Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,030 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€11,851Total of monetary amounts
€11,851Largest single case: Singapore Data Hub Pte Ltd
€11,851Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20251€11,851
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

7 Apr 2025 Singapore Data Hub Pte LtdSingapore Data Hub: 17,500 SGD after SQL injection attacks on point-of-sale software SingaporeData processors €11,851

The provider of point-of-sale and CRM software for small and medium-sized enterprises reported two attacks in 2024 in which perpetrators used SQL injection, among other methods, to extract files with data on a total of 698,112 individuals, including health information (skin conditions and treatments) of 9,122 individuals; the data was likely posted on a hacking forum. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) stressed that the SaaS provider holds large volumes of data on behalf of its clients and found a breach of the Protection Obligation: publicly accessible servers, no network firewall, no security testing before releases, unsupported operating system and PHP versions, and credentials left unprotected in source code and configuration files. Alongside 17,500 SGD it directed a package of measures ranging from network segmentation and patch management to vulnerability assessments and penetration tests at least once a year.

What organisations can take from it

SaaS providers holding customer data on a large scale must test new releases for security vulnerabilities before going live and consistently update or decommission legacy systems.

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24(a) PDPA 2012 (Protection Obligation)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
no
Mitigating circumstances
Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
Published
8 Jan 2026

Original amount 17,500 SGD, converted at the ECB reference rate of 7 Apr 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial