Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by regionAll jurisdictions
What for?
by area of lawAll areas of law
Who?
by company- Google LLC €1.19bn 32 % · 1 case
- Google €890m 24 % · 1 case
- Apple €500m 13 % · 2 cases
- Apple Distribution International Limited; Apple Operations International Limited; Apple Inc. €150m 4 % · 1 case
- Cadence Design Systems Inc. €120.1m 3 % · 1 case
- Comunicaciones Celulares S.A. (TIGO Guatemala) €102.1m 3 % · 1 case
- Apple Inc., Apple Distribution International Ltd, Apple Italia S.r.l. €98.6m 3 % · 1 case
- Anonymised companies €93.2m 2 % · 20 cases
- SK Telecom Co., Ltd. €83.2m 2 % · 1 case
- Telefónica Venezolana C.A. €79.1m 2 % · 1 case
- 84 more€433.3m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | €11,664 |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
3 Jul 2025 Ezynetic Pte. Ltd.Ezynetic: 17,500 SGD after ransomware at IT service provider for moneylenders €11,664
The SaaS provider operates a system for licensed moneylenders that is linked to the Moneylenders Credit Bureau and into which its clients enter data on loan applicants and borrowers; in June 2024 an attacker used a vulnerable web application to take over the SQL server's system administrator account, which was protected only by an easily guessed password, deleted databases and exfiltrated data on 190,589 individuals including credit report data, which was offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation (inadequate access control, no vulnerability assessments or penetration tests) and, given the company's role as a provider processing client data entrusted to it, considered a fine of 17,500 SGD appropriate; it rejected the request for a waiver or reduction. In addition, the company must obtain the Cyber Trust mark certification of the Cyber Security Agency of Singapore (CSA) for its new network within nine months.
Privileged default accounts such as a database server administrator must be disabled or secured with strong passwords and additional controls, and systems must be tested regularly for vulnerabilities.
Strong passwords and protection of privileged administrator accounts
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
- Published
- 3 Jul 2025
Original amount 17,500 SGD, converted at the ECB reference rate of 3 Jul 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Ezynetic (veröffentlicht 03.07.2025) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 2, Ezynetic Pte. Ltd., Case No. DP-2406-C2585, PDF (ohne Datum) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link