Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,019 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

South Korea Clear all filters
25cases from 1 jurisdiction
€1.07bnTotal of monetary amounts (23 cases with an amount)
€7.95mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Personal Information Protection Commission (PIPC, 개인정보보호위원회) 11 cases 44 % · €396.1m
  2. Korea Fair Trade Commission (KFTC) 8 cases 32 % · €627.8m
  3. Korea Financial Intelligence Unit (KoFIU) 2 cases 8 % · €42.1m
  4. Korea Media and Communications Commission (KMCC, 방송미디어통신위원회) 2 cases 8 % · €1.76m
  5. Financial Supervisory Service (FSS) 1 case 4 % · €45,990
  6. Ministry of Science and ICT (MSIT, 과학기술정보통신부) 1 case 4 % · €3,396

What for?

by area of law

All areas of law

  1. Data protection 12 cases 48 % · €396.1m
  2. Competition law 6 cases 24 % · €627.5m
  3. Consumer protection and online retail 3 cases 12 % · €2.04m
  4. Money laundering and terrorist financing 2 cases 8 % · €42.1m
  5. Information security and cyber 1 case 4 % · €3,396
  6. Environment and sustainability 1 case 4 % ·

Who?

by sector

All sectors

  1. Financial services and insurance 7 cases 28 % · €217m
  2. Media and online platforms 5 cases 20 % · €17.1m
  3. Retail and e-commerce 4 cases 16 % · €249m
  4. Telecoms, IT and software 4 cases 16 % · €188.4m
  5. Food and agriculture 2 cases 8 % · €384.3m
  6. Manufacturing and mechanical engineering 1 case 4 % · €1.93m
  7. Public sector 1 case 4 % · €141,669
  8. Transport, logistics and shipping 1 case 4 % · €10m

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20244€28.6m
Q1 20254€84.8m
Q2 20251–
Q3 20252€84.1m
Q4 20253€20.9m
Q1 20262€179.7m
Q2 20264€625.7m
Q3 20265€44m
Q4 20260–

25 cases

17 Sep 2026 PFC Technologies Co., Ltd. (vormals PeopleFund Company)P2P lending platform shared customer data without consent: FSS sanctions PFC South KoreaData protection €45,990

According to the sanctions disclosure of the Financial Supervisory Service (FSS, Korea's financial supervisor), the online lending platform PFC Technologies transferred the resident registration numbers of 8,497 customers to a third party without their consent on 28 September 2022 in order to calculate the error rate of a new service for mortgage customers, and received credit information on the same customers from that third party, likewise without consent (such as the address and official value of their properties); in addition, when the inspection began it had not implemented password rules against easily guessed numbers. The sanction of 17 September 2026 comprises an institutional warning, an administrative fine (과태료) of KRW 24 million and a penalty surcharge (과징금) of KRW 49 million, KRW 73 million in total.

What organisations can take from it

Even for internal tests and quality measurements, customer data may only be passed to third parties with consent or a clear legal basis.

Relevance to training and awareness

Consent for sharing credit data and password rules

Authority / court
Financial Supervisory Service (FSS)
Area of law
Data protection
Legal basis
Art. 19, 32 und 34 Credit Information Use and Protection Act; Art. 16, 28 und 29 Durchführungsverordnung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Measures against individuals are not set out here.
Published
17 Sep 2026

Original amount 73,000,000 KRW, converted at the ECB reference rate of 17 Sep 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

9 Sep 2026 Moorim P&P, Moorim Paper, Hansol Paper u. a. (6 Unternehmen)Bid-rigging for printing paper for Nongmin News: six paper firms sanctioned South KoreaCartels and collusion €1.93m

According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), six manufacturers and distributors of printing paper fixed in advance the winning bidder, cover bidders and bid prices in six tenders issued by the publisher Nongmin News Corp. between June 2021 and November 2024; the average winning bid rate was around 96.2%, compared with 87.6% in 2018 to 2020. The KFTC issued corrective orders, imposed fines totalling KRW 3,009 million (Moorim SP KRW 59 million, Moorim Paper KRW 573 million, Moorim P&P KRW 948 million, Hansol Paper KRW 556 million, Hankuk Paper KRW 515 million, Hongwon Paper KRW 358 million).

What organisations can take from it

Competition compliance reviews should always cover tender business as well as general pricing, because collusion there often runs in parallel.

Relevance to training and awareness

Bid-rigging in tenders

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 40 Abs. 1 Nr. 8 MRFTA (Monopoly Regulation and Fair Trade Act)
Action
Fine
Status of proceedings
unknown
Sector
Manufacturing and mechanical engineering
Published
9 Sep 2026

Original amount 3,009,000,000 KRW, converted at the ECB reference rate of 9 Sep 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 South KoreaData breaches and data security €7.95m

Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.

What organisations can take from it

Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.

Relevance to training and awareness

Credential stuffing and password reuse

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
Published
31 Aug 2026

Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells South KoreaData breaches and data security €32.7m

Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.

What organisations can take from it

Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.

Relevance to training and awareness

Lost network devices and certificate management

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
Liability of senior managers
The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
Published
30 Jul 2026

Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

6 Jul 2026 Agoda Company Pte. Ltd.Agoda: 2.424 billion KRW for unclear refund conditions and fees South KoreaInformation duties in online retail €1.39m

In its flight booking flow, Agoda Company Pte. Ltd. did not show clearly whether a ticket was refundable and which cancellation or change fees applied – the information could only be reached via a link to baggage rules – and, for accommodation paid later, displayed a price without the possible surcharge of up to 5%, partly in a foreign currency. The authority regarded this as a breach of the duty to explain key terms under the Telecommunications Business Act (전기통신사업법), imposed a fine of 2,424,000,000 KRW and ordered Agoda to show conditions, fees and final prices early and clearly, to check screen flows internally in advance and to have Korean translations reviewed by professionals.

What organisations can take from it

Refundability, fees and the final price belong in the booking flow itself – not behind links with unrelated labels.

Authority / court
Korea Media and Communications Commission (KMCC, 방송미디어통신위원회)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Telecommunications Business Act (전기통신사업법) Art. 50(1) Nr. 5-2, Art. 52, Art. 53; Enforcement Decree Art. 42 i. V. m. Anhang 4
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
no
Mitigating circumstances
Reduction of 10% because the authority had not imposed a fine in the preceding three years; partial voluntary corrections made after the investigation began were not accepted as a mitigating factor.
Published
6 Jul 2026

Original amount 2,424,000,000 KRW, converted at the ECB reference rate of 6 Jul 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee South KoreaData breaches and data security €240.8m

A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.

What organisations can take from it

When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.

Relevance to training and awareness

Offboarding: revoking access and keys

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Culpability
negligent
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
Liability of senior managers
The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
Published
11 Jun 2026

Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

9 Jun 2026 Coupang Corp.Coupang advertised a one-off coupon price as a permanent 'WOW Member Price' South KoreaMisleading advertising and pricing €283,216

From 26 August 2020 to 15 May 2022, Coupang advertised a 'WOW Member Price' below the regular selling price in its online shop without disclosing that it included a coupon redeemable only once by new members of its paid WOW subscription. The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) treated the omission of this information as deceptive advertising, issued a corrective order and imposed a fine of KRW 500 million, the statutory maximum fixed-amount fine.

What organisations can take from it

Member prices may only be advertised in the way customers actually receive them repeatedly; one-off discounts must be clearly labelled.

Relevance to training and awareness

Transparent pricing of membership discounts

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Art. 3 Abs. 1 Nr. 2 Act on Fair Labeling and Advertising (täuschende Werbung)
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
9 Jun 2026

Original amount 500,000,000 KRW, converted at the ECB reference rate of 9 Jun 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

20 May 2026 Sajo DongAOne, Daehan Flour Mills, CJ CheilJedang u. a. (7 Unternehmen)Flour cartel: record KRW 671bn fine on seven mills South KoreaCartels and collusion €384.3m

According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), seven flour manufacturers with a combined 87.7% of the B2B market coordinated, on 24 occasions between November 2019 and October 2025, the timing and extent of price changes as well as supply volumes and supply rankings towards large buyers such as noodle and confectionery manufacturers, including while receiving government price stabilisation subsidies. In addition to a cease-and-desist order, the KFTC ordered an independent re-determination of prices and imposed fines totalling KRW 671,045 million, the highest amount in any cartel case to date: Sajo DongAOne KRW 183,097 million, Daehan Flour Mills KRW 179,273 million, CJ CheilJedang KRW 131,701 million, Samyang KRW 94,787 million, Daesun Flour Mills KRW 38,448 million, Hantop KRW 24,291 million, Samhwa Flour Mills KRW 19,448 million.

What organisations can take from it

Anyone already sanctioned for a cartel must expect considerably harsher consequences if contacts with competitors resume.

