Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,032 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Data Protection Commission (PDPC) 9 cases 43 % · €320,376
- Monetary Authority of Singapore (MAS) 5 cases 24 % · €20.9m
- Competition and Consumer Commission of Singapore (CCCS) 3 cases 14 % · €13.9m
- Infocomm Media Development Authority (IMDA) 1 case 5 % · €660,197
- Ministry of Manpower (MOM), Singapur 1 case 5 % ·
- Ministry of Manpower (MOM); Verurteilung durch ein Singapurer Strafgericht 1 case 5 % · €339,697
- Singapore Customs; Verurteilung durch die State Courts 1 case 5 % · €24,218
What for?
by area of lawAll areas of law
- Data protection 9 cases 43 % · €320,376
- Money laundering and terrorist financing 3 cases 14 % · €19.2m
- Competition law 3 cases 14 % · €13.9m
- Health and safety and employment law 2 cases 10 % · €339,697
- Capital markets and financial supervision 2 cases 10 % · €1.72m
- Information security and cyber 1 case 5 % · €660,197
- Sanctions and export control 1 case 5 % · €24,218
Who?
by sectorAll sectors
- Financial services and insurance 6 cases 29 % · €24.5m
- Telecoms, IT and software 5 cases 24 % · €701,169
- Construction and real estate 4 cases 19 % · €10.3m
- Other 2 cases 10 % · €240,207
- Retail and e-commerce 1 case 5 % · €39,197
- Manufacturing and mechanical engineering 1 case 5 % · €339,697
- Food and agriculture 1 case 5 % ·
- Transport, logistics and shipping 1 case 5 % · €24,218
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 2 | €8.79m |
| Q1 2025 | 0 | – |
| Q2 2025 | 5 | €3.88m |
| Q3 2025 | 4 | €22m |
| Q4 2025 | 4 | €906,190 |
| Q1 2026 | 1 | €11,671 |
| Q2 2026 | 5 | €568,260 |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
21 cases
4 Jul 2025 Credit Suisse Singapore Branch, United Overseas Bank Limited, UBS AG Singapore Branch u. a. (9 Finanzinstitute)MAS: SGD 27.45m against nine financial institutions after major money laundering case €18.3m
Following inspections of institutions linked to persons of interest (POIs) in the major money laundering case of August 2023, the Monetary Authority of Singapore (MAS, Singapore's central bank and financial regulator) allegedly imposed composition penalties totalling SGD 27.45 million because existing AML/CFT policies had been implemented poorly or inconsistently – in customer risk assessment, corroboration of source of wealth, transaction monitoring and follow-up after suspicious transaction reports. Breakdown: Credit Suisse Singapore Branch SGD 5.8m, United Overseas Bank SGD 5.6m, UBS AG Singapore Branch SGD 3m, UOB Kay Hian SGD 2.85m, Citibank N.A. Singapore and Citibank Singapore Limited together SGD 2.6m, Bank Julius Baer & Co. Ltd. Singapore Branch SGD 2.4m, Blue Ocean Invest SGD 2.4m, Trident Trust Company (Singapore) SGD 1.8m and LGT Bank (Singapore) SGD 1m. The penalty for Credit Suisse also reflects breaches between November 2017 and October 2023 relating to accounts of certain US customers. The amount and the facts have not been confirmed against the primary source.
Anti-money laundering policies only protect an institution if relationship managers actually question inconsistencies in the source of wealth and systematically follow up alerts from transaction monitoring.
Recognising and escalating red flags in source of wealth and transaction patterns (relationship managers as the first line of defence)
- Authority / court
- Monetary Authority of Singapore (MAS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- MAS Notices 626, 1014, SFA04-N02 und TCA-N03; s 27B(2) Monetary Authority of Singapore Act 1970 bzw. s 16(4) Financial Services and Markets Act 2022; Composition nach s 176(1A) MAS Act 1970 bzw. s 177(1) FSMA 2022
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 4 Jul 2025
Original amount 27,450,000 SGD, converted at the ECB reference rate of 4 Jul 2025.
- MAS: MAS Takes Regulatory Actions against 9 Financial Institutions for AML-Related Breaches (04.07.2025) Press release of an authority
- MAS: Enforcement Actions (Verzeichnis, Eintrag 04.07.2025, Action Type Composition) Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
25 Jun 2026 Stars Engrg Pte LtdStars Engrg: SGD 500,000 fine after fatal explosion €339,697
An explosion and fire at a heated mixer machine at Stars Engrg Pte Ltd's Tuas worksite on 24 February 2021 killed three workers and injured seven; the company was fined a total of SGD 500,000 under the Workplace Safety and Health Act. According to investigations by the Ministry of Manpower (MOM, Singapore's labour ministry) and an inquiry committee, the machine had been kept running despite repeated warning signs such as overheating, oil leaks, smoke and a fire shortly beforehand, and there were failures in risk assessment, safe work procedures, maintenance, supervision and training. After the incident, messages significant to the investigation were also deleted.
Taking machinery warning signs seriously; risk assessment, safe work procedures and training
Missing or inadequate training played a role in the decision.
- Authority / court
- Ministry of Manpower (MOM); Verurteilung durch ein Singapurer Strafgericht
- Area of law
- Health and safety and employment law · Workplace safety and accidents
- Legal basis
- Workplace Safety and Health Act 2006 (WSHA); Penal Code (Behinderung der Justiz, gegen Einzelpersonen)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Manufacturing and mechanical engineering
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 25 Jun 2026
Original amount 500,000 SGD, converted at the ECB reference rate of 25 Jun 2026.
- MOM: Stars Engrg – Workplace Explosion At Tuas Worksite; Company Also Penalised (25.06.2026) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
25 May 2026 Padang Trust Singapore Pte. Ltd.MAS: SGD 300,000 against Padang Trust over failures in suspicious transaction reporting €201,708
The Monetary Authority of Singapore (MAS, Singapore's central bank and financial regulator) allegedly imposed a composition penalty of SGD 300,000 on the licensed trust company Padang Trust Singapore Pte. Ltd. because it failed to inquire into unusual transactions with no apparent economic or lawful purpose and did not file suspicious transaction reports promptly. According to MAS, the causes were inadequate controls, including a lack of scrutiny of unusual transactions and low staff awareness of money laundering and terrorist financing risks and red flags; the company paid the penalty, took remedial action and appointed an independent reviewer to confirm that the measures are effective. The amount and the facts have not been confirmed against the primary source.
Failing to question unusual transactions and delaying suspicious transaction reports breaches core anti-money laundering duties – staff must know the typical red flags.
Recognising unusual transactions and filing suspicious transaction reports without delay
- Authority / court
- Monetary Authority of Singapore (MAS)
- Area of law
- Money laundering and terrorist financing · Suspicious activity reports
- Legal basis
- MAS Notice TCA-N03; s 27B(2) Monetary Authority of Singapore Act (Cap. 186); Composition nach s 176(1A) MAS Act 1970
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Published
- 25 May 2026
Original amount 300,000 SGD, converted at the ECB reference rate of 25 May 2026.
- MAS: MAS Imposes $300,000 Composition Penalty on Padang Trust Singapore Pte. Ltd. for AML/CFT Breaches (25.05.2026) Press release of an authority
- MAS: Enforcement Actions (Verzeichnis, Eintrag 25.05.2026, Action Type Composition) Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
18 May 2026 Havenport Investments Pte LtdMAS: composition fine for Havenport Investments €26,855
The fund manager Havenport Investments Pte Ltd lacked an adequate framework for managing the risks of the assets under its management, breached its base capital requirement without reporting this to the Monetary Authority of Singapore (MAS, Singapore's central bank and financial regulator), and violated conditions of its Capital Markets Services Licence requiring prior approval for a new product and personalised advice from independent financial advisers for retail investors before onboarding. MAS allegedly imposed a composition fine of SGD 40,000; the company has ceased its retail fund management business and has not been allowed to manage retail investors' money since 18 July 2024. The amount and the facts have not been confirmed against the primary source.
Licence conditions and capital requirements belong in ongoing compliance monitoring by senior management; any shortfall must be reported immediately.
Senior management duties regarding licence conditions, capital requirements and reporting to the regulator
- Authority / court
- Monetary Authority of Singapore (MAS)
- Area of law
- Capital markets and financial supervision · Organisational requirements
- Legal basis
- Securities and Futures Act (SFA) und zugehörige Regulations; Auflagen der Capital Markets Services Licence
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 18 May 2026
Original amount 40,000 SGD, converted at the ECB reference rate of 18 May 2026.
- MAS: Enforcement Action against Havenport Investments Pte Ltd for Breaches of MAS Regulations (18.05.2026) Press release of an authority
- MAS: Enforcement Actions (Verzeichnis, Eintrag 18.05.2026) Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
1 Apr 2026 Twelve Cupcakes Pte. Ltd.Twelve Cupcakes (Singapore): stern warning over unpaid salaries for 80 employees Reprimand or warning
The Ministry of Manpower (MOM, Singapore's labour ministry) issued Twelve Cupcakes Pte. Ltd. a formal stern warning because 80 employees were not paid their salaries for 1 to 29 October 2025 after the company closed on 29 October 2025. The parent company Dhunseri Ventures Limited had placed it into liquidation because of an acute cash-flow shortfall; the ministry regarded the case as a genuine business closure in financial distress rather than a deliberate attempt to evade salary obligations and therefore limited its action to the warning.
Even an unavoidable closure does not release an employer from paying wages – informing employees, the union and the authority early reduces the consequences for all sides.
Salary payment obligations when closing a business
- Authority / court
- Ministry of Manpower (MOM), Singapur
- Area of law
- Health and safety and employment law · Minimum wage and undeclared work
- Legal basis
- Employment Act (EA), Singapur (fristgerechte Lohnzahlung)
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Employees
- 50 to 249
- Mitigating circumstances
- Salaries paid in full up to and including September 2025 despite continued losses, union informed on the day management learned of the liquidation, liquidator appointed; salary claims rank ahead of other unsecured debts in the insolvency.
- Published
- 1 Apr 2026
- Stern Warning Issued to Twelve Cupcakes for Non-Payment of Salaries (Ministry of Manpower, 1 April 2026) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
1 Apr 2026 The Management Corporation – Strata Title Plan No. 4869 (Riverfront Residences)MCST 4869: directions over lack of data protection instructions to managing agent Order
The management corporation of the Riverfront Residences condominium had not designated a data protection officer until March 2025, had no data protection policies of its own and had given its managing agent, which acted for it as a data intermediary, no instructions on handling personal data; in April 2025 an employee of the managing agent mistakenly sent the names, addresses and maintenance fee details of two owners to another owner. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found breaches of the Accountability Obligation and the Protection Obligation; by contrast, it found no breach in the circulation of a requisition for an extraordinary general meeting bearing the names and signatures of 303 owners, because strata management law prevailed. It directed the corporation to introduce, within 90 days, policies and procedures for the processing of data by the managing agent and to communicate them to it; the managing agent itself had given a voluntary undertaking.
Anyone who outsources management to a service provider remains responsible and needs their own data protection officer, their own policies and specific instructions to the provider.
Check recipients before sending, protect sensitive attachments and give service providers clear instructions
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Sections 11(3) und 12(a) PDPA 2012 (Accountability Obligation); Section 24 i. V. m. Section 4(3) PDPA (Protection Obligation bei Einsatz eines Data Intermediary)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Published
- 7 May 2026
- PDPC – Enforcement Decisions: Breach of the Accountability and Protection Obligations by MCST 4869 (veröffentlicht 07.05.2026) Enforcement database of an authority
- PDPC – Decision [2026] SGPDPC 1, The Management Corporation – Strata Title Plan No. 4869, Case No. DP-2503-C3469 (01.04.2026), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 Jan 2026 People Central Pte. Ltd.People Central: 17,500 SGD after attack on HR cloud holding data on 95,000 employees €11,671
The provider of cloud-based HR software received an extortion email in April 2024; an attacker had deleted databases on its AWS servers and likely exfiltrated data, and data allegedly taken was offered for sale on the dark web – data on 95,000 employees of its clients (including identity number, salary, bank account and religion) and on 24,765 emergency contacts and children was put at risk. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation because, despite the HR data entrusted to it by clients, the provider had no web application firewall against existing SQL injection vulnerabilities, remote desktop access open to the internet without two-factor authentication, and vulnerability scans only every two years. It imposed 17,500 SGD, payable in twelve monthly instalments in view of the company's cash flow, and directed among other things a web application firewall, annual penetration tests, two-factor authentication and encryption of all personal data fields.
