Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) 2 cases 50 % · €115.8m
- Korea Fair Trade Commission (KFTC) 1 case 25 % · €72.1m
- Korea Media and Communications Commission (KMCC, 방송미디어통신위원회) 1 case 25 % · €370,997
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 1 | €72.1m |
| Q2 2025 | 0 | – |
| Q3 2025 | 1 | €83.2m |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | €370,997 |
| Q3 2026 | 1 | €32.7m |
| Q4 2026 | 0 | – |
4 cases
29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells €32.7m
Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.
Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.
Lost network devices and certificate management
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
- Published
- 30 Jul 2026
Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.
- PIPC, 심의·의결서 제2026-015-093호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, 심의·의결서 제2026-015-094호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0113-02 등 2건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 30.07.2026: ‘㈜KT의 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 07.08.2026: The PIPC Sanctions KT Corporation for Data Breaches Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 May 2026 KT CorporationKT: 640 million KRW for cancelled Galaxy S25 pre-orders and false notices €370,997
In its own online shop for Galaxy S25 pre-orders, KT Corporation stated that benefits would apply unless the end of the promotion was shown, but then limited them to the first 1,000 orders and unilaterally cancelled 7,127 pre-orders that had come in via a YouTube channel and Genie TV and had already been fully completed. The authority regarded this as false information on key terms and an unjustified refusal to conclude contracts under the Telecommunications Business Act (전기통신사업법), imposed a fine of 640,000,000 KRW and ordered KT to show additional pre-order benefits clearly in future.
Promotion terms such as quotas must be visible before the contract is concluded – cancelling completed orders afterwards is no solution.
- Authority / court
- Korea Media and Communications Commission (KMCC, 방송미디어통신위원회)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Telecommunications Business Act (전기통신사업법) Art. 50(1) Nr. 5 und Nr. 5-2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 8 May 2026
Original amount 640,000,000 KRW, converted at the ECB reference rate of 8 May 2026.
- KMCC-Pressemitteilung vom 08.05.2026: ‘케이티(KT)’ 사전예약 이벤트 취소, 과징금 부과 Press release of an authority
- KMCC-Pressemitteilung vom 08.05.2026 (PDF) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers €83.2m
Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.
Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.
Undetected malware in core systems
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
- Liability of senior managers
- There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
- Published
- 28 Aug 2025
Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.
- PIPC, 심의·의결서 제2025-018-243호 (에스케이텔레콤 주식회사), 27.08.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0056 Enforcement database of an authority
- PIPC-Pressemitteilung vom 28.08.2025: ‘SK텔레콤 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 03.09.2025: The PIPC Sanctions SKT over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
12 Mar 2025 SK Telecom Co., Ltd., KT Co., Ltd., LG Uplus Co., Ltd.Mobile cartel: SK Telecom, KT and LG Uplus jointly steered switching figures €72.1m
According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), the three mobile network operators agreed in November 2015 to balance net gains and losses of new subscribers porting their numbers so that they would not concentrate on one operator, and implemented this until the end of September 2022 by coordinating their sales incentives for dealers with one another; they exchanged the information in a joint market monitoring group with the industry association KAIT. The KFTC issued cease-and-desist orders and provisionally set fines totalling KRW 114,026 million (SK Telecom KRW 42,662 million, KT KRW 33,029 million, LG Uplus KRW 38,334 million).
Self-regulatory bodies must not become a forum in which competitors coordinate customer gains and terms.
Cartel risks in industry bodies and self-regulation
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 40 Abs. 1 Nr. 3 MRFTA (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 12 Mar 2025
Original amount 114,026,000,000 KRW, converted at the ECB reference rate of 12 Mar 2025.
- KFTC press release (EN), 13 Mar 2025: KFTC Sanctions Three Telecommunication Companies for Collusion in Mobile Number Portability New Subscriber Adjustments Press release of an authority
- KFTC-Pressemitteilung (KO), 12.03.2025: 이동통신 3사의 담합행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Bußgeldtabelle je Unternehmen und Rechtsgrundlage Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link