Relevance to training and awareness

Price and volume agreements with competitors

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 40 Abs. 1 Nr. 1 und Nr. 3 MRFTA (Monopoly Regulation and Fair Trade Act)
Action
Fine
Status of proceedings
unknown
Sector
Food and agriculture
Repeat case
yes
Liability of senior managers
Measures against individuals are not set out here.
Published
20 May 2026

Original amount 671,045,000,000 KRW, converted at the ECB reference rate of 20 May 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 May 2026 KT CorporationKT: 640 million KRW for cancelled Galaxy S25 pre-orders and false notices South KoreaMisleading advertising and pricing €370,997

In its own online shop for Galaxy S25 pre-orders, KT Corporation stated that benefits would apply unless the end of the promotion was shown, but then limited them to the first 1,000 orders and unilaterally cancelled 7,127 pre-orders that had come in via a YouTube channel and Genie TV and had already been fully completed. The authority regarded this as false information on key terms and an unjustified refusal to conclude contracts under the Telecommunications Business Act (전기통신사업법), imposed a fine of 640,000,000 KRW and ordered KT to show additional pre-order benefits clearly in future.

What organisations can take from it

Promotion terms such as quotas must be visible before the contract is concluded – cancelling completed orders afterwards is no solution.

Authority / court
Korea Media and Communications Commission (KMCC, 방송미디어통신위원회)
Area of law
Consumer protection and online retail · Misleading advertising and pricing
Legal basis
Telecommunications Business Act (전기통신사업법) Art. 50(1) Nr. 5 und Nr. 5-2
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
8 May 2026

Original amount 640,000,000 KRW, converted at the ECB reference rate of 8 May 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

17 Mar 2026 Bithumb Co., Ltd.Bithumb: partial suspension and KRW 36.9bn fine for anti-money laundering breaches South KoreaCustomer due diligence €21.5m

The KoFIU (Korea Financial Intelligence Unit) found that the crypto exchange Bithumb had processed 45,772 transfers of crypto assets with 18 virtual asset service providers that had not complied with their reporting obligation between August 2022 and April 2025, and had breached customer identification duties and the associated transaction restrictions in large numbers; there were also shortcomings in suspicious transaction reporting, record keeping and the risk assessment of new products. On 17 March 2026 it ordered a six-month partial suspension of business (no transfers of crypto assets for new customers from 27 March to 26 September 2026) and imposed a fine of KRW 36,873.5 million. The amount and the facts have not been confirmed against the primary source.

What organisations can take from it

Crypto exchanges must check counterparties for deposits and withdrawals against the register of reported providers before allowing transfers.

Relevance to training and awareness

Counterparty checks and customer identification for crypto transfers

Authority / court
Korea Financial Intelligence Unit (KoFIU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 4, 5, 5-2, 5-4 und 8 Act on Reporting and Using Specified Financial Transaction Information; Art. 9, 10-6, 10-9 und 10-20 Durchführungsverordnung (Teilsperre wegen Art. 8 i. V. m. Art. 10-20 DVO: Geschäfte mit nicht gemeldeten Anbietern)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Liability of senior managers
Measures against individuals are not set out here.
Published
17 Mar 2026

Original amount 36,873,500,000 KRW, converted at the ECB reference rate of 17 Mar 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

21 Jan 2026 KB Kookmin Bank, Shinhan Bank, Woori Bank, Hana BankFour major banks exchanged loan-to-value ratios: KRW 272bn fine South KoreaCartels and collusion €158.2m

According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), the four banks exchanged their complete loan-to-value (LTV) ratios for mortgage lending over a long period, between 736 and 7,500 individual values per bank, and adjusted their own ratios accordingly; only conduct from December 2021, when the express prohibition of anti-competitive information exchange entered into force, was pursued. The KFTC issued cease-and-desist orders and fines totalling KRW 272,014 million (Kookmin KRW 69,747 million, Shinhan KRW 63,801 million, Woori KRW 51,535 million, Hana KRW 86,931 million), the first application of that provision.

What organisations can take from it

Exchanging individual contract terms with competitors is a stand-alone competition law infringement even without price fixing.

Relevance to training and awareness

Information exchange with competitors

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 40 Abs. 1 Nr. 9 MRFTA i. V. m. Art. 44 Abs. 2 Nr. 3 Durchführungsverordnung (Monopoly Regulation and Fair Trade Act)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
21 Jan 2026

Original amount 272,014,000,000 KRW, converted at the ECB reference rate of 21 Jan 2026.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

9 Dec 2025 Dunamu Inc.Upbit operator Dunamu: KRW 35.2bn fine for customer due diligence failures South KoreaCustomer due diligence €20.6m

The KoFIU (Korea Financial Intelligence Unit) found that Dunamu, operator of the crypto exchange Upbit, had failed to identify customers with due care in 5,324,165 cases between October 2021 and October 2024, for instance where identity documents could not be verified, were mere copies or photos, or where addresses were blank or implausible, and had nevertheless allowed transactions in 3,331,570 of these cases. In addition, it failed to file suspicious transaction reports on 15 customers linked to warrant applications by investigative authorities, and its monitoring system did not detect unusual patterns such as large crypto deposits followed by sale and withdrawal; KoFIU imposed a fine of KRW 35,215.6 million on 9 December 2025. The amount and the facts have not been confirmed against the primary source.

What organisations can take from it

Digital onboarding processes need checks that reliably reject copies of identity documents and implausible addresses before trading is possible.

Relevance to training and awareness

Customer identification (KYC) at crypto exchanges

Authority / court
Korea Financial Intelligence Unit (KoFIU)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
Art. 4, 5, 5-2 und 8 Act on Reporting and Using Specified Financial Transaction Information; Art. 9, 10-4, 10-6 und 10-20 Durchführungsverordnung
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
9 Dec 2025

Original amount 35,215,600,000 KRW, converted at the ECB reference rate of 9 Dec 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Nov 2025 Starbucks CorporationStarbucks: order over inadequate oversight of audit provider in Korea South KoreaData processors Order

Starbucks Corporation had suppliers in Korea audited under its Ethical Sourcing Program by Elevate Hong Kong Holdings Limited, did not conclude a processing contract containing all statutory terms and did not supervise the provider adequately; Elevate processed unnecessarily large amounts of data on supplier employees, such as personnel files, wage and working-time records, and transferred them out of the businesses. The authority ordered Starbucks to award such work only under a written contract with all mandatory terms and to train and supervise the provider, and recommended data minimisation; a separate order was issued against Elevate.

What organisations can take from it

Supply chain audits process personal data too – the commissioning company needs a complete processing contract and must check that the audit provider collects no more than necessary.

Relevance to training and awareness

Data processing in supplier audits

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data processors
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 26(1) und (4)
Action
Order
Status of proceedings
unknown
Sector
Food and agriculture
Employees
10,000 or more
Published
27 Nov 2025

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers South KoreaData breaches and data security €278,912

In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.

What organisations can take from it

Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.

Relevance to training and awareness

Malware on workstations and detection of unusual access

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Repeat case
yes
Mitigating circumstances
Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
Liability of senior managers
The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
Published
23 Oct 2025

Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers South KoreaData breaches and data security €83.2m

Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.

What organisations can take from it

Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.

Relevance to training and awareness

Undetected malware in core systems

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
yes
Mitigating circumstances
Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
Liability of senior managers
There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
Published
28 Aug 2025

Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

12 Aug 2025 Nol Universe Co., Ltd. (Yanolja), Yeogi Eottae CompanyBooking platforms Yanolja and Yeogi Eottae let prepaid discount coupons expire South KoreaAbuse of market power €954,488

The two leading accommodation booking platforms sold small and medium-sized lodging businesses advertising packages whose price included discount coupons for guests, and let unused coupons expire without compensation (Yanolja at the end of the contract period, Yeogi Eottae through a validity of only one day). The KFTC (Korea Fair Trade Commission, Korea's competition authority) treated this as an abuse of a superior bargaining position, issued corrective and notification orders and imposed fines totalling KRW 1,540 million: KRW 540 million on Nol Universe (Yanolja) and KRW 1,000 million, the statutory maximum fixed-amount fine, on Yeogi Eottae.

What organisations can take from it

Platforms must not devalue services that partners have already paid for through unilateral expiry rules.

Relevance to training and awareness

Fair terms towards dependent business partners on platforms

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Competition law · Abuse of market power
Legal basis
Art. 45 Abs. 1 Nr. 6 MRFTA i. V. m. Art. 52 und Anhang 2 Nr. 6 lit. d Durchführungsverordnung (Monopoly Regulation and Fair Trade Act)
Action
Fine
Status of proceedings
unknown
Sector
Media and online platforms
Published
12 Aug 2025

Original amount 1,540,000,000 KRW, converted at the ECB reference rate of 12 Aug 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

8 May 2025 Musinsa Co., Ltd., Shinsung Tongsang Co., Ltd., E-Land World Co., Ltd., ITX Korea Co., Ltd.Greenwashing on leather products: KFTC warns four fashion chains, including ZARA operator South KoreaMisleading environmental and sustainability claims Reprimand or warning

The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) found that Musinsa, Shinsung Tongsang, E-Land World and ITX Korea (operator of ZARA in Korea) had advertised leather products, including those made of synthetic materials, with blanket environmental terms such as 'eco' without sufficient evidence, and treated this as false, exaggerated and misleading advertising under the Labeling and Advertising Act. Because all four admitted the violations and corrected them voluntarily, it limited itself to warnings, issued between 2 April and 8 May 2025 (Shinsung Tongsang 2 April, Musinsa 10 April, E-Land World and ITX Korea 8 May); according to the KFTC it was the first sanctioned greenwashing case in the fashion sector.