Cloud providers processing sensitive HR data for clients must secure remote access and have their applications tested regularly for vulnerabilities.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach; payment in instalments in view of cash flow, while a waiver was refused.
- Published
- 8 Jan 2026
Original amount 17,500 SGD, converted at the ECB reference rate of 8 Jan 2026.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by People Central Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 4, People Central Pte. Ltd., Case No. DP-2405-C2330, PDF (ohne Datum) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
29 Dec 2025 SESAMi (Singapore) Pte Ltd; Abecha Pte LtdSESAMi: 8,750 SGD after ransomware attack on network drive shared with its subsidiary €5,786
In August 2024 an attacker encrypted a network drive shared by SESAMi and its subsidiary Abecha holding payment data (including full credit card numbers and bank account details) of around 20,471 customers of the subsidiary's fuel fleet discount programme and of up to 18,837 individuals from registrations for SESAMi's B2B platform; exfiltration could not be established. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) classified SESAMi, which ran the network for the subsidiary without a written contract, as a data intermediary in that respect and found a negligent breach of the Protection Obligation by SESAMi (including outdated firewall and VPN firmware, no patch management and unenforced password and MFA rules), and likewise by Abecha, which as controller had taken no steps to ensure adequate security at SESAMi. SESAMi received 8,750 SGD and directions, while Abecha, as the controller, received directions only, including setting out roles and data protection duties within the group in writing.
Even within a group, processing data for another group company requires a written allocation of roles and duties, and the responsible company must actively demand adequate security from its service provider.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation); Section 4(3) PDPA (Pflichten bei Einsatz eines Data Intermediary); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Cooperation, prompt and effective remediation, admission under the Expedited Decision Procedure; for Abecha also lower culpability owing to its limited autonomy as a wholly owned subsidiary, one of the reasons for not imposing a fine on it.
- Published
- 26 Feb 2026
Original amount 8,750 SGD, converted at the ECB reference rate of 29 Dec 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by SESAMi (Singapore) Pte Ltd and Abecha Pte Ltd (veröffentlicht 26.02.2026) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 1, SESAMi (Singapore) Pte Ltd / Abecha Pte Ltd, Case No. DP-2408-C2786 (29.12.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
11 Dec 2025 Singapore Telecommunications Limited (Singtel)IMDA: SGD 1m against Singtel after hours-long fixed-line voice outage €660,197
On 8 October 2024 Singtel's fixed-line voice service failed for more than four hours for around 500,000 residential and corporate users; customer service lines of government agencies, healthcare organisations and banks as well as emergency call services were also affected. The cause was that the virtualised firewalls of the voice system and of a monitoring system shared the same hardware, so that an overload of the insufficiently filtered monitoring system also disrupted the voice system and the automatic failover did not work cleanly; according to the investigation, there was no cyber-attack. The Infocomm Media Development Authority (IMDA, Singapore's telecoms and media regulator) imposed a penalty of SGD 1 million under the Telecommunications Act because the incident had been within Singtel's control to prevent.
Critical services need separated components and reliably tested failover mechanisms – shared hardware can turn a fault in an ancillary system into an outage of the core service.
- Authority / court
- Infocomm Media Development Authority (IMDA)
- Area of law
- Information security and cyber · Critical infrastructure
- Legal basis
- Telecommunications Act
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Employees
- 10,000 or more
- Published
- 11 Dec 2025
Original amount 1,000,000 SGD, converted at the ECB reference rate of 11 Dec 2025.
- IMDA: IMDA Imposes Financial Penalty on Singtel for Fixed Voice Disruption (11.12.2025) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
31 Oct 2025 Air Sino-Euro Associates Travel Pte. Ltd.Air Sino-Euro: 47,000 SGD – no data protection officer, no internal rules, data leak €31,252
After a cyberattack on the travel agency became public in December 2023, data on 336,759 individuals in its booking system was affected, in some cases including full images of identity cards, passports and birth certificates; part of the data was exfiltrated. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found negligent breaches of the Accountability Obligation – a data protection officer appointed only in April 2024, and apart from the customer-facing privacy policy no internal policies, no complaints process and no information to staff – and of the Protection Obligation, because there were no contracts with the IT vendors covering security tasks, no security reviews and no multi-factor authentication, and the server was still running the unsupported Windows Server 2012. It imposed 47,000 SGD, rejected objections based on COVID-19 losses and comparable cases, and directed among other things policies, security clauses in vendor contracts and a penetration test by a provider licensed by the Cyber Security Agency (CSA).
An outward-facing privacy policy is no substitute for a designated data protection officer or for internal rules that staff know and that apply in day-to-day work.
Internal data protection policies, communicating them to staff, and password rules
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); Section 24 PDPA (Protection Obligation); Section 48J(1)(a) PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- negligent
- Mitigating circumstances
- Voluntary early admission of the breaches (treated as significantly mitigating) and prompt, effective remediation.
- Published
- 8 Jan 2026
Original amount 47,000 SGD, converted at the ECB reference rate of 31 Oct 2025.
- PDPC – Enforcement Decisions: Breach of the Accountability and Protection Obligations by Air Sino-Euro Associates Travel Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC [5], Air Sino-Euro Associates Travel Pte. Ltd., Case No. DP-2312-C1857 (31.10.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
28 Oct 2025 Marina Bay Sands Pte. Ltd.Marina Bay Sands: 315,000 SGD after configuration error in middleware migration €208,955
When API configurations were manually transferred to a new middleware platform (September 2022 to March 2023), a single employee in sole charge omitted an app identifier, so token verification did not apply to the web page of the ArtScience Friends museum programme for at least six months; an attacker exploited this in October 2023 and retrieved data on 665,495 members of the Sands Rewards Lifestyle loyalty programme, which was then offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that the resort had negligently breached the Protection Obligation by relying on this one employee without independent checks or automation. It reduced the provisionally intended 450,000 SGD to 315,000 SGD after the company's representations; no directions were issued because remediation had already been carried out.
Security-critical configuration steps when migrating large data sets must not depend on a single person without independent checks or automation.
Human error in manual IT changes: four-eyes principle and automation
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Section 24 Personal Data Protection Act 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Culpability
- negligent
- Repeat case
- no
- Mitigating circumstances
- Otherwise adequate security arrangements, containment on the day of discovery, admission under the Expedited Decision Procedure, cooperation and voluntary notification of all affected individuals.
- Published
- 28 Oct 2025
Original amount 315,000 SGD, converted at the ECB reference rate of 28 Oct 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Marina Bay Sands Pte Ltd (veröffentlicht 28.10.2025) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC 6, Marina Bay Sands Pte. Ltd., Case No. DP-2310-C1622 (28.10.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
31 Jul 2025 ZGR Global Pte. Ltd.; Hanshan Money Express Pte. Ltd.CCCS: 5.37 million SGD against two remittance shops for exchanging exchange rates €3.61m
ZGR Global (formerly Zhongguo Remittance) and Hanshan Money Express, two adjacent leading providers of Chinese yuan remittances in People's Park Complex, shared their current and partly non-public remittance rates with each other daily, often several times a day, from at least January 2016 to February 2022, verbally over the counter, on paper slips or by phone. The Competition and Consumer Commission of Singapore (CCCS) found this to infringe s 34 of the Competition Act and on 31 July 2025 imposed penalties totalling 5,365,007 SGD (ZGR Global 2,793,700, Hanshan 2,571,307 SGD). In addition to its cooperation discount, Hanshan received a further 10% discount for its admission under the Fast Track Procedure.
Even routinely sharing current prices with the competitor next door is prohibited coordination; prices must be set independently.
No exchange of prices or pricing intentions with competitors
- Authority / court
- Competition and Consumer Commission of Singapore (CCCS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Competition Act 2004, s 34
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Hanshan: discount for cooperation plus a further 10% for its admission under the Fast Track Procedure.
- Published
- 31 Jul 2025
Original amount 5,365,007 SGD, converted at the ECB reference rate of 31 Jul 2025.
- CCCS: CCCS Penalises Chinese Yuan Remittance Service Providers $5.36 Million for Illegal Information Exchange (31.07.2025) Press release of an authority
- CCCS Public Register: CCCS 500-100-2020-003 (Decision Date 31.07.2025) Official register or notice
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
30 Jul 2025 Ayzo Pte LtdAyzo: SGD 36,000 fine for freight forwarder misusing other companies' entity identifiers €24,218
In 2024 the freight forwarder Ayzo Pte Ltd misused the Unique Entity Numbers of two other companies in applications for export permits for cigarette shipments to Australia that were described as other goods in the shipping documents, and failed to retain the bills of lading. Ayzo had relied solely on information from an unknown client in India without verifying it with the named importers and exporters. After the company pleaded guilty to ten charges under the Customs Act for incorrect UEN declarations and three charges for failure to retain trade documents, the State Courts imposed a fine of SGD 36,000 on 30 July 2025.
Freight forwarders must verify client and goods information before customs declarations and retain trade documents, or they become tools for smugglers.
Due diligence in customs declarations: verifying clients and goods descriptions
- Authority / court
- Singapore Customs; Verurteilung durch die State Courts
- Area of law
- Sanctions and export control · Customs
- Legal basis
- Customs Act (unrichtige Angabe der Unique Entity Number); drei weitere Anklagepunkte wegen fehlender Aufbewahrung von Handelsdokumenten (Vorschrift in der Mitteilung nicht genannt)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Transport, logistics and shipping
- Published
- 19 Aug 2025
Original amount 36,000 SGD, converted at the ECB reference rate of 30 Jul 2025.
- Singapore Customs Media Release 19.08.2025: Freight Forwarder Fined $36,000 for Misusing Companies' Unique Entity Identifiers (PDF) Press release of an authority
- Singapore Customs – News (Verzeichnis, Eintrag 19.08.2025 mit Link auf die Mitteilung) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
3 Jul 2025 Ezynetic Pte. Ltd.Ezynetic: 17,500 SGD after ransomware at IT service provider for moneylenders €11,664
The SaaS provider operates a system for licensed moneylenders that is linked to the Moneylenders Credit Bureau and into which its clients enter data on loan applicants and borrowers; in June 2024 an attacker used a vulnerable web application to take over the SQL server's system administrator account, which was protected only by an easily guessed password, deleted databases and exfiltrated data on 190,589 individuals including credit report data, which was offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation (inadequate access control, no vulnerability assessments or penetration tests) and, given the company's role as a provider processing client data entrusted to it, considered a fine of 17,500 SGD appropriate; it rejected the request for a waiver or reduction. In addition, the company must obtain the Cyber Trust mark certification of the Cyber Security Agency of Singapore (CSA) for its new network within nine months.
Privileged default accounts such as a database server administrator must be disabled or secured with strong passwords and additional controls, and systems must be tested regularly for vulnerabilities.
Strong passwords and protection of privileged administrator accounts
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
- Published
- 3 Jul 2025
Original amount 17,500 SGD, converted at the ECB reference rate of 3 Jul 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Ezynetic (veröffentlicht 03.07.2025) Enforcement database of an authority
- PDPC – Summary of the Decision [2025] SGPDPCS 2, Ezynetic Pte. Ltd., Case No. DP-2406-C2585, PDF (ohne Datum) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
27 Jun 2025 Remsea Pte Ltd, Arcade Plaza Traders Pte Ltd, J-Dee Remittance Services Pte Ltd u. a. (5 Zahlungsinstitute)MAS: 960,000 SGD against five remittance providers for AML failings €642,871
In examinations of five licensed payment institutions providing cross-border money transfers, the Monetary Authority of Singapore (MAS, Singapore's central bank and financial regulator) found failings in customer due diligence, such as missing residential addresses, no inquiry into beneficial owners, no screening of customers against money laundering risk information sources, unverified authority of persons acting for customers and missing originator or beneficiary information on cross-border wire transfers. On 27 June 2025 it allegedly imposed composition penalties totalling 960,000 SGD: Remsea 280,000, Arcade Plaza Traders 260,000, J-Dee Remittance Services 170,000, Mobile Community Tech 140,000 and OxPay SG 110,000 SGD. The amount and the facts have not been confirmed against the primary source.
Payment institutions offering cross-border transfers must check customers, representatives and beneficial owners and attach complete originator and beneficiary data to every cross-border transfer.
Customer due diligence and complete information on cross-border transfers
- Authority / court
- Monetary Authority of Singapore (MAS)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- MAS Notice PSN01; s 27B(2) Monetary Authority of Singapore Act bzw. s 16(4) Financial Services and Markets Act 2022; Composition nach s 176(1A) MAS Act 1970 bzw. s 177(1) FSMA 2022
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 27 Jun 2025
Original amount 960,000 SGD, converted at the ECB reference rate of 27 Jun 2025.
- MAS: MAS Imposes Composition Penalties against Five Major Payment Institutions (27.06.2025) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
20 Jun 2025 Goldheart Jewelry Pte. Ltd.Goldheart Jewelry: 58,000 SGD over security patch applied eleven months late €39,197
The jeweller applied a patch released in February 2022 for a known vulnerability (CVE-2022-24086) in the Magento platform of its online shop only in January 2023; through the gap an attacker extracted the customer database with data on 41,379 individuals and posted it on an online forum in May 2023. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a negligent breach of the Protection Obligation because the company relied entirely on its maintenance vendor for patching without directing or monitoring it, and rejected the argument that the vendor had been a data intermediary. Alongside 58,000 SGD (provisionally 64,000 SGD; the finding on credentials stored in plain text was dropped after representations) it directed an external security audit of access controls and the remediation of any gaps.
A company that outsources the maintenance of its web shop remains responsible for patching and must assign responsibilities and monitor implementation.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Section 24 PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Mitigating circumstances
- Prompt remediation once the incident was known, admission under the Expedited Decision Procedure and cooperation.
- Published
- 8 Jan 2026
Original amount 58,000 SGD, converted at the ECB reference rate of 20 Jun 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Goldheart Jewelry Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC 4, Goldheart Jewelry Pte. Ltd., Case No. DP-2305-C1061 (20.06.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
23 May 2025 Trust-Build Engineering & Construction Pte Ltd., Hunan Fengtian Construction Group Co., LtdCCCS: SGD 4.64m in penalties on two construction firms for bid-rigging €3.19m
The Competition and Consumer Commission of Singapore (CCCS, competition and consumer protection authority) found that Hunan Fengtian Construction Group had prepared the tender documents and prices of Trust-Build Engineering & Construction for three 2022 tenders of the People's Association (works at three community clubs, total value around SGD 56 million), so that the two did not bid independently; the People's Association noticed the possible collusion, reported it and excluded both bidders from the evaluation. Under section 34 of the Competition Act 2004, CCCS imposed financial penalties of SGD 4,295,059 on Trust-Build and SGD 349,350 on Hunan Fengtian, totalling SGD 4,644,409.
Preparing a competitor's bid or knowing its prices is bid-rigging – even if neither party ultimately wins the contract.
Bid-rigging: no coordination of bids with competitors in tenders
- Authority / court
- Competition and Consumer Commission of Singapore (CCCS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Section 34 Competition Act 2004; Geldbuße nach s 69(2)(e) Competition Act 2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Published
- 23 May 2025
Original amount 4,644,409 SGD, converted at the ECB reference rate of 23 May 2025.
- CCCS: CCCS Imposes A Total Of $4.6m Penalties On Contractors For Rigging Bids In Public Sector Tenders (23.05.2025) Press release of an authority
- CCS Case Register: CCCS 500-100-2023-001, Decision Date 23 May 2025 Enforcement database of an authority
- CCCS Infringement Decision, Construction Tenders, 23 May 2025 (PDF, verlinkt aus dem Case Register) Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
19 May 2025 The Management Corporation – Strata Title Plan No. 4599 (The Scotts Tower)MCST 4599: directions after refused access request for CCTV footage Order
A person involved in a traffic accident next to the condominium requested access to the CCTV footage in April 2024; the security company could not save it for lack of administrator access, the system overwrote it after 17 days, and the management corporation then refused the request, citing other individuals' data and strata management law. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) held that a blanket refusal was not justified (other individuals could have been masked) but, as the footage no longer existed, made no finding on the access obligation, and found a negligent breach of the Accountability Obligation: no data protection officer, no data protection policy of its own (only the managing agent's) and no instructions to the managing agent and security company on handling access requests. It directed the corporation to introduce, within 60 days, policies and a procedure for access requests concerning CCTV footage and to pass them on to the managing agent and contractors.
Access requests for CCTV footage need a set procedure that secures the footage before it is automatically overwritten and masks other individuals instead of refusing outright.
Recognise access requests, secure the relevant data immediately and respond in time
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Sections 11(3) und 12 PDPA 2012 (Accountability Obligation); geprüft auch Sections 21 und 22A PDPA (Auskunft, Aufbewahrung bei Ablehnung)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Culpability
- negligent
- Mitigating circumstances
- The management corporation appointed a data protection officer after the incident.
- Published
- 7 Aug 2025
- PDPC – Enforcement Decisions: Breach of the Accountability Obligation by MCST 4599 (veröffentlicht 07.08.2025) Enforcement database of an authority
- PDPC – Decision 2025 SGPDPC 3, The Management Corporation – Strata Title Plan No. 4599, Case No. DP-2405-C2318 (19.05.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
7 Apr 2025 Singapore Data Hub Pte LtdSingapore Data Hub: 17,500 SGD after SQL injection attacks on point-of-sale software €11,851
The provider of point-of-sale and CRM software for small and medium-sized enterprises reported two attacks in 2024 in which perpetrators used SQL injection, among other methods, to extract files with data on a total of 698,112 individuals, including health information (skin conditions and treatments) of 9,122 individuals; the data was likely posted on a hacking forum. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) stressed that the SaaS provider holds large volumes of data on behalf of its clients and found a breach of the Protection Obligation: publicly accessible servers, no network firewall, no security testing before releases, unsupported operating system and PHP versions, and credentials left unprotected in source code and configuration files. Alongside 17,500 SGD it directed a package of measures ranging from network segmentation and patch management to vulnerability assessments and penetration tests at least once a year.
SaaS providers holding customer data on a large scale must test new releases for security vulnerabilities before going live and consistently update or decommission legacy systems.
- Authority / court
- Personal Data Protection Commission (PDPC)
- Area of law
- Data protection · Data processors
- Legal basis
- Section 24(a) PDPA 2012 (Protection Obligation)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- no
- Mitigating circumstances
- Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
- Published
- 8 Jan 2026
Original amount 17,500 SGD, converted at the ECB reference rate of 7 Apr 2025.
- PDPC – Enforcement Decisions: Breach of the Protection Obligation by Singapore Data Hub Pte Ltd (veröffentlicht 08.01.2026) Enforcement database of an authority
- PDPC – Decision [2025] SGPDPC 2, Singapore Data Hub Pte Ltd, Case No. DP-2406-C2514 (07.04.2025), PDF Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
20 Dec 2024 Tarkus Interiors Pte Ltd; Flex Connect Pte Ltd (vormals Facility Link Pte Ltd)CCCS: 9,999,181 SGD against two interior fit-out firms for bid rigging €7.09m
From August 2016 to August 2021, Flex Connect (formerly Facility Link) and Tarkus Interiors colluded on twelve tenders for interior fit-out works in shops, food and beverage outlets and offices worth around 34.11 million SGD in total: the designated winner gave the other firm its prices and details so that it would submit a higher cover bid. On 20 December 2024 the Competition and Consumer Commission of Singapore (CCCS) imposed penalties of 5,113,918 SGD on Tarkus and 4,885,263 SGD on Flex Connect, totalling 9,999,181 SGD (the CCCS itself states the total as 9,999,182 SGD); Flex Connect received a leniency discount.
Cover bids remain prohibited collusion even if bidders fear being passed over in future tenders otherwise.
Recognising and refusing bid rigging and cover bids
- Authority / court
- Competition and Consumer Commission of Singapore (CCCS)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Competition Act 2004, s 34
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Construction and real estate
- Mitigating circumstances
- Leniency discount for Flex Connect.
- Published
- 20 Dec 2024
Original amount 9,999,181 SGD, converted at the ECB reference rate of 20 Dec 2024.
- CCCS: CCCS Penalises Contractors Specialising in Non-Residential Interior Fit-Out Tenders for Bid-Rigging (20.12.2024) Press release of an authority
- CCCS Public Register: CCCS 500-100-2021-001 (Decision Date 20.12.2024) Official register or notice
Checked against the official source on 4 Oct 2026 · Direct link