Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,030 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€5,786Total of monetary amounts
€5,786Largest single case: SESAMi (Singapore) Pte Ltd; Abecha Pte Ltd
€5,786Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20251€5,786
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

29 Dec 2025 SESAMi (Singapore) Pte Ltd; Abecha Pte LtdSESAMi: 8,750 SGD after ransomware attack on network drive shared with its subsidiary SingaporeData processors €5,786

In August 2024 an attacker encrypted a network drive shared by SESAMi and its subsidiary Abecha holding payment data (including full credit card numbers and bank account details) of around 20,471 customers of the subsidiary's fuel fleet discount programme and of up to 18,837 individuals from registrations for SESAMi's B2B platform; exfiltration could not be established. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) classified SESAMi, which ran the network for the subsidiary without a written contract, as a data intermediary in that respect and found a negligent breach of the Protection Obligation by SESAMi (including outdated firewall and VPN firmware, no patch management and unenforced password and MFA rules), and likewise by Abecha, which as controller had taken no steps to ensure adequate security at SESAMi. SESAMi received 8,750 SGD and directions, while Abecha, as the controller, received directions only, including setting out roles and data protection duties within the group in writing.

What organisations can take from it

Even within a group, processing data for another group company requires a written allocation of roles and duties, and the responsible company must actively demand adequate security from its service provider.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24(a) PDPA 2012 (Protection Obligation); Section 4(3) PDPA (Pflichten bei Einsatz eines Data Intermediary); Section 48J PDPA (Financial Penalty)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Cooperation, prompt and effective remediation, admission under the Expedited Decision Procedure; for Abecha also lower culpability owing to its limited autonomy as a wholly owned subsidiary, one of the reasons for not imposing a fine on it.
Published
26 Feb 2026

Original amount 8,750 SGD, converted at the ECB reference rate of 29 Dec 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial