Privacy enforcement worldwide 🌍
Outside Europe there is no single answer to who fines. The GDPR gives every authority the power to fine by its own decision; elsewhere that power runs from regulators that fine directly, to regulators that must ask a court, to regulators with no fining power at all, to laws whose penalties are not yet enforceable. This page maps the route in the 23 jurisdictions outside Europe covered elsewhere on this site. For the EU, the EEA, the United Kingdom and Switzerland, see GDPR enforcement in Europe.
Researched on 2 October 2026 from statutes, regulator websites and court reports, then checked a second time by an independent pass against the cited sources. Where a point could not be confirmed it says not confirmed rather than guessing. Several of these regimes changed in 2025 and 2026, and the page describes them as they stood on that date. This maps procedure; it is not legal advice.
Four models of enforcement
The first question is not how large the fine can be but who can impose it. Every jurisdiction on this page falls into one of four models, and the model decides where the courts come in.
The regulator penalises by its own decision
As under the GDPR: the regulator investigates and imposes the penalty in one administrative decision, and the organisation challenges it afterwards in a court or tribunal.
Here: Mexico, Colombia, Brazil, Argentina, Turkey, Israel, Saudi Arabia, Nigeria, Kenya, South Africa, China, South Korea, Thailand, Vietnam, Philippines, Singapore.
The regulator has to go to court
The regulator investigates and negotiates, but a monetary penalty needs a court order. In practice most of the money comes from settlements and consent orders rather than judgments.
Here: United States, Australia.
Courts or prosecutors only
The regulator has no fining power. Money penalties come through prosecution for offences, typically breaching a regulator's order, or through court proceedings the regulator or a complainant starts.
Here: Canada, Japan, Indonesia.
Nobody can penalise yet
The law is in force on paper, but the penalty machinery is not: an implementing regulation, a penalty schedule or the regulator itself is still missing.
Here: United Arab Emirates, India.
What changes outside the GDPR
Six differences a European practitioner meets first. Each country section has the detail and the sources.
| Difference | What it looks like | Why it matters |
|---|---|---|
| Fining power | Not every regulator can fine. Canada's federal Commissioner and Japan's Commission cannot; Australia's OAIC and the US FTC must ask a court; India's Board gets its penalty powers only in May 2027. | Ask first who can actually impose a penalty, and on what route, before reading the maximum. |
| The ceiling | Turnover-linked maximums now exist well beyond Europe: Brazil, Nigeria, China, South Korea, Vietnam, Singapore, Indonesia, Australia. Elsewhere the maximum is a fixed amount, often per violation, so several violations stack. | A fixed per-violation cap is not a low cap when violations are counted per person or per day. |
| Suing directly | In some places individuals have stronger tools than in Europe: statutory damages under the California CCPA for data breaches, statutory damages without proof of harm in Israel, punitive damages up to twice the actual loss in Thailand, and in Kenya the regulator itself orders compensation to complainants. | Litigation exposure can exceed regulatory exposure, especially in the United States. |
| Criminal and personal liability | Several regimes back their orders with criminal offences (Japan, Saudi Arabia, the Philippines, Indonesia), and some fine the responsible managers as well as the company (China). | Who is personally exposed matters for governance, not only the company's balance sheet. |
| Laws in transition | India's penalties start in May 2027; Indonesia's agency does not exist yet and its regulation applies from January 2027; the UAE federal law still lacks its penalty decision; Japan's surcharge takes effect within two years of July 2026; South Korea's cap rose to 10% for serious cases in September 2026; Vietnam's fines became enforceable in August 2026; Canada's reform bill was only tabled in June 2026. | The date a law entered into force is often not the date it became enforceable. |
| More than one enforcer | The United States splits enforcement between the FTC, state attorneys general, California's privacy agency and sector regulators; Nigeria's consumer authority fined Meta separately from the data protection commission; the UAE free zones run their own regimes beside the federal law; Quebec has its own regulator beside Canada's. | Map every enforcer that can reach you, not just the data protection authority. |
The map: three questions across the world
Choose a question. Each tile is a jurisdiction; select one to jump to its section. The EU tile leads to the European page.
- Regulator penalises by its own decision
- Regulator must go to court for a penalty
- Penalties only through courts or prosecutors
- No body can penalise yet
- Linked to turnover or revenue
- Fixed amount, often per violation
- No monetary penalty in force yet
- Not confirmed
- Yes, individuals can sue for damages
- Only in narrow cases
- No
The classification compresses each jurisdiction's text into one label; the section below is the authority. For the United States the label reflects the FTC and the state attorneys general, with California's privacy agency the exception that fines by its own decision. For the UAE it reflects the federal law; the DIFC and ADGM free zones fine directly. For Canada it reflects the federal Commissioner; Quebec's regulator fines directly. Israel's maximum is shown as not confirmed because the reported turnover ceiling rests on a single secondary source.
Comparison
One row per jurisdiction. Select a name for the full section.
| Jurisdiction | Regulator | Who penalises | First court | Maximum penalty | Private damages action |
|---|---|---|---|---|---|
| United States | FTC; CPPA (CalPrivacy) | Regulator must go to court for a penalty | Federal or state court (FTC and AG cases); California court review of CPPA fines | Fixed amount, often per violation | Only in narrow cases |
| Canada | OPC / CPVP | Penalties only through courts or prosecutors | Federal Court (fresh hearing, s.14); Court of Quebec for CAI penalties | Fixed amount, often per violation | Only in narrow cases |
| Mexico | SABG | Regulator penalises by its own decision | Federal district judges (amparo) | Fixed amount, often per violation | Only in narrow cases |
| Colombia | SIC | Regulator penalises by its own decision | Contentious-administrative courts | Fixed amount, often per violation | Only in narrow cases |
| Brazil | ANPD | Regulator penalises by its own decision | ANPD Board, then the federal courts | Linked to turnover or revenue | Yes, individuals can sue for damages |
| Argentina | AAIP | Regulator penalises by its own decision | Federal contentious-administrative courts (not confirmed) | Fixed amount, often per violation | Only in narrow cases |
| Turkey | KVKK | Regulator penalises by its own decision | Administrative courts (since June 2024) | Fixed amount, often per violation | Yes, individuals can sue for damages |
| Israel | PPA | Regulator penalises by its own decision | Magistrates' Court (reported) | Not confirmed | Yes, individuals can sue for damages |
| Saudi Arabia | SDAIA | Regulator penalises by its own decision | Board of Grievances (administrative courts) | Fixed amount, often per violation | Yes, individuals can sue for damages |
| United Arab Emirates | UAE Data Office / DIFC Commissioner / ADGM ODP | No body can penalise yet | DIFC Courts or ADGM Courts (free zones) | No monetary penalty in force yet | Only in narrow cases |
| Nigeria | NDPC | Regulator penalises by its own decision | Federal High Court | Linked to turnover or revenue | Yes, individuals can sue for damages |
| Kenya | ODPC | Regulator penalises by its own decision | High Court (s.64) | Fixed amount, often per violation | Yes, individuals can sue for damages |
| South Africa | IR / InfoReg | Regulator penalises by its own decision | High Court (s.97) | Fixed amount, often per violation | Yes, individuals can sue for damages |
| India | DPBI | No body can penalise yet | TDSAT (from 2027) | Fixed amount, often per violation | Only in narrow cases |
| China | CAC | Regulator penalises by its own decision | Administrative reconsideration or the people's courts | Linked to turnover or revenue | Yes, individuals can sue for damages |
| South Korea | PIPC | Regulator penalises by its own decision | Seoul Administrative Court | Linked to turnover or revenue | Yes, individuals can sue for damages |
| Japan | PPC | Penalties only through courts or prosecutors | District court (challenge to a PPC order) | Fixed amount, often per violation | Yes, individuals can sue for damages |
| Thailand | PDPC | Regulator penalises by its own decision | Administrative Court (not confirmed) | Fixed amount, often per violation | Yes, individuals can sue for damages |
| Vietnam | MPS / A05 | Regulator penalises by its own decision | People's Court | Linked to turnover or revenue | Yes, individuals can sue for damages |
| Philippines | NPC | Regulator penalises by its own decision | Court of Appeals | Fixed amount, often per violation | Yes, individuals can sue for damages |
| Singapore | PDPC | Regulator penalises by its own decision | Data Protection Appeal Panel, then the High Court | Linked to turnover or revenue | Yes, individuals can sue for damages |
| Indonesia | Lembaga PDP (planned); Komdigi (interim) | Penalties only through courts or prosecutors | State Administrative Court (planned); criminal courts now | Linked to turnover or revenue | Yes, individuals can sue for damages |
| Australia | OAIC | Regulator must go to court for a penalty | Federal Court sets the penalty | Linked to turnover or revenue | Only in narrow cases |
Jurisdiction by jurisdiction
Each section opens with the journey in plain words, then the regulator, the complaint, the procedure, the penalty, the appeal, direct claims, cases that tested the system, and sources.
United StatesFTCAmericas
In plain words
If you complain to the FTC or a state attorney general, your complaint feeds their investigations but nobody issues you a decision, and they usually settle with the company in a consent order or court settlement. Money penalties normally need a court, except in California, where the privacy agency (CalPrivacy) can fine companies itself and companies can challenge the fine in the state Superior Court. To get compensation yourself you generally need a specific law that lets you sue, such as Illinois's biometric law or California's data breach provision, usually through a class action.
Route of a fine
- FTC, state AG or CPPA
- Consent order, court action or CPPA fine
- Federal or state courts
The authority
- Name
- Federal Trade Commission (federal); California Privacy Protection Agency (California) (Federal Trade Commission; California Privacy Protection Agency (now branded CalPrivacy), FTC; CPPA (CalPrivacy)) Website
- How it is organised
- There is no federal data protection authority and no federal comprehensive privacy law. The FTC, an independent federal agency, polices privacy under Section 5 of the FTC Act (unfair or deceptive practices) and sector rules such as COPPA; California's CPPA, now branding itself CalPrivacy, is the only dedicated state privacy agency, governed by a five-member board with its own Enforcement Division.
- Regional authorities
- State attorneys general enforce the comprehensive state privacy laws (around 20 states, most AG-only) and state consumer protection and biometric laws; the California AG shares CCPA enforcement with the CPPA, and county district attorneys and city attorneys have joined California cases. Sector regulators include HHS Office for Civil Rights (HIPAA), the FTC, CFPB and banking regulators (GLBA), and the FCC (telecoms).
- National law
- No federal comprehensive law. Federal: FTC Act s.5 (15 U.S.C. 45), COPPA (1998), HIPAA (1996) and its Privacy Rule, Gramm-Leach-Bliley Act (1999). State: California Consumer Privacy Act 2018 as amended by the California Privacy Rights Act 2020 (Cal. Civ. Code 1798.100 et seq., CPRA amendments operative 1 January 2023, CPPA enforcement from July 2023), around 20 other state comprehensive laws phased in 2023-2026, Illinois Biometric Information Privacy Act 2008 (740 ILCS 14), Texas Capture or Use of Biometric Identifier Act (CUBI). A federal comprehensive bill (the American Privacy Rights Act draft, 2024) stalled. Text
Complaining
- How
- Federal: individuals can report to the FTC online (ReportFraud.ftc.gov), free, but the FTC does not resolve individual complaints and uses them as intelligence for its own cases. California: sworn or unsworn complaints can be filed online with the CPPA (Cal. Civ. Code 1798.199.45) or with the AG, free of charge; other states take consumer complaints through the AG's consumer protection division.
- Contact the organisation first?
- Not required by the FTC or CPPA. Some state laws require the regulator to give the business a notice and cure period before suing (for example Texas, Virginia, Utah); in California the mandatory 30-day cure ended on 1 January 2023, though the CPPA may still decide to give a business time to cure (s.1798.199.45(a)). A consumer bringing a CCPA data breach claim for statutory damages must first give 30 days' written notice (s.1798.150(b)).
- Deadlines
- No statutory deadline for the FTC or CPPA to act on a complaint. The CPPA must bring administrative action within five years of the violation (s.1798.199.70); federal civil penalty actions are generally subject to the five-year limit in 28 U.S.C. 2462.
- The complainant's position
- A complainant is not a party at the FTC, CPPA or state AG and receives no binding decision; the CPPA must, however, tell the complainant in writing what action it has taken or plans to take, and why (s.1798.199.45(b)).
Procedure
- FTC: investigation (civil investigative demands), then either a negotiated consent order (administrative, binding for 20 years typically) or litigation in an administrative Part 3 proceeding or in federal district court.
- FTC money: after AMG Capital (2021) the FTC cannot obtain restitution or disgorgement under s.13(b); civil penalties are available only for violating an existing order or a trade regulation rule or specific statute such as COPPA, and are sought in federal court, normally by the Department of Justice on referral.
- CPPA: Enforcement Division investigation, probable cause proceeding, then an administrative hearing before an administrative law judge and a decision by the CPPA Board (s.1798.199.50-.55); most cases end in a stipulated final order approved by the Board.
- California AG and other state AGs: investigation, notice (and cure where the state law provides), then a civil lawsuit in state court, usually resolved by a court-approved settlement and injunction.
- Who decides
- FTC Commissioners (consent orders, administrative decisions) and federal courts (civil penalties); the CPPA Board (administrative fines); state courts in AG actions.
- Limitation
- CPPA: five years from the violation (s.1798.199.70). Federal civil penalties: five years (28 U.S.C. 2462). State laws vary; not confirmed for each state.
Fines
- Who imposes them
- Mixed, so mapped as regulator-court: the FTC cannot fine for a first violation of Section 5 and must go to federal court (via DOJ) for civil penalties for order or rule violations, and state AGs must sue in court; the CPPA is the exception, imposing administrative fines itself of up to USD 2,500 per violation or USD 7,500 per intentional violation or violation involving minors under 16 (s.1798.155, CPI-adjusted to USD 2,663 and USD 7,988 from January 2025). The AG can recover the same amounts as civil penalties in court (s.1798.199.90).
- Public bodies
- Generally no: the FTC Act and the CCPA cover businesses, not government agencies. Federal agencies are governed by the Privacy Act of 1974, enforced by individual lawsuits, not fines; HIPAA covered entities can include public hospitals.
- National specifics
- Caps are per violation, so totals scale with the number of consumers or transactions rather than turnover. HIPAA civil money penalties are imposed administratively by HHS OCR, and criminal HIPAA offences are prosecuted by DOJ. Other sanctions include long-running consent orders with independent assessments, data and algorithm deletion orders, and bans on certain data uses.
Appeals
- First court
- FTC administrative orders: petition to a federal court of appeals (15 U.S.C. 45(c)). Federal court civil penalty judgments: ordinary federal appeals. CPPA decisions on a complaint or fine: judicial review in an action by an interested party, on an abuse of discretion standard (s.1798.199.85), in practice a petition for a writ of administrative mandate in the California Superior Court.
- Deadline
- FTC orders: 60 days after service (15 U.S.C. 45(c)). CPPA decisions: s.1798.199.85 sets no time limit; the deadline under the general Administrative Procedure Act rules is not confirmed.
- Does it hold payment?
- Not confirmed as a general rule; for FTC administrative orders, a cease and desist order becomes final only after the time for review expires or review concludes.
- Further appeal
- Federal: federal court of appeals, then a petition for certiorari to the US Supreme Court. California: Court of Appeal, then the California Supreme Court.
- If the authority does nothing
- There is no practical mechanism to challenge an FTC or AG decision not to act on a complaint; prosecutorial discretion is not reviewable in practice. For the CPPA, s.1798.199.85 allows judicial review of any decision on a complaint by an interested party, but whether a complainant can use it against a decision not to investigate is not confirmed. The individual's main route is a private lawsuit where a statute allows one.
Suing the organisation directly
- Courts
- Limited: there is no general private right of action under the FTC Act or most state comprehensive laws. The CCPA allows consumers to sue only for data breaches caused by a failure to maintain reasonable security (s.1798.150). Specific statutes give broad private rights, most importantly Illinois BIPA (740 ILCS 14/20), plus federal laws such as the Video Privacy Protection Act and Telephone Consumer Protection Act, and common law privacy torts.
- Compensation
- CCPA breach claims: statutory damages of USD 100 to 750 per consumer per incident or actual damages if greater (CPI-adjusted to USD 107 to 799). BIPA: USD 1,000 per negligent violation and USD 5,000 per intentional or reckless violation, or actual damages if greater; a 2024 amendment limits recovery to one violation per person rather than per scan.
- Collective actions
- Class actions are routine and are the main private enforcement tool; BIPA class actions have produced settlements such as Facebook's USD 650 million (2021). Arbitration clauses with class waivers often block them.
Cases worth knowing
- FTC v Facebook (USD 5 billion) 2019
Facebook paid a USD 5 billion civil penalty for violating its 2012 FTC privacy order, filed by the Department of Justice in the US District Court for the District of Columbia, together with a new order imposing board-level privacy oversight. The penalty was possible only because an earlier order had been breached. Source - California AG v Sephora; CPPA v American Honda; General Motors 2022-2026
The California AG's first CCPA settlement fined Sephora USD 1.2 million in August 2022 for selling data and ignoring Global Privacy Control. The CPPA's first major administrative decision fined Honda USD 632,500 in March 2025 for excessive verification and asymmetric opt-out choices, and the largest CCPA penalty so far is USD 12.75 million against General Motors (May 2026) obtained jointly by the AG, CalPrivacy and county prosecutors. Source - Texas v Meta and Texas v Google (biometrics) 2024-2025
Texas's AG settled with Meta for USD 1.4 billion in July 2024 over facial recognition under the state biometric statute (CUBI) and consumer protection law, and with Google for USD 1.375 billion in May 2025 over location, incognito and biometric data. Both were court lawsuits settled, not regulator fines. Source
Worth knowing
- There is no federal comprehensive privacy law and no federal data protection authority; protection is a patchwork of a consumer protection agency, sector laws and state laws.
- The FTC cannot fine a company for a first privacy violation under Section 5: it first obtains an order, and money comes only if that order is later broken (or under specific statutes such as COPPA), as the Supreme Court confirmed in AMG Capital Management v FTC (2021) for restitution.
- Much of the real money comes from private class actions and state AG lawsuits, not regulators; a single Illinois statute (BIPA) has generated settlements larger than most European fines.
- Several state laws give businesses a right to be warned and to cure before they can be penalised, and enforcement is spread across 50 AGs with different laws.
- Penalties are per violation, not per percentage of turnover, so totals depend on how many consumers or transactions are counted.
Sources (13) research confidence: medium
- FTC press release: FTC imposes USD 5 billion penalty on Facebook (24 July 2019)
- FTC case page: Facebook, Inc., In the Matter of
- AMG Capital Management, LLC v FTC, US Supreme Court, 22 April 2021
- CPPA announcement: Honda decision, USD 632,500 (12 March 2025)
- CPPA announcement: data broker decisions (8 January 2026)
- CalPrivacy: action against Virginia data broker, lists GM, Tractor Supply, Honda (September 2026)
- CalPrivacy: second data broker enforcement action, GM USD 12.75m with AG (August 2026)
- California AG: Sephora settlement (24 August 2022)
- Texas AG: USD 1.375 billion settlement with Google (May 2025)
- Biometric Update: Texas AG settlement with Google secondary
- Paul Weiss: California privacy updates Q1 2026 (Disney, PlayOn, Ford) secondary
- Clym: CCPA fines in 2026 (CPI-adjusted amounts, end of cure period) secondary
- Reflectiz: biggest CCPA fines list secondary
CanadaOPC / CPVPAmericas
In plain words
You complain to the federal Privacy Commissioner, who investigates and publishes findings with recommendations, but cannot fine the company or force it to comply. If you are not satisfied, you can take the case to the Federal Court within a year, which can order changes and award you damages. In Quebec the provincial commission can fine companies directly, up to CAD 10 million or 2% of turnover, and you can also sue for damages, including punitive damages.
Route of a fine
- OPC investigation and report
- Federal Court (s.14)
- Federal Court of Appeal
- Supreme Court (leave)
The authority
- Name
- Office of the Privacy Commissioner of Canada (Office of the Privacy Commissioner of Canada / Commissariat à la protection de la vie privée du Canada, OPC / CPVP) Website
- How it is organised
- The Privacy Commissioner is an independent officer of Parliament working on an ombudsman model: it investigates and recommends but cannot fine or issue binding orders under PIPEDA. Bill C-36 (June 2026) would move private-sector enforcement to a new Digital Safety and Data Protection Commission, leaving the OPC with the public-sector Privacy Act only.
- Regional authorities
- Quebec's Commission d'accès à l'information (CAI) enforces Law 25 and can impose administrative monetary penalties. Alberta and British Columbia have their own private-sector PIPA statutes enforced by provincial Information and Privacy Commissioners with order-making powers. The Competition Bureau and CRTC (anti-spam law) also act on data practices.
- National law
- Personal Information Protection and Electronic Documents Act (PIPEDA, 2000), in force for federally regulated and interprovincial commercial activity. Bill C-27 (Consumer Privacy Protection Act) died when Parliament was prorogued and dissolved in 2025; its successor, Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled on 15 June 2026 and is at an early parliamentary stage. Quebec: Act respecting the protection of personal information in the private sector (CQLR c P-39.1) as amended by Law 25 (2021), phased in from September 2022 to September 2024, with the penalty regime in force since 22 September 2023. Text
Complaining
- How
- Written complaint to the OPC (PIPEDA s.11), in English or French, free, usually through the OPC's online form. In Quebec, complaints go to the CAI, also free; disagreements over access or rectification go to the CAI's adjudicative function (P-39.1 s.42).
- Contact the organisation first?
- The OPC expects individuals to raise the matter with the organisation first, and PIPEDA s.12(1) lets the Commissioner decline to investigate where the complainant ought first to exhaust grievance procedures that are reasonably available; this is a discretion, not an absolute bar.
- Deadlines
- The Commissioner must issue a report of findings within one year after the complaint is filed (s.13(1)), though in practice investigations often take longer; a court noted one that took nearly three years. The OPC may also decline complaints not filed within a reasonable time (s.12(1)).
- The complainant's position
- The complainant receives the report of findings and, unusually, is the person entitled to take the matter to Federal Court under s.14; the organisation cannot apply under s.14.
Procedure
- OPC: early resolution where possible, otherwise formal investigation by an investigator, with preliminary findings shared with the organisation.
- Report of findings by the Commissioner, classified as well-founded, resolved, not well-founded, settled or discontinued, with non-binding recommendations; organisations may enter compliance agreements enforceable in Federal Court (s.17.1).
- Federal Court application by the complainant (s.14) or the Commissioner (s.15) within one year of the report; the Court hears the matter afresh and can order corrections, publication and damages (s.16).
- Quebec: CAI inspection or investigation, notice of non-compliance with an opportunity to respond, then an administrative monetary penalty imposed by a person designated by the CAI, or penal proceedings before the courts; the CAI can also issue orders.
- Who decides
- OPC Commissioner (non-binding findings); Federal Court (binding orders and damages). In Quebec, designated CAI officials (penalties) and the CAI (orders), with penal fines imposed by the Court of Québec on prosecution.
- Limitation
- Federal Court application: one year after the report or notice of discontinuance is sent, extendable by the Court (s.14). Limitation periods for Quebec penalties and prosecutions: not confirmed.
Fines
- Who imposes them
- Federally, mapped as court: the OPC has no fining power; the only federal monetary sanctions are Federal Court damages and fines for PIPEDA offences such as obstructing the Commissioner or breaching breach-reporting duties, up to CAD 100,000 on indictment (s.28), imposed by criminal courts. Quebec is the exception: the CAI imposes administrative monetary penalties of up to CAD 50,000 for individuals and CAD 10 million or 2% of worldwide turnover for enterprises, and penal fines on prosecution reach CAD 25 million or 4% of worldwide turnover (doubled for repeat offences).
- Public bodies
- PIPEDA does not apply to government institutions, which fall under the federal Privacy Act (OPC, no fines). Quebec's AMP regime is in the private-sector act; public bodies are governed by the separate Access Act, and whether AMPs apply to them is not confirmed.
- National specifics
- Bill C-36 would give the new Commission order-making power and AMPs of up to the greater of CAD 10 million or 3% of global revenue, with offence fines up to CAD 25 million or 5%, but it is not law. Alberta and BC commissioners issue binding orders, with offence fines up to CAD 100,000 (not confirmed against current statute text).
Appeals
- First court
- Federal: there is no appeal against an OPC finding as such; instead the complainant or Commissioner applies to the Federal Court for a fresh hearing (s.14-15). Quebec: CAI penalty decisions can be contested before the Court of Québec after a review request to the CAI.
- Deadline
- Federal Court s.14: one year after the report is sent. Quebec AMP contestation: commonly reported as 30 days, article number not confirmed.
- Does it hold payment?
- Not confirmed.
- Further appeal
- Federal Court decisions go to the Federal Court of Appeal and, with leave, the Supreme Court of Canada. Court of Québec decisions follow Quebec appeal routes to the Court of Appeal of Québec, then the Supreme Court of Canada with leave.
- If the authority does nothing
- If the OPC discontinues an investigation, the complainant can still apply to the Federal Court within one year of the notice of discontinuance (s.14). A decision not to investigate at all (s.12) does not open that route; judicial review of OPC conduct in the Federal Court is the general fallback.
Suing the organisation directly
- Courts
- Limited federally: PIPEDA has no free-standing right to sue; damages are available only through the Federal Court after an OPC complaint and report (s.14, s.16). Quebec gives a broader right: individuals can sue for damages in the ordinary Quebec courts, and Law 25 added punitive damages of at least CAD 1,000 for intentional or gross fault (P-39.1 s.93.1). Alberta and BC PIPA allow damages actions once a commissioner's order is final, and common law privacy torts exist in some provinces.
- Compensation
- Federal Court PIPEDA awards are modest, for example CAD 5,000 in A.T. v Globe24h.com (2017 FC 114). Quebec punitive damages minimum CAD 1,000 per intentional or gross fault.
- Collective actions
- Provincial class actions are the main private enforcement route, often pleaded in contract, negligence or privacy torts rather than directly under PIPEDA, as courts have noted the OPC's weak powers (Haikola v Personal Insurance, 2019 ONSC 5982). Quebec has an active class action regime for data breaches.
Cases worth knowing
- Privacy Commissioner of Canada v Facebook (Cambridge Analytica) 2019-2026
After a 2019 joint OPC and BC investigation found Facebook breached PIPEDA, the OPC applied to the Federal Court, which dismissed the case in April 2023; the Federal Court of Appeal reversed on 9 September 2024 (2024 FCA 140), holding Facebook failed to obtain meaningful consent and to safeguard data. The Supreme Court of Canada granted leave on 12 June 2025 and heard the appeal on 19 March 2026; no judgment had been confirmed at the time of research. Source - A.T. v Globe24h.com 2017
On a complainant's s.14 application after an OPC report, the Federal Court ordered a Romanian website republishing Canadian court decisions to remove them and pay CAD 5,000 damages (2017 FC 114). It shows how the court, not the OPC, provides binding remedies. Source
Worth knowing
- The federal regulator cannot fine anyone or issue binding orders; its findings are recommendations, and enforcement depends on a Federal Court hearing that starts from scratch.
- The right to go to court belongs to the complainant, not the company, and the court awards damages to the individual, so a complaint can end in compensation rather than a public fine.
- Quebec, inside the same country, has a GDPR-style regime with turnover-based fines of up to 4% and punitive damages, so the outcome depends heavily on the province.
- Federal reform has failed twice (Bill C-11 in 2021 and Bill C-27 in 2025); the third attempt, Bill C-36, would strip private-sector enforcement from the Privacy Commissioner and give it to a new government-appointed commission.
- An Ontario court has said class actions are needed to enforce PIPEDA because the regulator cannot award damages or fine (Haikola v Personal Insurance, 2019 ONSC 5982).
Sources (13) research confidence: medium
- PIPEDA, ss.11-17 (Justice Laws)
- OPC: Federal Court applications under PIPEDA
- OPC: Guide to the PIPEDA complaint process
- OPC: Organizations' guide to complaint investigations under PIPEDA
- DLA Piper: Canada tables Bill C-36 (June 2026) secondary
- Blakes: Third time's the charm? Bill C-36 secondary
- Teresa Scassa: Canada's new privacy reform bill (Bill C-36) secondary
- Bennett Jones: Facebook-OPC case at the Supreme Court of Canada secondary
- CIPPIC: appearance before the Supreme Court in Facebook v Privacy Commissioner secondary
- Gowling WLG: A.T. v Globe24h.com, 2017 FC 114 secondary
- nNovation: Haikola v Personal Insurance, 2019 ONSC 5982 secondary
- Loi 25 simple: sanctions et amendes (AMP and penal maximums) secondary
- Web25: the CAI and Law 25 (AMP regime since 22 September 2023, P-39.1 s.42 and s.90.1) secondary
MexicoSABGAmericas
In plain words
In Mexico you must first send your request to the company, which has 20 days to reply. If you are unhappy, you have 15 days to file a complaint with the federal Anti-Corruption and Good Government Secretariat, which tries to settle the matter and otherwise decides within about 50 days and can fine the company. Either side can then challenge the decision through a constitutional amparo before specialised federal judges, and compensation must be claimed separately in the civil courts.
Route of a fine
- Secretariat (SABG) decision
- Amparo before federal judges
- Collegiate circuit courts
The authority
- Name
- Anti-Corruption and Good Government Secretariat (Secretaría Anticorrupción y Buen Gobierno, SABG) Website
- How it is organised
- A federal government ministry (secretaría) of the executive branch, not an independent authority. It took over private-sector data protection on 21 March 2025 when the constitutionally autonomous INAI was abolished following the constitutional reform published on 20 December 2024 (art. 2 fr. XV and the thirteenth transitional article of the 2025 decree).
- Regional authorities
- No regional authorities for the private sector. Public-sector data protection is governed by a separate general law (the 2025 General Law on Protection of Personal Data Held by Obligated Subjects) and federal public-sector transparency functions passed to 'Transparencia para el Pueblo'; its enforcement details were not confirmed. Consumer (Profeco) and financial (Condusef) authorities run do-not-call style registries and handle related complaints.
- National law
- Ley Federal de Protección de Datos Personales en Posesión de los Particulares (Federal Law on Protection of Personal Data Held by Private Parties), published in the Diario Oficial de la Federación on 20 March 2025 and in force 21 March 2025, replacing the 2010 law. The executive had 90 days to adapt the implementing regulation; whether a new regulation has been issued was not confirmed. Text
Complaining
- How
- By filing a request for protection of rights (solicitud de protección de derechos) with the Secretariat, which may supply deficiencies in the complaint without altering the facts. Fee and language details were not confirmed; Spanish is the working language.
- Contact the organisation first?
- Yes. The data subject must first submit an ARCO request (access, rectification, cancellation, objection) to the controller, which has 20 days to answer and 15 more to implement (art. 31). The protection request is filed within 15 days of the controller's answer, or after the answer deadline expires if there is none (art. 40).
- Deadlines
- The Secretariat must decide within 50 days of the request, extendable once for an equal period (art. 42). If the request is incomplete the complainant gets one chance to correct it within 5 days.
- The complainant's position
- The data subject is a party to the protection-of-rights procedure, which is adversarial: the controller has 15 days to respond and submit evidence, and the Secretariat can attempt conciliation and record a binding agreement.
Procedure
- ARCO request to the controller (20 days to answer, art. 31).
- Protection-of-rights procedure before the Secretariat (arts. 40 to 50): admission, controller response within 15 days, possible conciliation, decision within 50 days confirming, revoking or modifying the controller's answer or ordering delivery of the data.
- Verification procedure (art. 54), opened on the Secretariat's own initiative or at a party's request, to check compliance generally.
- Sanctioning procedure (arts. 56 to 57): the controller has 15 days to submit evidence and arguments; decision within 50 days, extendable once.
- Publication of decisions in redacted public versions (art. 52).
- Who decides
- The Secretaría Anticorrupción y Buen Gobierno (the internal unit that decides was not confirmed).
- Limitation
- Not confirmed; no prescription rule for enforcement was found in the 2025 law.
Fines
- Who imposes them
- The Secretariat imposes sanctions itself by administrative decision (art. 56), so who_penalises is regulator. Fines are fixed ranges in UMA (Unidad de Medida y Actualización): 100 to 160,000 UMA for the infractions in art. 58 fr. II to VII, 200 to 320,000 UMA for fr. VIII to XVIII, and an additional 100 to 320,000 UMA for persistent infringement (art. 59); amounts may be doubled for sensitive data. The first infraction (failing to answer an ARCO request) is met with a warning (apercibimiento).
- Public bodies
- No: the federal law covers private parties only. Public bodies fall under the separate general law for obligated subjects, where breaches lead to administrative responsibility of officials rather than fines on the body (not confirmed in detail).
- National specifics
- Fine criteria include the nature of the data, whether the refusal was obviously unfounded, intent, the offender's economic capacity and recidivism. Criminal offences exist: 3 months to 3 years' prison for an authorised person who causes a security breach for profit (art. 62), 6 months to 5 years for processing data through deceit for profit (art. 63), doubled for sensitive data (art. 64). At 2025 UMA values the top ordinary fine is roughly MXN 36 million (value not confirmed against INEGI).
Appeals
- First court
- Constitutional amparo before specialised federal district judges and circuit tribunals (art. 51: 'Contra las resoluciones de la Secretaría, los particulares podrán promover juicio de amparo'). This replaced the former route of nullity proceedings before the Federal Administrative Court.
- Deadline
- Not confirmed; the general Amparo Law time limit is reported as 15 working days but was not checked for this regime.
- Does it hold payment?
- Not confirmed; suspension would depend on the amparo court granting a suspension order.
- Further appeal
- Review (recurso de revisión) of amparo judgments to the collegiate circuit courts and, in some cases, the Supreme Court (not confirmed for the specialised courts). The twentieth transitional article required the judiciary to set up specialised district courts and collegiate circuit tribunals within 120 calendar days and suspended procedural time limits in pending data protection and transparency amparo cases for 180 calendar days.
- If the authority does nothing
- Not confirmed. Because the regulator is a ministry, inaction would in principle be challenged by amparo; the law sets no specific remedy.
Suing the organisation directly
- Courts
- Limited: art. 53 preserves the data subject's right to seek compensation under the applicable civil or criminal law, so damages claims go to the ordinary civil courts under general civil liability (moral damage) rules rather than a specific privacy-law cause of action.
- Compensation
- No statutory damages; compensation under general civil law rules.
- Collective actions
- Federal collective actions exist under the Federal Code of Civil Procedure, mainly for consumer and environmental matters; their use for data protection was not confirmed.
Cases worth knowing
- Abolition of INAI and transfer of data protection to a ministry 2024-2025
The constitutional reform published on 20 December 2024 abolished the autonomous INAI, which was dissolved when the new transparency and data protection laws, published on 20 March 2025, entered into force on 21 March 2025. INAI's files passed to the Secretaría Anticorrupción y Buen Gobierno within 20 working days under the decree's thirteenth transitional article. Source
Worth knowing
- The data protection regulator is now an ordinary government ministry focused on anti-corruption, not an independent authority; this is a sharp departure from the GDPR independence model.
- Challenges to the regulator's decisions go straight to constitutional amparo before specialised federal judges, rather than to an administrative court.
- Fines are set in UMA units, a reference value updated yearly, and are fixed ranges, not turnover-based; they can be doubled where sensitive data is involved.
- The complaint route is tightly time-limited: the data subject has only 15 days after the controller's answer to go to the regulator.
Sources (4) research confidence: medium
- Ley Federal de Protección de Datos Personales en Posesión de los Particulares (Chamber of Deputies, DOF 20 March 2025)
- Garrigues: Mexico's new federal data protection law eliminates INAI secondary
- EY Mexico: Entry into force of the new LFPDPPP secondary
- Wikipedia: National Institute of Transparency for Access to Information and Personal Data Protection secondary
ColombiaSICAmericas
In plain words
In Colombia you must first make a formal claim to the company, which has 15 working days to answer. If it does not fix the problem, you can complain free of charge to the Superintendence of Industry and Commerce, which can investigate, order the data deleted and fine the company up to 2,000 monthly minimum wages, with appeals first inside the SIC and then to the administrative courts. You can also ask any judge for a quick 'tutela' order protecting your data, but compensation needs a separate civil claim.
Route of a fine
- SIC decision
- Internal appeals
- Administrative courts
- Council of State
The authority
- Name
- Superintendence of Industry and Commerce, Delegated Superintendence for Personal Data Protection (Superintendencia de Industria y Comercio, Delegatura para la Protección de Datos Personales, SIC) Website
- How it is organised
- A technical superintendence attached to the Ministry of Commerce, Industry and Tourism, not a stand-alone independent authority. Within it, the Delegated Superintendent for Personal Data Protection (art. 19 Law 1581) supervises compliance, with a Directorate of Personal Data Protection Investigation handling cases at first instance. The SIC is also the consumer, competition and industrial property authority, and exercises judicial functions in some of those fields.
- Regional authorities
- No regional authorities. The Financial Superintendence shares supervision of financial and credit data under Law 1266 of 2008; the Procurator General (Procuraduría) handles breaches by public authorities; judges protect habeas data through the constitutional tutela action.
- National law
- Statutory Law 1581 of 2012 on personal data protection (reviewed in advance by the Constitutional Court in judgment C-748 of 2011) and Decree 1377 of 2013, now compiled in Decree 1074 of 2015; Statutory Law 1266 of 2008 on financial and credit habeas data; constitutional right to habeas data in art. 15 of the Constitution. Text
Complaining
- How
- By filing a complaint (denuncia or reclamo) with the SIC, online through its electronic portal or in writing, free of charge, in Spanish.
- Contact the organisation first?
- Yes, mandatory: art. 16 Law 1581 makes prior exhaustion of the query or claim process with the controller a procedural requirement (requisito de procedibilidad). Controllers must answer queries within 10 working days (art. 14) and claims within 15 working days (art. 15), each extendable.
- Deadlines
- Not confirmed; no statutory deadline for the SIC to decide was confirmed.
- The complainant's position
- Not confirmed. The administrative sanctioning procedure runs between the SIC and the controller; the complainant's party rights were not confirmed.
Procedure
- Complaint after the controller has failed to resolve the claim, or own-initiative inquiry; the SIC can request information and carry out inspections.
- Preliminary inquiry and formal statement of charges (formulación de cargos) by the Directorate of Personal Data Protection Investigation.
- Defence and evidence phase, then a first-instance decision imposing fines and orders (for example to delete data or stop a practice).
- Appeal for reconsideration (reposición) to the Directorate, and appeal (apelación) to the Delegated Superintendent for Personal Data Protection.
- The SIC can also issue administrative orders (órdenes administrativas) to bring processing into line, including to foreign platforms operating in Colombia.
- Who decides
- The Director of Personal Data Protection Investigation at first instance; the Delegated Superintendent for Personal Data Protection on appeal.
- Limitation
- Reported as 3 years from the conduct under the general administrative sanctions rule in art. 52 of the Administrative Procedure Code (CPACA); not confirmed against the text.
Fines
- Who imposes them
- The SIC imposes fines itself by administrative decision (art. 23 Law 1581), so who_penalises is regulator. The maximum is 2,000 statutory monthly minimum wages (SMMLV) per sanction; national rules require such wage-linked amounts to be expressed in tax or basic value units, and the conversion now applied by the SIC was not confirmed.
- Public bodies
- No fines on public authorities: under art. 23 Law 1581, where the infringer is a public authority the SIC refers the case to the Procurator General's Office for disciplinary action.
- National specifics
- Other sanctions are suspension of processing activities for up to 6 months, temporary closure of operations if the failings are not corrected, and immediate and definitive closure of operations involving sensitive data (art. 23). Graduation criteria in art. 24 include harm, benefit obtained, recidivism, obstruction and acknowledgement. Unauthorised access to or use of personal data is also a crime under art. 269F of the Criminal Code (Law 1273 of 2009), with 48 to 96 months' prison.
Appeals
- First court
- After the internal appeals, judicial review is by the action for annulment and restoration of rights (nulidad y restablecimiento del derecho) before the contentious-administrative courts (Administrative Court of Cundinamarca or Council of State, depending on amount); not confirmed against a primary source.
- Deadline
- Internal appeals: reported as 10 working days after notification under the CPACA (not confirmed). Judicial review: reported as 4 months (not confirmed).
- Does it hold payment?
- Not confirmed. Internal appeals are generally suspensive under the CPACA; filing a court action does not by itself suspend the decision.
- Further appeal
- Second-instance appeal within the contentious-administrative jurisdiction, ending at the Council of State (Consejo de Estado).
- If the authority does nothing
- The data subject can bring a tutela action (art. 86 Constitution) before any judge for violation of the fundamental right to habeas data, decided within about 10 days; this is also the usual route against public bodies.
Suing the organisation directly
- Courts
- Tutela gives fast judicial orders to correct, update or delete data but not damages. Compensation is claimed in the ordinary civil courts under general civil liability rules, as Law 1581 creates no specific damages action, so private_action is limited.
- Compensation
- No statutory damages.
- Collective actions
- Group actions (acciones de grupo) and popular actions under Law 472 of 1998 exist for collective harm; their use in data protection was not confirmed.
Cases worth knowing
- Comcel (Claro): 'Amigos que te premian' campaign 2023
On 6 July 2023 the SIC fined Comcel (Claro) COP 1,306,289,600, then described as its highest data protection sanction, for collecting third parties' phone numbers through a referral campaign without prior, express and informed authorisation, aggravated by recidivism. It ordered Claro to stop using and delete the data; the decision was open to reconsideration and appeal within the SIC. Source - 2025 enforcement surge, including a biometric login fine 2025
By August 2025 the SIC had opened 101 data protection investigations that year (83 in 2024, 55 in 2023) and imposed fines totalling COP 5,157 million, including COP 214.4 million on an e-commerce company that made account access conditional on facial biometric data, and COP 190.5 million plus a temporary suspension of processing on another company. Source
Worth knowing
- The data protection authority sits inside the trade and consumer superintendence, which also acts as a judge in consumer and competition disputes; it is not an independent DPA in the GDPR sense.
- Complaining to the controller first is a legal precondition: the SIC will not process a complaint until the claim process with the controller is exhausted.
- Fines are pegged to the national minimum wage (up to 2,000 monthly minimum wages), not turnover, and public bodies cannot be fined at all: they are referred to the Procurator General.
- Constitutional tutela is a fast, free way for individuals to enforce habeas data before any judge, and the Constitutional Court's tutela case law has shaped Colombian data protection more than statute.
Sources (6) research confidence: medium
- Law 1581 of 2012 (Senate legal database)
- Law 1581 of 2012 (Función Pública Gestor Normativo)
- SIC: highest sanction for improper data processing imposed on Claro ('Amigos que te premian')
- SIC: 101 investigations and COP 5,157 million in fines in 2025
- Universidad Externado: report on SIC 2025 enforcement figures secondary
- DLA Piper Data Protection Laws of the World: Colombia enforcement secondary
BrazilANPDAmericas
In plain words
In Brazil you first ask the company to deal with your data request; if it does not, you can petition the national data protection agency (ANPD) online for free. The ANPD uses complaints to decide whom to inspect, and if it finds a breach it can itself fine a company up to 2% of its Brazilian revenue (maximum BRL 50 million per breach) or order it to stop processing, with appeals going to its board and then the federal courts. Many people instead go straight to a consumer body or sue the company in a civil or small claims court for compensation.
Route of a fine
- ANPD decision
- ANPD Board
- Federal courts
- STJ or STF
The authority
- Name
- National Data Protection Agency (formerly National Data Protection Authority) (Agência Nacional de Proteção de Dados (formerly Autoridade Nacional de Proteção de Dados), ANPD) Website
- How it is organised
- Federal regulatory agency (special autonomous body) linked to the Ministry of Justice and Public Security, with functional, technical, decision-making, administrative and financial autonomy, run by a Board of Directors (Conselho Diretor). Provisional Measure 1.317 of 17/18 September 2025 converted it from an authority into a regulatory agency under Law 13.848/2019 and gave it supervision of the Digital Statute of Children and Adolescents (Law 15.211/2025); Congress approved the conversion on 24 February 2026, and the number of the resulting law was not confirmed.
- Regional authorities
- No regional data protection authorities. In practice consumer bodies (state and municipal Procons and the federal National Consumer Secretariat, Senacon) and public prosecutors (Ministério Público) also act on privacy failures under the Consumer Defence Code and through public civil actions.
- National law
- Lei Geral de Proteção de Dados Pessoais (LGPD), Law 13.709 of 14 August 2018, in force 18 September 2020; administrative sanctions (arts. 52 to 54) applicable from 1 August 2021. Key ANPD rules: Resolution CD/ANPD 1/2021 (inspection and sanctioning procedure) and Resolution CD/ANPD 4/2023 (dosimetry and application of sanctions, February 2023). Text
Complaining
- How
- Through the ANPD's online petition service on the gov.br portal, free of charge, in Portuguese. Two routes exist: a data subject petition (petição de titular) about one's own data, and a report (denúncia) about a suspected LGPD breach that anyone can file.
- Contact the organisation first?
- Yes for a data subject petition: art. 18 para. 1 LGPD gives the right to petition the ANPD against the controller, and art. 25 para. 1 of Resolution CD/ANPD 1/2021 requires proof that the request was first made to the controller and not resolved in time (a self-declaration is accepted if no other proof exists). A denúncia does not need prior contact.
- Deadlines
- Not confirmed. The ANPD does not commit to deciding individual petitions within a fixed period; it handles complaints in bulk, using them to prioritise monitoring and inspection.
- The complainant's position
- Limited. The petitioner is informed of the outcome but the sanctioning procedure runs between the ANPD and the controller; the complainant is not a party with appeal rights in the way a GDPR complainant is (not confirmed in a primary source).
Procedure
- Monitoring, guidance and preventive phase: the ANPD can request information, issue guidance and impose preventive measures (for example the 2024 Meta AI suspension) with a daily fine for non-compliance.
- Inspection (fiscalização) triggered by complaints, breach notifications or own initiative.
- Administrative sanctioning procedure (processo administrativo sancionador) opened by the General Coordination of Inspection, with notice of charges and a defence period.
- First-instance decision applying sanctions graded under Resolution CD/ANPD 4/2023; administrative appeal to the Board of Directors.
- Publication of the sanction and, where applicable, a publicity order requiring the controller to disclose the infringement.
- Who decides
- The General Coordination of Inspection decides at first instance; the Board of Directors (Conselho Diretor) decides administrative appeals and adopts preventive measures in urgent cases.
- Limitation
- Not confirmed in a primary source; the general five-year limitation for federal punitive administrative action (Law 9.873/1999) is reported to apply.
Fines
- Who imposes them
- The ANPD imposes fines itself by administrative decision (art. 52 LGPD), so who_penalises is regulator. The simple fine is up to 2% of the revenue of the private legal entity, group or conglomerate in Brazil in its last financial year, excluding taxes, capped at BRL 50 million per infringement; a daily fine is also available.
- Public bodies
- Public bodies cannot be fined: art. 52 para. 3 LGPD limits them to warnings, publicity, blocking, deletion and suspension-type sanctions. Most ANPD sanctions to date (Ministry of Health, INSS, state health and education secretariats) were warnings or publicity orders against public entities.
- National specifics
- Other sanctions are warning, publicisation of the infringement, blocking or deletion of the data, partial suspension of the database for up to six months (renewable), suspension of the processing activity, and partial or total prohibition of data processing. The LGPD itself creates no criminal offences; criminal liability comes from other laws. The 2% cap uses Brazilian revenue only, not global turnover.
Appeals
- First court
- Administrative appeal first lies to the ANPD Board of Directors. Judicial review is before the federal courts (Justiça Federal), since the ANPD is a federal body.
- Deadline
- Administrative appeal: 10 working days to the Board of Directors (art. 58 Resolution CD/ANPD 1/2021). Judicial review: not confirmed.
- Does it hold payment?
- The administrative appeal suspends the decision only as to the matter contested, unless there is a justified risk of harm that is hard to repair (art. 60 Resolution CD/ANPD 1/2021). Preventive measures can stay in force meanwhile, as in the 2024 Meta case.
- Further appeal
- Ordinary federal appeals: Regional Federal Court (TRF), then the Superior Court of Justice (STJ) and, on constitutional questions, the Federal Supreme Court (STF).
- If the authority does nothing
- Not confirmed. There is no specific statutory remedy against ANPD inaction; complainants typically turn to consumer bodies, public prosecutors or the courts directly.
Suing the organisation directly
- Courts
- Yes: art. 42 LGPD makes controllers and processors liable for material, moral, individual or collective damage caused by processing in breach of the law, and art. 22 allows defence of data subjects' interests individually or collectively in court. Claims go to the ordinary state civil courts, including small claims courts, or consumer courts where the Consumer Defence Code applies.
- Compensation
- No statutory damages; compensation is assessed by the judge. There is heavy volume of individual LGPD litigation, and the burden of proof can be reversed in the data subject's favour (art. 42 para. 2). The STJ has reportedly held that a leak of ordinary (non-sensitive) personal data does not by itself create presumed moral damages (case reference not confirmed).
- Collective actions
- Yes: collective redress through the public civil action (ação civil pública, Law 7.347/1985) and the Consumer Defence Code, brought by public prosecutors, public defenders, consumer bodies and associations such as Idec. Prosecutors also obtain settlement agreements (TACs) with companies.
Cases worth knowing
- Telekall Infoservice: first ANPD fine 2023
In July 2023 the ANPD fined a small telemarketing firm BRL 14,400 in total, plus a warning, for processing personal data without a legal basis to sell contact lists for the 2020 municipal election campaign and for failing to cooperate. It is the only ANPD fine on a private company found in the sources checked. Source - Meta AI training: preventive suspension 2024
On 2 July 2024 the ANPD Board ordered Meta, as a preventive measure, to suspend its new privacy policy allowing Facebook, Instagram and Messenger data to be used to train generative AI, under a daily fine of BRL 50,000, citing an inadequate legitimate interest basis, poor transparency, obstacles to objecting and risks to children's data. After Meta submitted a compliance plan (in-app notices, opt-out forms, a 30-day wait, no use of under-18 accounts), the ANPD lifted the suspension on 30 August 2024 by Despacho Decisório 33/2024/PR/ANPD. Source - INSS and Ministry of Health: sanctions against public bodies 2024
In 2024 the ANPD ordered the National Social Security Institute (INSS) to publicise its infringement for 60 days after it failed to notify data subjects of an incident involving more than 90 million unauthorised queries to its benefits systems, and issued warnings to the Ministry of Health, including over CPF numbers and health data exposed through an unauthenticated API. No fines were possible because art. 52 para. 3 LGPD excludes public bodies from monetary penalties. Source
Worth knowing
- The cap is 2% of Brazilian revenue, capped at BRL 50 million per infringement, not a share of worldwide turnover, so the absolute ceiling is low for multinationals; the daily fine attached to preventive orders can matter more.
- Consumer authorities (Procons, Senacon) and public prosecutors have historically produced larger privacy-related penalties and settlements than the ANPD, using the Consumer Defence Code; a controller can face several enforcers for the same facts.
- The ANPD became a full regulatory agency only in 2025-2026 and its only confirmed fine is BRL 14,400 on a micro-enterprise; most sanctioned entities are public bodies, which can be warned but never fined.
- Private litigation is the main real-world enforcement channel: thousands of individual LGPD damages claims are filed in civil and small claims courts.
Sources (12) research confidence: medium
- LGPD, Law 13.709/2018 (Planalto)
- Chamber of Deputies: Provisional measure structures the National Data Protection Agency
- Senado Notícias: Provisional measure transforms ANPD into regulatory agency
- Teletime: Senate approves MP that transforms ANPD into agency (24 Feb 2026) secondary
- DLA Piper Data Protection Laws of the World: Brazil enforcement and authority secondary
- Telesíntese: ANPD can apply only one fine among eight sanctioning procedures (Telekall) secondary
- Confidata: map of ANPD sanctions secondary
- Mayer Brown: retrospective on ANPD in 2024 secondary
- Portal de Privacidade (Paraíba state): ANPD orders precautionary suspension of Meta AI training secondary
- Consumidor Moderno: ANPD suspends Meta privacy policy secondary
- Correio Braziliense: ANPD keeps Meta suspension after reconsideration request secondary
- Desinformante: ANPD frees Meta to use Brazilians' data for AI (Despacho Decisório 33/2024) secondary
ArgentinaAAIPAmericas
In plain words
In Argentina you first ask the organisation for your data or a correction; it has 10 days for access and 5 working days for corrections. If it fails, you can file a free online complaint with the Agency for Access to Public Information, which can investigate and impose warnings, suspensions or small fines, or you can go straight to a judge with a fast 'habeas data' action. Compensation has to be claimed separately in the civil courts.
Route of a fine
- AAIP decision
- Federal administrative courts
- Supreme Court
The authority
- Name
- Agency for Access to Public Information (National Directorate for Personal Data Protection) (Agencia de Acceso a la Información Pública (Dirección Nacional de Protección de Datos Personales), AAIP) Website
- How it is organised
- A self-governing body created by the Access to Public Information Law 27.275 (2016) and given the data protection supervisory role in 2017, operating within the orbit of the Chief of Cabinet of Ministers. Data protection is handled by its National Directorate for Personal Data Protection; the AAIP also runs the national 'No Llame' do-not-call registry under Law 26.951.
- Regional authorities
- Some provinces and the City of Buenos Aires have their own data protection rules and bodies; Law 25.326 invites provincial adherence and federal jurisdiction applies to national bodies and interjurisdictional networks (art. 44). Consumer authorities also act on related complaints.
- National law
- Personal Data Protection Law 25.326 of 2000 (Ley de Protección de los Datos Personales), regulated by Decree 1558/2001, with constitutional habeas data in art. 43 of the National Constitution. Sanctions are classified and graded by AAIP Resolution 126/2024 (published 24 May 2024, in force 1 June 2024). A replacement bill sent by the executive in 2023 (Message 87/2023) was never enacted. Text
Complaining
- How
- By filing a complaint (denuncia) for breach of Law 25.326 with the AAIP, online through the remote procedures platform, free of charge, in Spanish, attaching a copy of the original request to the controller and any reply.
- Contact the organisation first?
- Yes in practice: the AAIP asks for proof that the right was first exercised with the controller. The controller must answer an access request within 10 calendar days (art. 14) and act on rectification, update or deletion within 5 working days.
- Deadlines
- Not confirmed; no published deadline for the AAIP to decide a complaint was found.
- The complainant's position
- Not confirmed. The sanctioning procedure is an administrative inquiry (sumario) between the AAIP and the controller; the complainant's party status was not confirmed.
Procedure
- Complaint, or own-initiative action (for example the April 2026 investigation into debt collection calls by 5 ON LINE S.R.L.).
- Administrative inquiry (sumario) under art. 31, section 3 of Decree 1558/2001, with notice of the charges and a right of defence.
- Decision classifying the infringement as minor, serious or very serious and imposing sanctions under Resolution 126/2024.
- Voluntary payment within 20 working days of notification reduces the fine by 50%.
- Final sanctions are entered in a public register of infringers (sanciones firmes) on the AAIP website.
- Who decides
- The AAIP (head of the agency), acting through its National Directorate for Personal Data Protection.
- Limitation
- Not confirmed. Resolution 126/2024 counts recidivism over 3 years from notification of a prior sanction.
Fines
- Who imposes them
- The AAIP imposes fines itself by administrative decision (art. 31 Law 25.326), so who_penalises is regulator. The statutory range is ARS 1,000 to ARS 100,000 per infringement; Resolution 126/2024 splits it into minor (ARS 1,000 to 80,000), serious (ARS 80,001 to 90,000) and very serious (ARS 90,001 to 100,000) bands, and caps accumulated fines for the same conduct at 500 times the band maximum (so at most ARS 50 million).
- Public bodies
- Not confirmed. The law covers public and private databases, but whether the AAIP fines public bodies in practice was not confirmed.
- National specifics
- Other sanctions: warnings, suspension (up to 30 days for serious, 31 to 365 days for very serious), closure or cancellation of the database, plus orders to comply and to train staff. The fine amounts were set in 2000 and never indexed, so with inflation they are very small in real terms. Art. 32 added criminal offences to the Penal Code (arts. 117 bis and 157 bis): 1 month to 2 years' prison for knowingly inserting false data or unlawfully accessing or disclosing data in a database, and up to 3 years for knowingly supplying false information from a database to third parties.
Appeals
- First court
- Not confirmed. Under general federal administrative law (Law 19.549) AAIP decisions can be challenged by administrative remedies and then before the federal contentious-administrative courts.
- Deadline
- Not confirmed.
- Does it hold payment?
- Not confirmed.
- Further appeal
- Not confirmed; ordinary federal appeals end at the National Supreme Court of Justice on federal or constitutional questions.
- If the authority does nothing
- The data subject does not need the AAIP: the habeas data action (art. 43 Constitution, arts. 33 to 43 Law 25.326) goes directly to a judge to obtain access, rectification, update, confidentiality or deletion.
Suing the organisation directly
- Courts
- Habeas data is a fast judicial action in which the judge orders the controller to report within a maximum of 5 working days and then rules on deletion, rectification or confidentiality (arts. 38 to 43). The competent judge can be at the plaintiff's or defendant's domicile or where the effects occur, with federal courts for national bodies and interjurisdictional networks (art. 36).
- Compensation
- Habeas data does not award damages. Compensation for privacy harm is claimed separately in the civil courts under general civil liability rules, with no statutory damages (so private_action is limited).
- Collective actions
- Argentina's Supreme Court recognised collective actions for homogeneous individual rights in the Halabi case (2009), which concerned telecommunications data retention; collective claims are possible but there is no specific data protection class action statute (case details not confirmed against a primary source).
Cases worth knowing
- 5 ON LINE S.R.L.: debt collection investigation 2026
In April 2026 the AAIP opened an investigation into a collection agency that allegedly contacted debtors' relatives, friends, co-workers and neighbours, and warned the creditor entities that share data with collectors that they remain jointly liable. The outcome was not confirmed. Source
Worth knowing
- Argentina has an EU adequacy decision (2003), yet its statutory fines remain capped at ARS 100,000 per infringement, an amount set in 2000 and eroded by inflation to a trivial figure; the 500-times accumulation cap is the only route to larger totals.
- Habeas data is a constitutional judicial action, so individuals often bypass the regulator entirely and go straight to a judge for access or deletion.
- The regulator shares its agency with freedom of information and the do-not-call registry, and much of its visible enforcement concerns 'No Llame' telemarketing complaints.
- Modernisation has stalled: the 2023 GDPR-style reform bill was never enacted, so the 2000 law still applies.
- Fines are graded under AAIP Resolution 126/2024, which sets 16 grading criteria and replaced the earlier sanction rules.
Sources (8) research confidence: medium
- Law 25.326 (Argentina.gob.ar normativa)
- AAIP Resolution 126/2024 (official text)
- Boletín Oficial: AAIP Resolution 126/2024
- AAIP: personal data protection
- AAIP: your rights and how to complain
- AAIP: register of those who do not comply (final sanctions)
- AAIP: data protection bill (Message 87/2023)
- AAIP news: investigation into debt collection practices (April 2026)
TurkeyKVKKMiddle East
In plain words
You first write to the company, which has 30 days to answer; if you are not satisfied you have a short window to complain to the KVKK Board. The Board investigates, can order the company to fix the problem and fine it directly, and the company can challenge the fine in an administrative court. Compensation for you is a separate claim in the civil courts.
Route of a fine
- KVKK Board decision
- Administrative court
- Regional administrative court
- Council of State
The authority
- Name
- Personal Data Protection Authority (decisions taken by the Personal Data Protection Board) (Kişisel Verileri Koruma Kurumu (Kişisel Verileri Koruma Kurulu), KVKK) Website
- How it is organised
- Public legal entity with administrative and financial autonomy, related to the Presidency. Its decision-making body is the nine-member Board (Kurul), which handles complaints, runs ex officio examinations and imposes administrative fines (Art. 22).
- Regional authorities
- No regional authorities. Public prosecutors and criminal courts handle the data offences in the Turkish Penal Code (Arts. 135 to 140), and sector regulators (for example the ICT Authority for electronic communications and the banking regulator) apply their own confidentiality rules.
- National law
- Law No. 6698 on the Protection of Personal Data (2016), amended by Law No. 7499 published on 12 March 2024 (new rules on special category data and cross-border transfers, a new fine for failing to notify standard contracts, and fines to be challenged before administrative courts, in force 1 June 2024) Text
Complaining
- How
- Written complaint to the Board, including through the Authority's online complaint system; no fee is reported. Complaints are in Turkish.
- Contact the organisation first?
- Yes, mandatory. The data subject must first apply to the data controller (Art. 13), which has 30 days to answer free of charge; only then may they complain to the Board (Art. 14(2)).
- Deadlines
- The complaint must be lodged within 30 days of learning the controller's answer, and in any case within 60 days of the original application (Art. 14(1)). If the Board does not answer within 60 days of the complaint, the complaint is deemed refused (Art. 15(4)).
- The complainant's position
- The complainant receives the Board's answer but the Board's fine is an administrative sanction, not compensation; compensation claims under general law are reserved (Art. 14(3)).
Procedure
- Application to the data controller (Art. 13), or the Board learns of an alleged violation and acts ex officio (Art. 15(1))
- Complaint to the Board within the Art. 14 deadlines
- Examination: the controller must provide information and documents within 15 days and allow on-site inspection (Art. 15(3))
- Board decision ordering the controller to remedy the violation within 30 days of notification (Art. 15(5)), possibly a public principle decision for widespread violations (Art. 15(6)), and an administrative fine (Art. 18)
- Where damage would be difficult or impossible to remedy and the violation is clear, the Board may order processing or transfers abroad to stop (Art. 15(7))
- Who decides
- The Personal Data Protection Board.
- Limitation
- General limitation periods of the Law on Misdemeanours No. 5326 apply to administrative fines (specific periods not confirmed this session).
Fines
- Who imposes them
- Regulator: the Board imposes administrative fines itself by decision (Arts. 18 and 22). Fines are fixed bands per violation type, revalued every January; for 2026 the bands are about TRY 85,437 to 1,709,200 for breach of the duty to inform (Art. 10), TRY 256,357 to 17,092,242 for data security failures (Art. 12), TRY 427,263 to 17,092,242 for not complying with Board decisions, TRY 341,809 to 17,092,242 for registry (VERBIS) breaches, and about TRY 90,308 to 1,806,177 for failing to notify standard transfer contracts.
- Public bodies
- Public institutions are not fined: where a violation occurs within a public institution or a professional organisation with public status, disciplinary proceedings are applied to the officials concerned on the Board's notice, and the result is reported to the Board (Art. 18).
- National specifics
- Criminal offences are prosecuted separately: Art. 17 applies Turkish Penal Code Arts. 135 to 140 (unlawful recording, unlawful disclosure or acquisition, failure to destroy data), and failure to erase or anonymise data is punishable under TPC Art. 138. The Board also publishes decision summaries that name sectors and sometimes companies.
Appeals
- First court
- Since 1 June 2024, administrative courts (idare mahkemeleri), under Art. 18 as amended by Law No. 7499. Before that, objections to fines went to criminal judgeships of peace (sulh ceza hakimlikleri) under the Law on Misdemeanours.
- Deadline
- Not confirmed; the general time limit for annulment actions before administrative courts under the Administrative Procedure Law is 60 days from notification (not confirmed for this law specifically).
- Does it hold payment?
- Not confirmed.
- Further appeal
- Regional administrative courts and the Council of State (Danıştay) under ordinary administrative procedure; the Constitutional Court by individual application for rights violations.
- If the authority does nothing
- A complaint not answered within 60 days is deemed refused (Art. 15(4)); Board decisions on complaints are administrative acts that can be challenged before administrative courts.
Suing the organisation directly
- Courts
- Yes, through general law: KVKK creates no specific damages action, but Art. 14(3) reserves compensation for anyone whose personal rights are violated, so individuals can sue in the civil courts under the Turkish Code of Obligations and the Civil Code's personality rights provisions, without first going to the Board.
- Compensation
- Material and moral (non-pecuniary) damages under general civil law; no statutory or minimum damages.
- Collective actions
- No class action mechanism; associations can bring limited collective claims under general procedure (not confirmed for data cases).
Cases worth knowing
- Facebook (Meta) data breach fine 2019
In April 2019 (announced 10 May 2019) the Board fined Facebook TRY 1.65 million over a September 2018 photo API bug that let third-party apps access photos of around 300,000 Turkish users for 12 days, finding inadequate technical measures. In October 2019 it fined Facebook a further TRY 1.6 million over the 'View As' breach affecting 280,959 users, partly for failing to notify the Authority. Source - Yemeksepeti breach fine 2021
By Decision No. 2021/1324 of 23 December 2021 the Board fined the food delivery platform Yemeksepeti TRY 1.9 million for inadequate technical and administrative security measures after a March 2021 breach of data on about 21.5 million users that went undetected for eight days. Source - Law No. 7499: fines move to administrative courts 2024
The March 2024 amendment changed the forum for challenging KVKK fines from criminal judgeships of peace to administrative courts from 1 June 2024, and added a new fine for failing to notify standard contracts for transfers abroad. Source
Worth knowing
- Fines are fixed bands in Turkish lira, revalued every year by the tax revaluation rate, so the statutory amounts in the 2016 text (TRY 5,000 to 1,000,000) are far below current figures; there is no turnover-based cap.
- You cannot complain to the regulator without first applying to the controller, and the window to complain afterwards is short (30 days from the answer, at most 60 days from the application).
- Public bodies are never fined: their officials face disciplinary proceedings instead.
- Until June 2024 fines were challenged before criminal judgeships of peace, a single-judge criminal court, rather than administrative courts.
- Data offences in the Penal Code carry prison sentences and run in parallel with the Board's administrative regime.
Sources (5) research confidence: medium
- KVKK: Law No. 6698 (English translation)
- Prighter: Turkish KVKK legal text (consolidated English text incl. Art. 18 as amended) secondary
- Erdem and Erdem: Administrative fines under Law No. 6698 updated secondary
- Köksal Partners: KVKK administrative fines 2026 secondary
- Istanbul Attorneys: KVKK compliance for foreign companies (appeal route since 1 June 2024) secondary
IsraelPPAMiddle East
In plain words
You can complain to the Privacy Protection Authority at the Ministry of Justice, which decides whether to inspect the organisation and, since August 2025, can fine it directly. Serious cases can become criminal investigations. Separately, you can sue the organisation yourself and claim fixed statutory compensation without proving you suffered harm.
Route of a fine
- PPA financial sanction
- Magistrates' Court (reported)
The authority
- Name
- Privacy Protection Authority (הרשות להגנת הפרטיות (HaRashut LeHaganat HaPratiyut), PPA) Website
- How it is organised
- A unit within the Ministry of Justice, headed by the Registrar of Databases, rather than a separate independent statutory body. Since Amendment 13 it supervises, inspects, investigates (including criminal investigation of privacy offences) and imposes financial sanctions.
- Regional authorities
- No regional authorities. The State Attorney and police prosecute criminal privacy offences; sector regulators (Bank of Israel, Capital Markets Authority, Ministry of Health) apply sectoral confidentiality rules. The European Commission has recognised Israel as adequate since 2011.
- National law
- Protection of Privacy Law, 5741-1981, with Amendment 13 (published 14 August 2024, in force 14 August 2025) and the Protection of Privacy (Data Security) Regulations 2017 Text
Complaining
- How
- Online complaint form on the PPA pages of gov.il; no fee reported. Complaints can be filed in Hebrew; availability of other languages not confirmed.
- Contact the organisation first?
- Not confirmed as a formal requirement.
- Deadlines
- No statutory deadline for the PPA to decide complaints was found.
- The complainant's position
- The complainant is a source of information, not a party: the PPA decides whether to open an inspection or investigation. Individual redress is pursued in the civil courts.
Procedure
- Complaint, breach report, media report or own-initiative audit (sectoral audits are common)
- Administrative inspection: inspectors can demand documents and system logs and enter premises; in serious cases a criminal investigation
- Findings, and where a financial sanction is intended a notice of intent giving the controller the right to respond (procedural details not confirmed)
- Decision: administrative warning, orders to remedy or stop processing, suspension of a database, financial sanction, and publication of the sanction; or referral for criminal prosecution
- Who decides
- The head of the Privacy Protection Authority for administrative measures and financial sanctions; criminal courts for offences.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- Regulator: since 14 August 2025 the PPA imposes financial sanctions itself, without going to court. Under Amendment 13 sanctions are calculated per violation from base amounts that vary by provision (secondary sources cite ILS 150,000 for key breaches and ILS 320,000 for some security breaches), scaled by the number of data subjects in the database and doubled for very large databases or repeat violations, with an overall ceiling reported as 5% of annual turnover. Secondary sources differ on the figures and the statute was not checked. Before Amendment 13 the PPA could only impose small fines (around ILS 10,000 to 25,000).
- Public bodies
- Public bodies are within the regime and must appoint data protection officers; secondary sources indicate they can receive financial sanctions, but this was not confirmed from the statute.
- National specifics
- Criminal offences: wilful infringement of privacy under s 5 carries up to 5 years imprisonment, and Amendment 13 raised database offences (such as unauthorised processing, misleading the PPA or obstructing an investigation) to up to 3 years (secondary sources). Reductions are available for having a DPO and self-reporting (secondary).
Appeals
- First court
- Magistrates' Court, according to a 2026 practice guide (not confirmed from the statute).
- Deadline
- 45 days, according to a 2026 practice guide (not confirmed from the statute).
- Does it hold payment?
- No, unless the head of the PPA agrees or the court orders a stay, according to a 2026 practice guide (not confirmed from the statute).
- Further appeal
- Not confirmed. Administrative decisions of government bodies can also be challenged before the Supreme Court sitting as High Court of Justice or the administrative affairs courts, depending on the matter.
- If the authority does nothing
- Not confirmed; a complainant would rely on general administrative law petitions, but no specific route was found.
Suing the organisation directly
- Courts
- Yes. Infringement of privacy is a civil wrong under the Protection of Privacy Law (s 4), actionable in the Magistrates' or District Courts depending on value, and individuals can sue without going to the PPA.
- Compensation
- Statutory compensation without proof of harm: for general privacy infringements under s 29A, reported as up to about ILS 50,000 (index-linked, around ILS 65,000) and doubled where the infringement was intended to harm, giving the ILS 100,000 figure cited by some sources; Amendment 13 added statutory damages of up to ILS 10,000 for certain database breaches such as failure to notify or correct data. Exact current amounts not confirmed from the statute.
- Collective actions
- Class actions are available under the Class Actions Law 2006 and are a significant risk for breaches; representative and personal actions are both used (secondary source).
Cases worth knowing
- Sanction on a National Insurance Institute employee 2025
A law firm reported that in August 2025 the PPA imposed ILS 75,000 on a National Insurance Institute employee for 15 instances of accessing personal data in the Institute's systems for non-professional purposes, in breach of s 8(b). Whether this was imposed under the new Amendment 13 regime is not confirmed; the PPA decision was not checked. Source - Meuhedet Health Fund: first reported Amendment 13 sanction 2026
Reported as the first financial sanction under Amendment 13: on 21 July 2026 the PPA imposed ILS 256,000 on the Meuhedet Health Fund for failing to report a serious security event immediately under the Data Security Regulations, after it learned of unauthorised access to medical records in November 2025 but reported only in late January 2026. The amount reflects statutory reductions. From a consultancy summary, not the PPA decision. Source
Worth knowing
- The regulator sits inside the Ministry of Justice rather than being a separately constituted independent authority, yet Israel has held an EU adequacy decision since 2011.
- Until August 2025 the regulator had almost no fining power; Amendment 13 gave it GDPR-style administrative sanctions, though the first reported sanction under the new regime came almost a year later.
- Individuals can claim statutory compensation without proving any harm, which makes class actions attractive.
- The same authority runs both administrative inspections and criminal investigations of privacy offences.
- Sanctions are scaled by the number of people in the database, not only by the seriousness of the conduct.
Sources (7) research confidence: low
- Privacy Protection Authority (gov.il)
- Baker McKenzie: Israel regulators, enforcement priorities and penalties secondary
- DPOAS: Amendment 13 complete guide secondary
- DPOAS: Israel's Protection of Privacy Law secondary
- AI-Law: first fines under Amendment 13 secondary
- Ius Laboris: Major amendment to privacy law in Israel secondary
- BigID: What Israel's Amendment 13 means for businesses secondary
Saudi ArabiaSDAIAMiddle East
In plain words
You complain to SDAIA through its national data governance platform. A SDAIA violations committee investigates and can warn or fine the organisation directly, and the organisation can challenge that decision in the administrative courts of the Board of Grievances. Serious leaks of sensitive data can be prosecuted as crimes, and you can separately ask a court for compensation if you suffered damage.
Route of a fine
- SDAIA violations committee
- Board of Grievances
The authority
- Name
- Saudi Data and Artificial Intelligence Authority (الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا), SDAIA) Website
- How it is organised
- Government authority reporting to the Prime Minister, designated as the competent authority under the PDPL. Enforcement decisions are taken by its Committees for Reviewing Violations; the National Data Management Office (NDMO) sits within SDAIA and the PDPL contemplated a possible later transfer of the role to it, which had not been announced as at 2026 (secondary).
- Regional authorities
- No regional authorities. The Public Prosecution investigates and prosecutes the PDPL's criminal offences; sector regulators such as the Saudi Central Bank, the Communications, Space and Technology Commission and the National Cybersecurity Authority apply their own data rules.
- National law
- Personal Data Protection Law (Royal Decree M/19 of 1443H, amended by Royal Decree M/148 of 1444H) and its Implementing Regulations and Regulation on Personal Data Transfer; in force 14 September 2023 with a one-year grace period, fully enforceable since 14 September 2024 Text
Complaining
- How
- Complaints and breach notifications go through SDAIA's National Data Governance Platform; no fee reported. Arabic is the working language; English availability not confirmed.
- Contact the organisation first?
- Not confirmed as a formal requirement, though data subject rights must first be exercised against the controller.
- Deadlines
- The deadline for lodging complaints and SDAIA's handling deadline are set in the Implementing Regulations; exact periods not confirmed this session. Controllers must notify SDAIA of breaches within 72 hours.
- The complainant's position
- The complainant is not a party to the violation proceedings; damages must be claimed separately in court (Art. 40).
Procedure
- Complaint, breach notification or own-initiative inspection by SDAIA staff
- Referral to a Committee for Reviewing Violations, which notifies the controller and hears its response (secondary sources report short response windows of about 5 days)
- Committee decision: warning or fine of up to SAR 5 million, doubled for repeat violations (Art. 36), with possible publication at the violator's expense
- Separately, the Public Prosecution investigates criminal offences under Art. 35 and prosecutes before the competent criminal court, which may also order confiscation of proceeds (Art. 38)
- Who decides
- SDAIA's Committees for Reviewing Violations for administrative penalties; the competent criminal court for Art. 35 offences.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- Regulator: SDAIA's Committees for Reviewing Violations impose warnings and fines themselves (Art. 36), up to SAR 5 million per violation, which may be doubled for a repeat violation. Criminal penalties under Art. 35 (disclosure or publication of sensitive data with intent to harm or for personal benefit: up to 2 years imprisonment and/or a fine up to SAR 3 million) are imposed by courts after Public Prosecution proceedings.
- Public bodies
- Public entities are subject to the PDPL; whether committees fine public entities in practice was not confirmed.
- National specifics
- In January 2026 SDAIA announced that its committees had issued 48 enforcement decisions (covering processing without a legal basis, unauthorised disclosure, inadequate security and unsolicited marketing) but published no names, amounts or decision texts.
Appeals
- First court
- The competent court, which for administrative decisions of government bodies is the administrative judiciary of the Board of Grievances (Diwan al-Mazalim); secondary sources state appeals go to the competent court.
- Deadline
- Reported as 60 days from notification of the committee decision (secondary source; consistent with Board of Grievances procedure but not confirmed from the PDPL text).
- Does it hold payment?
- Not confirmed.
- Further appeal
- Administrative Court of Appeal and the High Administrative Court within the Board of Grievances (not confirmed for PDPL cases specifically).
- If the authority does nothing
- Not confirmed; no specific route against SDAIA inaction was found.
Suing the organisation directly
- Courts
- Yes: Art. 40 lets anyone who suffers damage from a PDPL violation claim compensation before the competent court. Damage must be proved and there is no published case law.
- Compensation
- Compensation for material or moral damage as assessed by the court; no statutory damages.
- Collective actions
- No class action mechanism.
Cases worth knowing
- SDAIA announces 48 enforcement decisions 2026
On 16 January 2026 SDAIA said its Committees for Reviewing Violations had issued 48 decisions confirming violations and imposing penalties, covering unlawful processing, unauthorised disclosure, inadequate safeguards and unsolicited marketing messages. No company names or amounts were published. Source
Worth knowing
- Enforcement is opaque: decisions are announced in aggregate without names, amounts or reasoning.
- The regulator is also the national data and AI agency, not a dedicated privacy authority.
- Disclosing sensitive data with intent to harm is a crime with up to 2 years imprisonment, prosecuted by the Public Prosecution rather than the regulator.
- Fines are fixed amounts per violation (up to SAR 5 million, doubled for repeat offences), not turnover-based.
Sources (4) research confidence: medium
United Arab EmiratesUAE Data Office / DIFC Commissioner / ADGM ODPMiddle East
In plain words
Where you complain depends on where the organisation sits. If it is in the DIFC or ADGM financial free zones, you complain to that zone's Data Protection Commissioner, who can fine it, and appeals go to the zone's own courts; in the DIFC you can also sue directly. Elsewhere in the UAE the federal law exists but its regulator is not yet fully running and no fines have been set, so in practice there is no federal privacy enforcement yet.
Route of a fine
- DIFC or ADGM Commissioner fine
- DIFC or ADGM Courts
The authority
- Name
- UAE Data Office (federal); DIFC Commissioner of Data Protection; ADGM Office of Data Protection (مكتب الإمارات للبيانات (UAE Data Office), UAE Data Office / DIFC Commissioner / ADGM ODP) Website
- How it is organised
- Three separate regimes. The federal UAE Data Office was created by Federal Decree-Law No. 44 of 2021 but is not yet fully operational, with transitional administrative support from the TDRA. The Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) financial free zones each have their own data protection Commissioner, which is the operational enforcement in practice.
- Regional authorities
- Federal PDPL does not apply in the DIFC and ADGM, nor to government data, health data and banking and credit data covered by their own laws. Sector regulators (Central Bank of the UAE, TDRA, health authorities) enforce sectoral confidentiality rules, and the Public Prosecution prosecutes privacy and data crimes under Federal Decree-Law No. 34 of 2021 on cybercrimes and the Penal Code.
- National law
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (in force 2 January 2022; Executive Regulations still not issued as at September 2026, and compliance is due six months after they are issued under Art. 29); DIFC Data Protection Law No. 5 of 2020 (amended by DIFC Law No. 1 of 2025, effective 15 July 2025); ADGM Data Protection Regulations 2021 Text
Complaining
- How
- Federal: the PDPL allows complaints to the UAE Data Office (Art. 24), but no operational complaint channel or procedure has been confirmed. DIFC and ADGM: complaints to the respective Commissioner through their websites, free of charge, in English.
- Contact the organisation first?
- Not confirmed for any of the three regimes.
- Deadlines
- Federal: a grievance against a Data Office decision can be filed with its Director General within 30 days (Art. 25, secondary source). DIFC and ADGM complaint deadlines not confirmed.
- The complainant's position
- In DIFC the complainant can appeal a Commissioner decision to the DIFC Courts and, since July 2025, sue directly; in ADGM the complainant can seek compensation in the ADGM Courts.
Procedure
- Federal: complaint to the UAE Data Office, investigation, and administrative sanctions to be defined by Cabinet decision (Art. 26); not yet operating in practice
- DIFC: complaint or own-initiative inquiry by the Commissioner, directions to remedy or restrict processing, and administrative fines
- ADGM: complaint or investigation by the Commissioner of Data Protection, directions including temporary or permanent bans on processing, and fines
- Appeals to the DIFC Courts or ADGM Courts respectively
- Who decides
- Federal: the Cabinet on the proposal of the Data Office Director General (sanctions not yet defined). DIFC: the Commissioner of Data Protection. ADGM: the Commissioner of Data Protection.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- None-yet at federal level: Art. 26 of the PDPL leaves violations and administrative penalties to a Cabinet decision that had not been issued as at September 2026, so the federal regulator has no fine schedule to apply. In the free zones the Commissioners fine directly by decision without going to court: DIFC fines follow fixed amounts per contravention in Schedule 2 of the DP Law (reported up to USD 100,000 each), and ADGM fines can reach USD 28 million.
- Public bodies
- Federal government data is excluded from the federal PDPL; public bodies in the free zones not confirmed.
- National specifics
- Criminal liability for privacy invasions and unlawful data disclosure exists under Federal Decree-Law No. 34 of 2021 on combating rumours and cybercrimes and the Penal Code, prosecuted by the Public Prosecution; specific articles and penalties were not confirmed this session.
Appeals
- First court
- Federal: grievance to the Data Office Director General (Art. 25), then presumably the federal courts (not confirmed). DIFC: appeal to the DIFC Courts. ADGM: reference to the ADGM Courts.
- Deadline
- DIFC: 30 days from the Commissioner's decision (secondary). ADGM: within three months of the penalty notice (stated in ADGM penalty notices). Federal grievance: 30 days (secondary).
- Does it hold payment?
- Not confirmed.
- Further appeal
- DIFC Court of Appeal within the DIFC Courts; ADGM Court of Appeal within the ADGM Courts (not confirmed for data protection matters specifically).
- If the authority does nothing
- Not confirmed for any regime.
Suing the organisation directly
- Courts
- Limited: under the federal PDPL there is no specific damages action and general civil law would apply (not confirmed). In the DIFC, since 15 July 2025 data subjects can sue controllers and processors directly in the DIFC Courts without first going to the Commissioner. In ADGM, data subjects can seek compensation in the ADGM Courts.
- Compensation
- DIFC: compensation for material and non-material loss, including distress (secondary). ADGM: compensation as assessed by the court. No statutory damages.
- Collective actions
- Not confirmed; no class action regime identified.
Cases worth knowing
- ADGM Commissioner fines Okadoc Technologies 2024
On 21 May 2024 the ADGM Commissioner of Data Protection fined Okadoc Technologies USD 20,000 (reduced to USD 16,000 for early payment) for failing to answer a data subject access request within two months, having no data protection policy and not cooperating with the Office of Data Protection (DPR 2021 ss.10, 22 and 29). Source - ADGM action against VentureRock Global 2023
On 23 June 2023 the ADGM Commissioner of Data Protection issued a Direction to VentureRock Global under s.54(1) of the Data Protection Regulations 2021 for breaching the security principle, citing poor cybersecurity practices, inadequate staff training and missing policies. It was a direction to remedy, not a fine. Source - Federal PDPL: no enforcement yet 2026
More than four years after the federal PDPL took effect, the Executive Regulations and the Cabinet decision on penalties were still not on the UAE legislation portal as at 23 September 2026, so no federal fines can be imposed. Source
Worth knowing
- Three regimes in one country: the federal PDPL is on the books but not yet enforceable, while the DIFC and ADGM free zones have mature, GDPR-style regimes with their own Commissioners and common-law courts.
- The federal compliance deadline only starts running six months after Executive Regulations that have not been issued.
- ADGM's maximum fine (USD 28 million) is far higher than DIFC's per-contravention fines.
- DIFC added a direct private right of action in July 2025, so individuals no longer need the Commissioner first.
- Government data, health data and banking data are carved out of the federal law and handled by separate rules.
Sources (7) research confidence: medium
- DIFC Data Protection
- UAE Legislation portal
- Chambers Practice Guides: Data Protection and Privacy 2026, UAE trends and developments secondary
- ITSecNow: UAE PDPL Executive Regulations 2026 explained secondary
- RecordingLaw: UAE data privacy laws (Federal PDPL, DIFC and ADGM) secondary
- Multilaw: Data Protection Guide United Arab Emirates secondary
- DY Legal Consultants: Data protection law UAE secondary
NigeriaNDPCAfrica
In plain words
You complain to the Nigeria Data Protection Commission, which can investigate, order the company to fix the problem and impose a fine linked to its revenue. A company that disagrees goes to the Federal High Court, and you can also sue for damages yourself. Separately, the consumer protection authority can fine companies for unfair data practices, with appeals to a specialist tribunal.
Route of a fine
- NDPC order
- Federal High Court
- Court of Appeal
The authority
- Name
- Nigeria Data Protection Commission (Nigeria Data Protection Commission, NDPC) Website
- How it is organised
- Federal commission established by the Nigeria Data Protection Act 2023, succeeding the Nigeria Data Protection Bureau; headed by a National Commissioner. It investigates, issues compliance and enforcement orders and imposes remedial sanctions itself.
- Regional authorities
- No regional regulators. In practice the Federal Competition and Consumer Protection Commission (FCCPC) also enforces privacy as a consumer protection matter under the Federal Competition and Consumer Protection Act 2018 and imposed the largest privacy-related fine (Meta, USD 220 million); sector regulators such as the Central Bank also set data rules.
- National law
- Nigeria Data Protection Act 2023 (NDPA), signed and in force June 2023, which replaced the Nigeria Data Protection Regulation 2019 (NDPR) as the main framework; detailed by the NDPA General Application and Implementation Directive (GAID) 2025, reported as issued in March 2025 and effective 19 September 2025. Text
Complaining
- How
- A data subject aggrieved by a controller's or processor's conduct may complain to the NDPC (NDPA s.46, as described in secondary sources); the Commission may also act on its own initiative. Complaint form, fee and language were not confirmed.
- Contact the organisation first?
- Not confirmed.
- Deadlines
- Not confirmed.
- The complainant's position
- Not confirmed beyond the right to complain and to seek judicial review or damages in court.
Procedure
- Complaint or own-initiative investigation (NDPA s.46); in the Fidelity Bank case the NDPC sent an investigation notice and held a pre-action meeting with the bank.
- Compliance order (s.47) requiring the controller to remedy the breach, which may include a remedial fee or payment.
- Enforcement order and sanction (s.48), including a remedial fine set by reference to annual gross revenue, typically with a 14-day payment deadline in published cases.
- Who decides
- The Nigeria Data Protection Commission.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- The NDPC imposes remedial fines itself by enforcement order (s.48), so 'regulator'. The FCCPC separately imposes administrative penalties under consumer and competition law, reviewable by the Competition and Consumer Protection Tribunal.
- Public bodies
- The NDPA applies to public and private controllers, but whether the NDPC has fined a public body was not confirmed.
- National specifics
- The maximum is the greater of a fixed sum and 2% of annual gross revenue in the preceding financial year: NGN 10 million or 2% for data controllers and processors of major importance, and (per secondary sources) NGN 2 million or 2% for others, so the cap is turnover based. The NDPC has also used negotiated 'remedial fees'. Criminal offences exist for failing to comply with Commission orders, but the penalty details were not confirmed from the statute text.
