Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,019 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Personal Information Protection Commission (PIPC, 개인정보보호위원회) 11 cases 44 % · €396.1m
- Korea Fair Trade Commission (KFTC) 8 cases 32 % · €627.8m
- Korea Financial Intelligence Unit (KoFIU) 2 cases 8 % · €42.1m
- Korea Media and Communications Commission (KMCC, 방송미디어통신위원회) 2 cases 8 % · €1.76m
- Financial Supervisory Service (FSS) 1 case 4 % · €45,990
- Ministry of Science and ICT (MSIT, 과학기술정보통신부) 1 case 4 % · €3,396
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
- Financial services and insurance 7 cases 28 % · €217m
- Media and online platforms 5 cases 20 % · €17.1m
- Retail and e-commerce 4 cases 16 % · €249m
- Telecoms, IT and software 4 cases 16 % · €188.4m
- Food and agriculture 2 cases 8 % · €384.3m
- Manufacturing and mechanical engineering 1 case 4 % · €1.93m
- Public sector 1 case 4 % · €141,669
- Transport, logistics and shipping 1 case 4 % · €10m
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 4 | €28.6m |
| Q1 2025 | 4 | €84.8m |
| Q2 2025 | 1 | – |
| Q3 2025 | 2 | €84.1m |
| Q4 2025 | 3 | €20.9m |
| Q1 2026 | 2 | €179.7m |
| Q2 2026 | 4 | €625.7m |
| Q3 2026 | 5 | €44m |
| Q4 2026 | 0 | – |
25 cases
17 Sep 2026 PFC Technologies Co., Ltd. (vormals PeopleFund Company)P2P lending platform shared customer data without consent: FSS sanctions PFC €45,990
According to the sanctions disclosure of the Financial Supervisory Service (FSS, Korea's financial supervisor), the online lending platform PFC Technologies transferred the resident registration numbers of 8,497 customers to a third party without their consent on 28 September 2022 in order to calculate the error rate of a new service for mortgage customers, and received credit information on the same customers from that third party, likewise without consent (such as the address and official value of their properties); in addition, when the inspection began it had not implemented password rules against easily guessed numbers. The sanction of 17 September 2026 comprises an institutional warning, an administrative fine (과태료) of KRW 24 million and a penalty surcharge (과징금) of KRW 49 million, KRW 73 million in total.
Even for internal tests and quality measurements, customer data may only be passed to third parties with consent or a clear legal basis.
Consent for sharing credit data and password rules
- Authority / court
- Financial Supervisory Service (FSS)
- Area of law
- Data protection
- Legal basis
- Art. 19, 32 und 34 Credit Information Use and Protection Act; Art. 16, 28 und 29 Durchführungsverordnung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 17 Sep 2026
Original amount 73,000,000 KRW, converted at the ECB reference rate of 17 Sep 2026.
- FSS 제재내용 공개 (Sanktionsveröffentlichung), 피에프씨테크놀로지스 주식회사, 17.09.2026 Enforcement database of an authority
- FSS-PDF: 피에프씨테크놀로지스 제재내용 공개안 Decision of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
9 Sep 2026 Moorim P&P, Moorim Paper, Hansol Paper u. a. (6 Unternehmen)Bid-rigging for printing paper for Nongmin News: six paper firms sanctioned €1.93m
According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), six manufacturers and distributors of printing paper fixed in advance the winning bidder, cover bidders and bid prices in six tenders issued by the publisher Nongmin News Corp. between June 2021 and November 2024; the average winning bid rate was around 96.2%, compared with 87.6% in 2018 to 2020. The KFTC issued corrective orders, imposed fines totalling KRW 3,009 million (Moorim SP KRW 59 million, Moorim Paper KRW 573 million, Moorim P&P KRW 948 million, Hansol Paper KRW 556 million, Hankuk Paper KRW 515 million, Hongwon Paper KRW 358 million).
Competition compliance reviews should always cover tender business as well as general pricing, because collusion there often runs in parallel.
Bid-rigging in tenders
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 40 Abs. 1 Nr. 8 MRFTA (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Manufacturing and mechanical engineering
- Published
- 9 Sep 2026
Original amount 3,009,000,000 KRW, converted at the ECB reference rate of 9 Sep 2026.
- KFTC press release (EN), 10 Sep 2026: KFTC Sanctions Bid-Rigging in Nongmin News Corp. Printing Paper Tenders Press release of an authority
- KFTC-Pressemitteilung (KO), 09.09.2026: 농민신문사 발주 인쇄용지 입찰담합 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Bußgeldtabelle je Unternehmen und Rechtsgrundlage Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Aug 2026 GS Retail Co., Ltd.GS Retail: 12.839 billion KRW after credential stuffing on GS SHOP and GS25 €7.95m
Using credentials stolen elsewhere, attackers logged in en masse on the websites of GS SHOP (June 2024 to February 2025) and GS25 (December 2024 to January 2025) and obtained data on 1,581,025 and 79,128 people respectively; GS Retail Co., Ltd. detected neither the bursts of login attempts from the same IP addresses nor the rising number of failed attempts, and after the first discovery at GS25 did not stop the parallel attack on GS SHOP. The authority also found an inadequate data protection organisation and that 1,599 further people were notified more than 72 hours late, imposed a penalty surcharge of 12,836,000,000 KRW and an administrative fine of 3,000,000 KRW (12,839,000,000 KRW in total) and ordered detection measures and a review of the data protection organisation.
Login pages need rate limiting and anomaly detection; after a first credential-stuffing finding, all of a company’s portals must be checked.
Credential stuffing and password reuse
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 40% for cooperation, remediation and protective efforts (ISMS-P certification, self-regulation, privacy impact assessment); increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to deploy dedicated data protection staff and to define the powers and responsibility of its chief privacy officer (CPO) clearly.
- Published
- 31 Aug 2026
Original amount 12,839,000,000 KRW, converted at the ECB reference rate of 26 Aug 2026.
- PIPC, 심의·의결서 제2026-017-107호 (㈜지에스리테일), 26.08.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0004 Enforcement database of an authority
- PIPC-Pressemitteilung vom 31.08.2026: ㈜지에스리테일 유출사고에 대해 과징금 128억 3,600만 원, 과태료 300만 원 부과 Press release of an authority
- PIPC press release (English), 03.09.2026: The PIPC Sanctions GS Retail and Three Other Businesses Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
29 Jul 2026 KT CorporationKT: 53.979 billion KRW after data leak through manipulated femtocells €32.7m
Attackers copied certificates from lost femtocells of KT Corporation into home-made devices, stayed connected to the mobile network undetected for around eleven months, intercepted data on 16,647 subscribers (phone number, IMSI, IMEI) and used intercepted confirmation codes to trigger unauthorised mobile payments of around 240 million KRW affecting 368 people. For inadequate access control – certificates valid for ten years, no IP restriction, no detection of unknown cell IDs – the authority imposed a penalty surcharge of 53,979,000,000 KRW and ordered vulnerability checks and a stronger role for the chief privacy officer.
Network devices at customer premises are part of the attack surface too – lost devices, long-lived certificates and missing anomaly detection open up the core network.
Lost network devices and certificate management
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Sanktion nach Art. 64-2(1) Nr. 9; gesonderter Beschluss 제2026-015-094호: Art. 63(1)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Culpability
- negligent
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for cooperation, remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years.
- Liability of senior managers
- The company was ordered to define the responsibility and role of its chief privacy officer (CPO) for the whole company clearly and to revise its governance.
- Published
- 30 Jul 2026
Original amount 53,979,000,000 KRW, converted at the ECB reference rate of 29 Jul 2026.
- PIPC, 심의·의결서 제2026-015-093호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, 심의·의결서 제2026-015-094호 (주식회사 케이티), 29.07.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0113-02 등 2건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 30.07.2026: ‘㈜KT의 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 07.08.2026: The PIPC Sanctions KT Corporation for Data Breaches Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
6 Jul 2026 Agoda Company Pte. Ltd.Agoda: 2.424 billion KRW for unclear refund conditions and fees €1.39m
In its flight booking flow, Agoda Company Pte. Ltd. did not show clearly whether a ticket was refundable and which cancellation or change fees applied – the information could only be reached via a link to baggage rules – and, for accommodation paid later, displayed a price without the possible surcharge of up to 5%, partly in a foreign currency. The authority regarded this as a breach of the duty to explain key terms under the Telecommunications Business Act (전기통신사업법), imposed a fine of 2,424,000,000 KRW and ordered Agoda to show conditions, fees and final prices early and clearly, to check screen flows internally in advance and to have Korean translations reviewed by professionals.
Refundability, fees and the final price belong in the booking flow itself – not behind links with unrelated labels.
- Authority / court
- Korea Media and Communications Commission (KMCC, 방송미디어통신위원회)
- Area of law
- Consumer protection and online retail · Information duties in online retail
- Legal basis
- Telecommunications Business Act (전기통신사업법) Art. 50(1) Nr. 5-2, Art. 52, Art. 53; Enforcement Decree Art. 42 i. V. m. Anhang 4
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- no
- Mitigating circumstances
- Reduction of 10% because the authority had not imposed a fine in the preceding three years; partial voluntary corrections made after the investigation began were not accepted as a mitigating factor.
- Published
- 6 Jul 2026
Original amount 2,424,000,000 KRW, converted at the ECB reference rate of 6 Jul 2026.
- KMCC, 심의·의결 제2026-22-464호 (아고다 컴퍼니 유한회사, Agoda Company Pte. Ltd.), 06.07.2026 Decision of an authority
- KMCC, Entscheidungsdatenbank 심결정보 (Eintrag Nr. 776) Enforcement database of an authority
- KMCC-Pressemitteilung vom 06.07.2026: ‘환불 조건·수수료 불명확’ 아고다에 과징금 Press release of an authority
- KMCC-Pressemitteilung vom 06.07.2026 (PDF) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
10 Jun 2026 Coupang Corp.Coupang: 423.6 billion KRW after data leak by a former employee €240.8m
A former employee used authentication signing keys that had been accessible to him in plain text during his employment and were neither renewed nor destroyed after he left to create forged tokens and, from April to November 2025, retrieve data on around 33.22 million customers and delivery data on around 4.33 million other people. For inadequate security measures the authority imposed a penalty surcharge of 423,575,000,000 KRW on Coupang Corp. and, for late notification and failure to delete, an administrative fine of 16,800,000 KRW (423,591,800,000 KRW in total) and criticised the exclusion of the chief privacy officer from the internal investigation. A separate decision on the same day imposed a further 201,106,000,000 KRW for collecting behavioural data on third-party websites and apps without consent.
When employees leave, every key and credential they knew must be renewed immediately – otherwise a single signing key can open the entire customer account system.
Offboarding: revoking access and keys
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 34(1), Art. 21(1), Art. 31(6), Art. 63(2); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Culpability
- negligent
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and 50% for remediation, compensation, certification and proportionality; increases of 25% (duration of the infringement), 30% (at least two previous penalties) and 10% (obstruction of the investigation).
- Liability of senior managers
- The chief privacy officer (CPO) was excluded from the internal investigation and publication; the company was ordered to set up governance that secures the CPO’s independent work and access to information in incidents.
- Published
- 11 Jun 2026
Original amount 423,591,800,000 KRW, converted at the ECB reference rate of 10 Jun 2026.
- PIPC, 심의·의결서 제2026-011-075호 (쿠팡 주식회사), 10.06.2026 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025-조이-0149 Enforcement database of an authority
- PIPC-Pressemitteilung vom 11.06.2026: 쿠팡 및 계열사의 개인정보 유출 및 침해 제재처분 의결 Press release of an authority
- PIPC press release (English), 17.06.2026: The PIPC Sanctions Coupang and CFS Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
9 Jun 2026 Coupang Corp.Coupang advertised a one-off coupon price as a permanent 'WOW Member Price' €283,216
From 26 August 2020 to 15 May 2022, Coupang advertised a 'WOW Member Price' below the regular selling price in its online shop without disclosing that it included a coupon redeemable only once by new members of its paid WOW subscription. The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) treated the omission of this information as deceptive advertising, issued a corrective order and imposed a fine of KRW 500 million, the statutory maximum fixed-amount fine.
Member prices may only be advertised in the way customers actually receive them repeatedly; one-off discounts must be clearly labelled.
Transparent pricing of membership discounts
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Art. 3 Abs. 1 Nr. 2 Act on Fair Labeling and Advertising (täuschende Werbung)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 9 Jun 2026
Original amount 500,000,000 KRW, converted at the ECB reference rate of 9 Jun 2026.
- KFTC press release (EN), 10 Jun 2026: Sanctions Against Coupang Corp. for Deceptive Advertising of Its 'WOW Member Price' Press release of an authority
- KFTC-Pressemitteilung (KO), 09.06.2026: 와우회원가 광고 관련, 쿠팡(주)의 표시광고법 위반행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF): Art. 3 Abs. 1 Nr. 2 표시광고법, 과징금 5억 원 Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
20 May 2026 Sajo DongAOne, Daehan Flour Mills, CJ CheilJedang u. a. (7 Unternehmen)Flour cartel: record KRW 671bn fine on seven mills €384.3m
According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), seven flour manufacturers with a combined 87.7% of the B2B market coordinated, on 24 occasions between November 2019 and October 2025, the timing and extent of price changes as well as supply volumes and supply rankings towards large buyers such as noodle and confectionery manufacturers, including while receiving government price stabilisation subsidies. In addition to a cease-and-desist order, the KFTC ordered an independent re-determination of prices and imposed fines totalling KRW 671,045 million, the highest amount in any cartel case to date: Sajo DongAOne KRW 183,097 million, Daehan Flour Mills KRW 179,273 million, CJ CheilJedang KRW 131,701 million, Samyang KRW 94,787 million, Daesun Flour Mills KRW 38,448 million, Hantop KRW 24,291 million, Samhwa Flour Mills KRW 19,448 million.
Anyone already sanctioned for a cartel must expect considerably harsher consequences if contacts with competitors resume.
Price and volume agreements with competitors
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 40 Abs. 1 Nr. 1 und Nr. 3 MRFTA (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Repeat case
- yes
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 20 May 2026
Original amount 671,045,000,000 KRW, converted at the ECB reference rate of 20 May 2026.
- KFTC press release (EN), 21 May 2026: Sanctions Imposed on Seven Flour Millers for Flour Price-Fixing Press release of an authority
- KFTC-Pressemitteilung (KO), 20.05.2026: 7개 제분사 밀가루 담합 적발·제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Tabelle 5 (Geldbußen je Mühle) und Rechtsgrundlage Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 May 2026 KT CorporationKT: 640 million KRW for cancelled Galaxy S25 pre-orders and false notices €370,997
In its own online shop for Galaxy S25 pre-orders, KT Corporation stated that benefits would apply unless the end of the promotion was shown, but then limited them to the first 1,000 orders and unilaterally cancelled 7,127 pre-orders that had come in via a YouTube channel and Genie TV and had already been fully completed. The authority regarded this as false information on key terms and an unjustified refusal to conclude contracts under the Telecommunications Business Act (전기통신사업법), imposed a fine of 640,000,000 KRW and ordered KT to show additional pre-order benefits clearly in future.
Promotion terms such as quotas must be visible before the contract is concluded – cancelling completed orders afterwards is no solution.
- Authority / court
- Korea Media and Communications Commission (KMCC, 방송미디어통신위원회)
- Area of law
- Consumer protection and online retail · Misleading advertising and pricing
- Legal basis
- Telecommunications Business Act (전기통신사업법) Art. 50(1) Nr. 5 und Nr. 5-2
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 8 May 2026
Original amount 640,000,000 KRW, converted at the ECB reference rate of 8 May 2026.
- KMCC-Pressemitteilung vom 08.05.2026: ‘케이티(KT)’ 사전예약 이벤트 취소, 과징금 부과 Press release of an authority
- KMCC-Pressemitteilung vom 08.05.2026 (PDF) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
17 Mar 2026 Bithumb Co., Ltd.Bithumb: partial suspension and KRW 36.9bn fine for anti-money laundering breaches €21.5m
The KoFIU (Korea Financial Intelligence Unit) found that the crypto exchange Bithumb had processed 45,772 transfers of crypto assets with 18 virtual asset service providers that had not complied with their reporting obligation between August 2022 and April 2025, and had breached customer identification duties and the associated transaction restrictions in large numbers; there were also shortcomings in suspicious transaction reporting, record keeping and the risk assessment of new products. On 17 March 2026 it ordered a six-month partial suspension of business (no transfers of crypto assets for new customers from 27 March to 26 September 2026) and imposed a fine of KRW 36,873.5 million. The amount and the facts have not been confirmed against the primary source.
Crypto exchanges must check counterparties for deposits and withdrawals against the register of reported providers before allowing transfers.
Counterparty checks and customer identification for crypto transfers
- Authority / court
- Korea Financial Intelligence Unit (KoFIU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 4, 5, 5-2, 5-4 und 8 Act on Reporting and Using Specified Financial Transaction Information; Art. 9, 10-6, 10-9 und 10-20 Durchführungsverordnung (Teilsperre wegen Art. 8 i. V. m. Art. 10-20 DVO: Geschäfte mit nicht gemeldeten Anbietern)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 17 Mar 2026
Original amount 36,873,500,000 KRW, converted at the ECB reference rate of 17 Mar 2026.
- KoFIU 제재공시, Detailseite Eintrag Nr. 119 (17.03.2026) mit PDF (주)빗썸 제재내용 공개안 Enforcement database of an authority
- KoFIU 제재공시 (Sanktionsveröffentlichungen), Eintrag Nr. 119 vom 17.03.2026: (주)빗썸 제재내용 공개안 (PDF), dazu Nr. 118 개선조치 요구사항 Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
21 Jan 2026 KB Kookmin Bank, Shinhan Bank, Woori Bank, Hana BankFour major banks exchanged loan-to-value ratios: KRW 272bn fine €158.2m
According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), the four banks exchanged their complete loan-to-value (LTV) ratios for mortgage lending over a long period, between 736 and 7,500 individual values per bank, and adjusted their own ratios accordingly; only conduct from December 2021, when the express prohibition of anti-competitive information exchange entered into force, was pursued. The KFTC issued cease-and-desist orders and fines totalling KRW 272,014 million (Kookmin KRW 69,747 million, Shinhan KRW 63,801 million, Woori KRW 51,535 million, Hana KRW 86,931 million), the first application of that provision.
Exchanging individual contract terms with competitors is a stand-alone competition law infringement even without price fixing.
Information exchange with competitors
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 40 Abs. 1 Nr. 9 MRFTA i. V. m. Art. 44 Abs. 2 Nr. 3 Durchführungsverordnung (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 21 Jan 2026
Original amount 272,014,000,000 KRW, converted at the ECB reference rate of 21 Jan 2026.
- KFTC press release (EN), 22 Jan 2026: KFTC Sanctions Four Major Commercial Banks for Collusive Information Exchange Press release of an authority
- KFTC-Pressemitteilung (KO), 21.01.2026: 4대 시중은행의 정보교환의 담합 행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Bußgeldtabelle je Bank und Rechtsgrundlage Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
9 Dec 2025 Dunamu Inc.Upbit operator Dunamu: KRW 35.2bn fine for customer due diligence failures €20.6m
The KoFIU (Korea Financial Intelligence Unit) found that Dunamu, operator of the crypto exchange Upbit, had failed to identify customers with due care in 5,324,165 cases between October 2021 and October 2024, for instance where identity documents could not be verified, were mere copies or photos, or where addresses were blank or implausible, and had nevertheless allowed transactions in 3,331,570 of these cases. In addition, it failed to file suspicious transaction reports on 15 customers linked to warrant applications by investigative authorities, and its monitoring system did not detect unusual patterns such as large crypto deposits followed by sale and withdrawal; KoFIU imposed a fine of KRW 35,215.6 million on 9 December 2025. The amount and the facts have not been confirmed against the primary source.
Digital onboarding processes need checks that reliably reject copies of identity documents and implausible addresses before trading is possible.
Customer identification (KYC) at crypto exchanges
- Authority / court
- Korea Financial Intelligence Unit (KoFIU)
- Area of law
- Money laundering and terrorist financing · Customer due diligence
- Legal basis
- Art. 4, 5, 5-2 und 8 Act on Reporting and Using Specified Financial Transaction Information; Art. 9, 10-4, 10-6 und 10-20 Durchführungsverordnung
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 9 Dec 2025
Original amount 35,215,600,000 KRW, converted at the ECB reference rate of 9 Dec 2025.
- KoFIU 제재공시, Detailseite Eintrag Nr. 108 (09.12.2025) mit PDF 두나무(주) 제재내용 공개안 Enforcement database of an authority
- KoFIU 제재공시 (Sanktionsveröffentlichungen), Eintrag Nr. 108 vom 09.12.2025: 두나무(주) 제재내용 공개안 (PDF) Enforcement database of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Nov 2025 Starbucks CorporationStarbucks: order over inadequate oversight of audit provider in Korea Order
Starbucks Corporation had suppliers in Korea audited under its Ethical Sourcing Program by Elevate Hong Kong Holdings Limited, did not conclude a processing contract containing all statutory terms and did not supervise the provider adequately; Elevate processed unnecessarily large amounts of data on supplier employees, such as personnel files, wage and working-time records, and transferred them out of the businesses. The authority ordered Starbucks to award such work only under a written contract with all mandatory terms and to train and supervise the provider, and recommended data minimisation; a separate order was issued against Elevate.
Supply chain audits process personal data too – the commissioning company needs a complete processing contract and must check that the audit provider collects no more than necessary.
Data processing in supplier audits
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data processors
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 26(1) und (4)
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Food and agriculture
- Employees
- 10,000 or more
- Published
- 27 Nov 2025
- PIPC, 심의·의결서 제2025-024-301호 (Starbucks Corporation), 26.11.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2023조일0035 등 3건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.11.2025: 개인정보를 과다 수집‧처리한 스타벅스 본사(미국), 엘리베이트(홍콩)에 시정명령 Press release of an authority
- PIPC press release (English), 03.12.2025: The PIPC Issues Correction Orders on Starbucks and Elevate Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
22 Oct 2025 Incruit CorporationIncruit: 463 million KRW after repeat data leak affecting 7.3 million job seekers €278,912
In January 2025 attackers infected the work computer of an employee of the online job portal Incruit with malware, took over the employee’s database access and, until February 2025, extracted data on all 7,275,843 members and 54,475 stored CVs, cover letters and copies of certificates (438 GB in total). Despite conspicuous database access outside business hours, the company only noticed the leak through an extortion message; it had already been sanctioned in July 2023 for inadequate access controls. The authority imposed a penalty surcharge of 463,000,000 KRW and ordered the appointment of a qualified chief privacy officer and a plan to prevent further incidents and support those affected.
Anyone who makes only piecemeal fixes after a first incident risks a higher penalty – database access outside business hours must trigger an alert.
Malware on workstations and detection of unusual access
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29; Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 55% because no benefit was derived and the company is a medium-sized enterprise under the Korean Framework Act on Small and Medium Enterprises, and a further 20% for cooperation, remediation and self-regulation; increase of 65% because the infringement lasted more than two years and because of the July 2023 sanction.
- Liability of senior managers
- The company was ordered to appoint a new, qualified chief privacy officer (CPO) and to define the CPO’s responsibility clearly.
- Published
- 23 Oct 2025
Original amount 463,000,000 KRW, converted at the ECB reference rate of 22 Oct 2025.
- PIPC, 심의·의결서 제2025-022-256호 (인크루트(주)), 22.10.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.10.2025: 취업 준비생 개인정보를 유출한 인크루트에 과징금 4.6억원 부과 Press release of an authority
- PIPC press release (English), 24.10.2025: The PIPC Sanctions Incruit over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
27 Aug 2025 SK Telecom Co., Ltd.SK Telecom: 134.8 billion KRW after leak of USIM data on around 23 million customers €83.2m
Attackers who had planted malware in systems of SK Telecom Co., Ltd. since August 2021 took 9.82 GB of data on around 23 million subscribers from the home subscriber server in April 2025, including USIM authentication keys and IMSI. The authority found a lack of network segregation and access controls, authentication data not securely encrypted, missing security updates, an inadequate set-up of the chief privacy officer function and late notification of those affected. It imposed a penalty surcharge of 134,791,000,000 KRW and an administrative fine of 9,600,000 KRW (134,800,600,000 KRW in total) and issued orders on security, governance and oversight of service providers and sales partners.
Core mobile network systems belong in the protection and certification scheme – leaving them out means overlooking attackers who have been embedded for years.
Undetected malware in core systems
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 29, Art. 31(1) und (3), Art. 34(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Repeat case
- yes
- Mitigating circumstances
- Reduction of 30% because no benefit was derived and a further 50% for completed remediation, compensation of those affected and protective efforts; increase of 50% because the infringement lasted more than two years. Cooperation was not taken into account because documents were submitted late.
- Liability of senior managers
- There was no chief privacy officer (CPO) with overall responsibility; the company was ordered to define the CPO’s responsibility and role clearly and to rebuild its governance.
- Published
- 28 Aug 2025
Original amount 134,800,600,000 KRW, converted at the ECB reference rate of 27 Aug 2025.
- PIPC, 심의·의결서 제2025-018-243호 (에스케이텔레콤 주식회사), 27.08.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2025조이0056 Enforcement database of an authority
- PIPC-Pressemitteilung vom 28.08.2025: ‘SK텔레콤 개인정보 유출사고’ 제재처분 의결 Press release of an authority
- PIPC press release (English), 03.09.2025: The PIPC Sanctions SKT over Data Breach Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
12 Aug 2025 Nol Universe Co., Ltd. (Yanolja), Yeogi Eottae CompanyBooking platforms Yanolja and Yeogi Eottae let prepaid discount coupons expire €954,488
The two leading accommodation booking platforms sold small and medium-sized lodging businesses advertising packages whose price included discount coupons for guests, and let unused coupons expire without compensation (Yanolja at the end of the contract period, Yeogi Eottae through a validity of only one day). The KFTC (Korea Fair Trade Commission, Korea's competition authority) treated this as an abuse of a superior bargaining position, issued corrective and notification orders and imposed fines totalling KRW 1,540 million: KRW 540 million on Nol Universe (Yanolja) and KRW 1,000 million, the statutory maximum fixed-amount fine, on Yeogi Eottae.
Platforms must not devalue services that partners have already paid for through unilateral expiry rules.
Fair terms towards dependent business partners on platforms
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Abuse of market power
- Legal basis
- Art. 45 Abs. 1 Nr. 6 MRFTA i. V. m. Art. 52 und Anhang 2 Nr. 6 lit. d Durchführungsverordnung (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Media and online platforms
- Published
- 12 Aug 2025
Original amount 1,540,000,000 KRW, converted at the ECB reference rate of 12 Aug 2025.
- KFTC press release (EN), 13 Aug 2025: KFTC Sanctions Yanolja and Yeogi Eottae for Abuse of Superior Bargaining Position Press release of an authority
- KFTC-Pressemitteilung (KO), 12.08.2025: 2개 숙박앱 사업자의 거래상지위 남용행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Rechtsgrundlage und Maßnahmen je Unternehmen Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
8 May 2025 Musinsa Co., Ltd., Shinsung Tongsang Co., Ltd., E-Land World Co., Ltd., ITX Korea Co., Ltd.Greenwashing on leather products: KFTC warns four fashion chains, including ZARA operator Reprimand or warning
The KFTC (Korea Fair Trade Commission, Korea's competition and consumer authority) found that Musinsa, Shinsung Tongsang, E-Land World and ITX Korea (operator of ZARA in Korea) had advertised leather products, including those made of synthetic materials, with blanket environmental terms such as 'eco' without sufficient evidence, and treated this as false, exaggerated and misleading advertising under the Labeling and Advertising Act. Because all four admitted the violations and corrected them voluntarily, it limited itself to warnings, issued between 2 April and 8 May 2025 (Shinsung Tongsang 2 April, Musinsa 10 April, E-Land World and ITX Korea 8 May); according to the KFTC it was the first sanctioned greenwashing case in the fashion sector.
Environmental claims such as 'eco' need a specific, substantiated reference to the whole product, otherwise they count as misleading.
Substantiated environmental claims in advertising and product labelling
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Environment and sustainability · Misleading environmental and sustainability claims
- Legal basis
- Art. 3 Abs. 1 Nr. 1 Act on Fair Labeling and Advertising (Labeling and Advertising Act; falsche oder übertriebene Werbung)
- Action
- Reprimand or warning
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Mitigating circumstances
- All four companies admitted the violations and corrected them voluntarily; the KFTC therefore limited itself to warnings.
- Published
- 15 May 2025
- KFTC press release (EN), 15 May 2025: Sanctions Imposed on Four Fashion SPA Business Operators for Violations of the Act on Fair Labeling and Advertising in Relation to Eco-friendliness Press release of an authority
- KFTC-Pressemitteilung (KO), 15.05.2025: 4개 패션 SPA브랜드 사업자의 부당한 광고행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF): Verwarnung (경고) der vier Unternehmen mit Datum je Unternehmen, Art. 3 Abs. 1 Nr. 1 표시광고법 Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
26 Mar 2025 Woori Card Co., Ltd.Woori Card: 13.451 billion KRW after a branch used merchant data for card marketing €8.51m
From July 2022 to April 2024, the Incheon sales branch of Woori Card Co., Ltd. looked up data on at least 207,538 owners of card-accepting merchants in the merchant management system, including resident registration numbers, and passed it via chat and e-mail to card recruiters, who used it to market new credit cards; 74,692 of those affected had not consented to marketing. The authority also criticised excessively broad access rights and the company’s failure to intervene despite more than 30 million look-ups and downloads a month, and imposed a penalty surcharge of 13,451,000,000 KRW. It ordered a review of internal controls, training and supervision of staff, minimised access rights and regular log reviews.
Access rights to customer databases must be limited to what is necessary and bulk look-ups monitored automatically – otherwise a sales branch becomes a data source for sales.
Purpose limitation and data misuse by employees
Missing or inadequate training played a role in the decision.
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 18(1), Art. 24-2(1), Art. 29; Sanktion nach Art. 64-2(1) Nr. 1
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 50% for an ISMS-P certification; increase of 25% because the infringement lasted around one year and nine months.
- Liability of senior managers
- Measures against individuals are not set out here.
- Published
- 27 Mar 2025
Original amount 13,451,000,000 KRW, converted at the ECB reference rate of 26 Mar 2025.
- PIPC, 심의·의결서 제2025-007-021호 (주식회사 우리카드), 26.03.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조일0034 Enforcement database of an authority
- PIPC-Pressemitteilung vom 27.03.2025: 개인정보를 목적 외로 이용한 ㈜우리카드에 과징금 134억 5,100만 원 부과 Press release of an authority
- PIPC press release (English), 28.03.2025: The PIPC Sanctions Woori Card Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
12 Mar 2025 SK Telecom Co., Ltd., KT Co., Ltd., LG Uplus Co., Ltd.Mobile cartel: SK Telecom, KT and LG Uplus jointly steered switching figures €72.1m
According to the KFTC (Korea Fair Trade Commission, Korea's competition authority), the three mobile network operators agreed in November 2015 to balance net gains and losses of new subscribers porting their numbers so that they would not concentrate on one operator, and implemented this until the end of September 2022 by coordinating their sales incentives for dealers with one another; they exchanged the information in a joint market monitoring group with the industry association KAIT. The KFTC issued cease-and-desist orders and provisionally set fines totalling KRW 114,026 million (SK Telecom KRW 42,662 million, KT KRW 33,029 million, LG Uplus KRW 38,334 million).
Self-regulatory bodies must not become a forum in which competitors coordinate customer gains and terms.
Cartel risks in industry bodies and self-regulation
- Authority / court
- Korea Fair Trade Commission (KFTC)
- Area of law
- Competition law · Cartels and collusion
- Legal basis
- Art. 40 Abs. 1 Nr. 3 MRFTA (Monopoly Regulation and Fair Trade Act)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 12 Mar 2025
Original amount 114,026,000,000 KRW, converted at the ECB reference rate of 12 Mar 2025.
- KFTC press release (EN), 13 Mar 2025: KFTC Sanctions Three Telecommunication Companies for Collusion in Mobile Number Portability New Subscriber Adjustments Press release of an authority
- KFTC-Pressemitteilung (KO), 12.03.2025: 이동통신 3사의 담합행위 제재 Press release of an authority
- KFTC-Pressemitteilung (KO, PDF) mit Bußgeldtabelle je Unternehmen und Rechtsgrundlage Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
22 Jan 2025 Kakaopay Corp.Kakao Pay: 5.968 billion KRW for transferring user data to Alipay without consent €3.99m
Kakaopay Corp. transferred data on all users three times in 2018 and, from June 2019 to May 2024, data on around 40 million users every day without consent to Alipay in Singapore, which used it to calculate for Apple a score for the likelihood of insufficient funds on bundled App Store payments (NSF score). The authority treated this as an unlawful transfer abroad, imposed a penalty surcharge of 5,968,000,000 KRW and ordered remediation and publication of the decision on the company’s website. In separate decisions on the same day Apple received a penalty surcharge of 2,405,000,000 KRW and an administrative fine of 2,200,000 KRW, and Alipay was ordered to delete the scoring model.
Anyone passing customer data to a partner’s foreign service provider must check whether this is a transfer requiring consent and limit the data to what is necessary.
Data sharing with partners’ foreign service providers
- Authority / court
- Personal Information Protection Commission (PIPC, 개인정보보호위원회)
- Area of law
- Data protection · International data transfers
- Legal basis
- Personal Information Protection Act (개인정보 보호법) Art. 28-8(1); Sanktion nach Art. 64-2(1) Nr. 9
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Mitigating circumstances
- Reduction of 30% for completed remediation, cooperation and ISMS-P certification; increase of 50% because the infringement lasted more than two years (June 2019 to May 2024).
- Published
- 23 Jan 2025
Original amount 5,968,000,000 KRW, converted at the ECB reference rate of 22 Jan 2025.
- PIPC, 심의·의결서 제2025-001-002호 (㈜카카오페이), 22.01.2025 Decision of an authority
- PIPC, Entscheidungsdatenbank (위원회 결정문), Eintrag 2024조삼0005 등 3건 Enforcement database of an authority
- PIPC-Pressemitteilung vom 23.01.2025: 개인정보 무단 국외 이전한 카카오페이·애플에 과징금·과태료 부과 Press release of an authority
- PIPC press release (English), 31.01.2025: The PIPC Sanctions Kakao Pay and Apple Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link