Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,032 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Data Protection Commission (PDPC) €11,671 100 % · 1 case
What for?
by area of lawAll areas of law
Who?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 1 | €11,671 |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
8 Jan 2026 People Central Pte. Ltd.People Central: 17,500 SGD after attack on HR cloud holding data on 95,000 employees €11,671
The provider of cloud-based HR software received an extortion email in April 2024; an attacker had deleted databases on its AWS servers and likely exfiltrated data, and data allegedly taken was offered for sale on the dark web – data on 95,000 employees of its clients (including identity number, salary, bank account and religion) and on 24,765 emergency contacts and children was put at risk. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation because, despite the HR data entrusted to it by clients, the provider had no web application firewall against existing SQL injection vulnerabilities, remote desktop access open to the internet without two-factor authentication, and vulnerability scans only every two years. It imposed 17,500 SGD, payable in twelve monthly instalments in view of the company's cash flow, and directed among other things a web application firewall, annual penetration tests, two-factor authentication and encryption of all personal data fields.
Cloud providers processing sensitive HR data for clients must secure remote access and have their applications tested regularly for vulnerabilities.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach; payment in instalments in view of cash flow, while a waiver was refused.
- Published
- 8 Jan 2026
Original amount 17,500 SGD, converted at the ECB reference rate of 8 Jan 2026.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by People Central Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 4, People Central Pte. Ltd., Case No. DP-2405-C2330, PDF (ohne Datum) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link