Appeals
- First court
- The Federal High Court, which has jurisdiction over actions against federal agencies; the NDPA provides for judicial review of Commission orders (reported as s.50, not confirmed from the statute text). Meta's challenge to the NDPC's USD 32.8 million fine was heard there by Justice James Omotosho, who entered the parties' settlement as a consent judgment on 3 November 2025.
- Deadline
- Not confirmed (reported in secondary sources as 30 days for judicial review, not verified).
- Does it hold payment?
- Not confirmed.
- Further appeal
- Court of Appeal and Supreme Court under the ordinary hierarchy. For FCCPC penalties the route is the Competition and Consumer Protection Tribunal, with further appeal to the Court of Appeal.
- If the authority does nothing
- Not confirmed; judicial review at the Federal High Court is the general route for challenging a federal agency's decision or inaction.
Suing the organisation directly
- Courts
- Yes: the NDPA gives a data subject who suffers injury, loss or harm from a breach a right to recover damages in civil proceedings (reported as s.51), and fundamental rights enforcement actions for the constitutional right to privacy are common in Nigeria, so 'yes'. The statute text of this section was not confirmed directly.
- Compensation
- Not confirmed; no statutory damages amount was confirmed.
- Collective actions
- Representative actions are possible under court rules and civil society groups such as SERAP have threatened litigation on behalf of users, but no collective privacy damages outcome was confirmed.
Cases worth knowing
- FCCPC v Meta Platforms and WhatsApp, USD 220 million 2024-2025
After a joint FCCPC and NDPC investigation into Meta's privacy policies, the FCCPC (the consumer and competition authority, not the NDPC) fined Meta and WhatsApp USD 220 million on 19 July 2024 for exploitative and discriminatory data practices. On 25 April 2025 the Competition and Consumer Protection Tribunal upheld the fine, affirmed the FCCPC's jurisdiction and found Meta's privacy policy offended Nigerian law, awarded the FCCPC USD 35,000 investigation costs, and set aside one order. Whether the fine has been paid or further appealed was not confirmed. Source - NDPC v Fidelity Bank, NGN 555.8 million 2024
The NDPC opened an investigation in April 2023 into inadequate security and data handling at Fidelity Bank, demanded a NGN 250 million remedial fee in December 2023 and, in August 2024, imposed a NGN 555.8 million fine, about 0.1% of the bank's 2023 gross revenue, payable within 14 days and aggravated by lack of cooperation. The bank publicly denied any breach; no court challenge was confirmed. Source - NDPC v Meta, USD 32.8 million, set aside by consent judgment 2025
In February 2025 the NDPC fined Meta USD 32.8 million for behavioural advertising without consent and unlawful cross-border transfers. Meta challenged it in the Federal High Court, Abuja, and on 3 November 2025 Justice James Omotosho entered the parties' settlement as a consent judgment. According to the leaked agreement, the NDPC's final orders, including the fine, were set aside in exchange for general compliance commitments and payment of the NDPC's legal fees. Source
Worth knowing
- The largest privacy fine in Nigeria came from the consumer and competition authority (FCCPC), not the data protection regulator, and was reviewed by a specialist tribunal rather than a court.
- The fine formula is the greater of a fixed sum and 2% of gross revenue, so there is effectively no upper ceiling for large firms.
- The NDPC openly negotiates: it has demanded 'remedial fees' before formal fines, and its USD 32.8 million Meta fine was set aside under a court-endorsed settlement in November 2025.
- Much of the operational detail of the NDPA sits in a regulator-issued directive (the GAID 2025) rather than in the Act.
Sources (10) research confidence: low to medium
- FCCPC: Tribunal upholds FCCPC's USD 220 million fine against Meta/WhatsApp
- Nairametrics: Tribunal orders Meta to pay fine and USD 35,000 in 60 days secondary
- Concurrences: FCCPC imposes USD 220m fine on WhatsApp/Meta secondary
- Techpoint Africa: Meta, NDPC agree out-of-court settlement of USD 32.8 million fine secondary
- Channels TV: Fidelity Bank fined N555.8m by NDPC secondary
- Infusion Lawyers: NDPC's N555.8 million fine against Fidelity Bank secondary
- TheCable: Fidelity Bank disputes NDPC's allegations secondary
- Arise TV: NDPC seeks amicable resolution with Meta secondary
- SERAP: Pay USD 220m fine, compensate victims or face legal action secondary
- Nigeria Data Protection Commission website
KenyaODPCAfrica
In plain words
You complain to the Data Commissioner, in writing or even orally, and the Office must decide within 90 days. If it finds a breach it can order the company to fix it, order it to pay you compensation directly, and fine it up to KES 5 million if it ignores the order. Either side can appeal to the High Court.
Route of a fine
- ODPC penalty notice
- High Court
- Court of Appeal
The authority
- Name
- Office of the Data Protection Commissioner (Office of the Data Protection Commissioner, ODPC) Website
- How it is organised
- State office headed by the Data Commissioner, created by the Data Protection Act 2019. It registers controllers and processors, determines complaints, issues enforcement and penalty notices, and orders compensation to complainants in its determinations.
- Regional authorities
- No regional regulators. Criminal offences under the Act are tried in the ordinary criminal courts; the High Court also hears constitutional privacy petitions under Article 31 of the Constitution.
- National law
- Data Protection Act, 2019 (Act No. 24 of 2019), commenced 25 November 2019; supported by the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021 and the other 2021 regulations. No major amendment to the enforcement chapter was confirmed. Text
Complaining
- How
- A data subject aggrieved by a decision of any person under the Act may lodge a complaint with the Data Commissioner orally or in writing; oral complaints are recorded in writing by the Office (s.56). The detailed form and channels are set by the Complaints Handling Procedure and Enforcement Regulations 2021; no fee was confirmed.
- Contact the organisation first?
- Not required by s.56 as far as confirmed; whether the 2021 Regulations require prior contact with the controller was not confirmed.
- Deadlines
- The ODPC must investigate and conclude a complaint within 90 days (s.56(5)). No time limit for filing was confirmed.
- The complainant's position
- The complainant is a party to the determination and can be awarded compensation by the ODPC itself (s.65). Protections apply to natural persons, not companies, according to ODPC determinations.
Procedure
- Complaint (s.56) or own-initiative inquiry; the ODPC notifies the respondent and investigates, gathering its own evidence rather than relying only on the parties' submissions (s.57).
- Determination within 90 days, which may find liability, order remedial action and award compensation to the complainant (s.65).
- Enforcement notice specifying the contravention and remedial measures, with at least 21 days to comply and a statement of the right of appeal (s.58).
- Penalty notice if the ODPC is satisfied the person has failed or is failing as described in s.58, with the amount set by reference to listed aggravating and mitigating factors (s.62, s.63).
- Who decides
- The Data Commissioner.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- The Data Commissioner imposes administrative fines directly by penalty notice (s.62), so 'regulator'. Penalty notices have typically followed failure to comply with an enforcement notice.
- Public bodies
- The Act applies to public bodies as controllers, but whether the ODPC has fined a public body was not confirmed.
- National specifics
- The cap is up to KES 5 million or, for an undertaking, 1% of the previous year's annual turnover, whichever is lower (s.63), so the turnover figure can only reduce the maximum, which is why the cap is classed as 'fixed'. Separately, ignoring an enforcement notice is a criminal offence (fine up to KES 5 million or up to 2 years' imprisonment, s.58(3)), and the general penalty for other offences is a fine up to KES 3 million or up to 10 years' imprisonment, plus forfeiture or stop orders (s.73).
Appeals
- First court
- The High Court: a person against whom any administrative action is taken by the Data Commissioner, including enforcement and penalty notices, may appeal to it (s.64). In 2025 the High Court dismissed a lender's constitutional petition against its penalty because it had bypassed this statutory appeal.
- Deadline
- No deadline is stated in s.64; a specific deadline in the regulations was not confirmed.
- Does it hold payment?
- Not confirmed.
- Further appeal
- Court of Appeal and then the Supreme Court under the ordinary hierarchy. The High Court has held it will interfere with the ODPC's assessment of compensation only if it was arrived at injudiciously (Muthoni v Solpia, as reported).
- If the authority does nothing
- The complainant can appeal an adverse determination to the High Court under s.64 or, where there is no decision, seek judicial review; a constitutional petition is possible but courts expect the statutory route to be used first.
Suing the organisation directly
- Courts
- Yes. A person who suffers damage by a contravention is entitled to compensation from the controller or processor (s.65); this is usually obtained through an ODPC complaint, and civil claims or constitutional petitions in the High Court are also possible, so 'yes'.
- Compensation
- Damage includes financial loss and non-financial damage, including distress (s.65). The ODPC itself awards compensation in its determinations: an independent tracker counts over 180 determinations with compensation orders and a median award of about KES 350,000 (for example KES 450,000 against Whitepath in 2024).
- Collective actions
- No class action mechanism in the Act was confirmed; representative constitutional petitions under the Constitution are possible in principle but no data protection outcome was confirmed.
Cases worth knowing
- Oppo Kenya, KES 5 million (first penalty notice) 2022
Oppo used a complainant's photo on its Instagram account without consent. After it failed to comply with an enforcement notice of 3 November 2022, the ODPC issued its first penalty notice on 21 December 2022 for KES 5 million, the statutory maximum, under ss.62 and 63. Source - Roma School, Mulla Pride and Casa Vera Lounge, KES 9.375 million in total 2023
In September 2023 the ODPC fined Roma School KES 4.55 million for posting pupils' pictures without parental consent, digital lender Mulla Pride (KeCredit and FairKash apps) KES 2.975 million for using contacts to send threatening messages, and Casa Vera Lounge KES 1.85 million for posting a customer's image without consent. Mulla Pride challenged its penalty by constitutional petition; in 2025 the High Court (Justice Chacha Mwita) dismissed it because the lender should have used the statutory appeal under s.64. Source - Whitepath Company and Regus Kenya penalty notices; Whitepath compensation order 2023-2024
In April 2023 the ODPC issued penalty notices to digital lender Whitepath (about 150 complaints of accessing borrowers' phone contacts and sending unsolicited messages) and Regus Kenya (repeated spam), reported at about USD 37,000 each. In a separate 2024 determination (ODPC/COMP/1764/2024) the ODPC ordered Whitepath to pay a complainant KES 450,000 compensation under s.65. Source
Worth knowing
- The regulator itself orders the company to pay compensation to the individual complainant, something EU DPAs cannot do; this is the most common outcome of ODPC determinations.
- The fine cap is the lower of KES 5 million and 1% of turnover, so large companies face a small fixed ceiling while small companies may face less.
- The ODPC must conclude complaints within 90 days by statute (s.56(5)).
- Ignoring an enforcement notice is a criminal offence with up to 2 years' imprisonment, separate from the administrative penalty (s.58(3)).
- Courts insist on the statutory appeal to the High Court under s.64; constitutional petitions that bypass it have been dismissed.
Sources (17) research confidence: medium
- Data Protection Act 2019, Kenya Law consolidated text
- dataprotection.co.ke: s.56 Complaints secondary
- dataprotection.co.ke: s.58 Enforcement notices secondary
- dataprotection.co.ke: s.62 Penalty notices secondary
- dataprotection.co.ke: s.63 Administrative fines secondary
- dataprotection.co.ke: s.64 Right of appeal secondary
- dataprotection.co.ke: s.65 Compensation secondary
- dataprotection.co.ke: s.73 General penalty secondary
- ODPC/COMP/1764/2024 Whitepath Company Limited secondary
- ODPC: penalty notice against Oppo Kenya
- Kenya News Agency: ODPC issues penalty notices totalling Sh 9,375,000
- CIO Africa: ODPC fines two firms (Whitepath, Regus) secondary
- CIPIT case law library: penalty notices secondary
- Kenyan Wall Street: Court dismisses digital lender's suit over KSh 2.98mn fine secondary
- Mutie Advocates: High Court deference to ODPC damages awards (Muthoni v Solpia) secondary
- Bowmans: ODPC decisions in the determination of complaints secondary
- ALN: Kenya's evolving data protection framework secondary
South AfricaIR / InfoRegAfrica
In plain words
You complain to the Information Regulator, which can mediate, investigate and then order the organisation to fix things through an enforcement notice. Only if the organisation ignores that order does a fine of up to ZAR 10 million usually follow, and the organisation can either pay or insist on a criminal trial. Either side can take the Regulator's decision to the High Court, and you can also sue the organisation for damages without having to prove it was at fault.
Route of a fine
- