“ ЕООД, ТПКИ „Здравоход“ (Rechtsnachfolger ТПКИ „Комфорт“), „Кавалер Юнион 2001“ ЕООД 1 case 1 % · €1.4m
- 11705580 Canada Inc. 1 case 1 % · €311,294
- 12066424 Canada Inc. 1 case 1 % · €62,555
- 3R Technology UK Ltd 1 case 1 % · €92,442
- A. Tsokkos Hotels Public Limited 1 case 1 % · €16,500
- AFK Letters Co Ltd 1 case 1 % · €108,020
- AG Communications Limited 1 case 1 % · €1.43m
- Air Sino-Euro Associates Travel Pte. Ltd. 1 case 1 % · €31,252
- 115 more115 cases
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €208,955 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
28 Oct 2025 Marina Bay Sands Pte. Ltd.Marina Bay Sands: 315,000 SGD after configuration error in middleware migration €208,955
When API configurations were manually transferred to a new middleware platform (September 2022 to March 2023), a single employee in sole charge omitted an app identifier, so token verification did not apply to the web page of the ArtScience Friends museum programme for at least six months; an attacker exploited this in October 2023 and retrieved data on 665,495 members of the Sands Rewards Lifestyle loyalty programme, which was then offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that the resort had negligently breached the Protection Obligation by relying on this one employee without independent checks or automation. It reduced the provisionally intended 450,000 SGD to 315,000 SGD after the company's representations; no directions were issued because remediation had already been carried out.
Security-critical configuration steps when migrating large data sets must not depend on a single person without independent checks or automation.
Human error in manual IT changes: four-eyes principle and automation
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Section 24 Personal Data Protection Act 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- negligent
- Repeat case
- no
- Mitigating circumstances
- Otherwise adequate security arrangements, containment on the day of discovery, admission under the Expedited Decision Procedure, cooperation and voluntary notification of all affected individuals.
- Published
- 28 Oct 2025
Original amount 315,000 SGD, converted at the ECB reference rate of 28 Oct 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Marina Bay Sands Pte Ltd (veröffentlicht 28.10.2025) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC 6, Marina Bay Sands Pte. Ltd., Case No. DP-2310-C1622 (28.10.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link