What organisations can take from it

Environmental claims such as 'eco' need a specific, substantiated reference to the whole product, otherwise they count as misleading.

Relevance to training and awareness

Substantiated environmental claims in advertising and product labelling

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Environment and sustainability · Misleading environmental and sustainability claims
Legal basis
Art. 3 Abs. 1 Nr. 1 Act on Fair Labeling and Advertising (Labeling and Advertising Act; falsche oder übertriebene Werbung)
Action
Reprimand or warning
Status of proceedings
unknown
Sector
Retail and e-commerce
Mitigating circumstances
All four companies admitted the violations and corrected them voluntarily; the KFTC therefore limited itself to warnings.
Published
15 May 2025

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing South KoreaMarketing and consent €8.51m

From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.

What organisations can take from it

Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.

Relevance to training and awareness

Purpose limitation and data misuse by employees

Missing or inadequate training played a role in the decision.

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · Marketing and consent
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
Liability of senior managers
Measures against individuals are not set out here.
Published
27 Mar 2025

Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

12 Mar 2025 SK Telecom Co., Ltd., KT Co., Ltd., LG Uplus Co., Ltd.Mobile cartel: SK Telecom, KT and LG Uplus jointly steered switching figures South KoreaCartels and collusion €72.1m

According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), the three mobile network operators agreed in November 2015 to balance net gains and losses of new subscribers porting their numbers so that they would not concentrate on one operator, and implemented this until the end of September 2022 by coordinating their sales incentives for dealers with one another; they exchanged the information in a joint market monitoring group with the industry association KAIT. The KFTC issued cease-and-desist orders and provisionally set fines totalling KRW 114,026 million (SK Telecom KRW 42,662 million, KT KRW 33,029 million, LG Uplus KRW 38,334 million).

What organisations can take from it

Self-regulatory bodies must not become a forum in which competitors coordinate customer gains and terms.

Relevance to training and awareness

Cartel risks in industry bodies and self-regulation

Authority / court
Korea Fair Trade Commission (KFTC)
Area of law
Competition law · Cartels and collusion
Legal basis
Art. 40 Abs. 1 Nr. 3 MRFTA (Monopoly Regulation and Fair Trade Act)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
12 Mar 2025

Original amount 114,026,000,000 KRW, converted at the ECB reference rate of 12 Mar 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

22 Jan 2025 Kakaopay Corp.Kakao Pay: 5.968 billion KRW for transferring user data to Alipay without consent South KoreaInternational data transfers €3.99m

Kakaopay Corp. transferred data on all users three times in 2018 and, from June 2019 to May 2024, data on around 40 million users every day without consent to Alipay in Singapore, which used it to calculate for Apple a score for the likelihood of insufficient funds on bundled App Store payments (NSF score). The authority treated this as an unlawful transfer abroad, imposed a penalty surcharge of 5,968,000,000 KRW and ordered remediation and publication of the decision on the company’s website. In separate decisions on the same day Apple received a penalty surcharge of 2,405,000,000 KRW and an administrative fine of 2,200,000 KRW, and Alipay was ordered to delete the scoring model.

What organisations can take from it

Anyone passing customer data to a partner’s foreign service provider must check whether this is a transfer requiring consent and limit the data to what is necessary.

Relevance to training and awareness

Data sharing with partners’ foreign service providers

Authority / court
Personal Information Protection Commission (PIPC, 개인정보보호위원회)
Area of law
Data protection · International data transfers
Legal basis
Personal Information Protection Act (개인정보 보호법) Art. 28-8(1); Sanktion nach Art. 64-2(1) Nr. 9
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Mitigating circumstances
Reduction of 30% for completed remediation, cooperation and ISMS-P certification; increase of 50% because the infringement lasted more than two years (June 2019 to May 2024).
Published
23 Jan 2025

Original amount 5,968,000,000 KRW, converted at the ECB reference rate of 22 Jan 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Load 5 more of 5

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial