GRC Report Staff

South Korea’s Privacy Regulator Hits SK Telecom with $99.9 Million Sanction over Massive Data Breach

South Korea’s Personal Information Protection Commission (PIPC) has imposed one of the country’s largest-ever privacy penalties on SK Telecom (SKT), ordering the mobile carrier to pay $99.9 million (KRW 134.8 billion) after a series of failures that exposed the personal information of more than 23 million subscribers.

Disney to Pay $10 Million in FTC Settlement Over Children’s Data Collection on YouTube

Disney will pay $10 million to settle allegations from the Federal Trade Commission (FTC) that it violated children’s online privacy protections by mislabeling YouTube videos, allowing the unlawful collection of personal data from under-13 viewers. The case not only imposes a financial penalty on one of the biggest names in entertainment but also signals a shift in how regulators expect companies to safeguard kids’ online experiences.

SocGen Fined $2.55 Million Over Market Gatekeeper Failures

One of the biggest players in Australia’s futures market has been hit with a $2.55 million (AUD 3.88 million) penalty after failing to stop a wave of suspicious trading orders in the electricity and wheat futures market. The Market Disciplinary Panel (MDP) imposed the fine on SocGen, following an ASIC investigation that found the firm breached market integrity rules by permitting two clients to place 33 suspicious orders between May 2023 and February 2024.

Furniture Retail Chain Fined in GDPR Ruling

The Western High Court in Denmark has imposed a fine of $216,000 (DKK 1.5 million) on ILVA, a Danish furniture retail chain known for its Scandinavian-style home furnishings, for violating the General Data Protection Regulation (GDPR). The ruling establishes an important precedent for how fines against companies are calculated.

Singapore Gives Companies More Time on Climate Reporting

Singapore has hit pause, just slightly, on its march toward stricter climate reporting. The Accounting and Corporate Regulatory Authority (ACRA) and Singapore Exchange Regulation (SGX RegCo) announced they will extend timelines for companies to meet new reporting and assurance rules, a move designed to give businesses breathing room to build the systems and expertise needed for high-quality disclosures.

Axiom GRC Acquires The DPO Centre to Strengthen Data Protection Capabilities

Axiom GRC has announced the acquisition of The DPO Centre, a leading UK-based provider of outsourced Data Protection Officer (DPO) and privacy services. The deal underscores the growing importance of data protection expertise as organizations face heightened regulatory and technological risks.

MAS Launches Consultation on Updated Liquidity Risk Guidelines for Banks

The Monetary Authority of Singapore (MAS) has issued a consultation paper proposing updated Guidelines on Liquidity Risk Management for banks, merchant banks, and finance companies in Singapore. The move marks the first major revision since 2013, reflecting lessons learned from supervisory reviews and recent global banking turmoil.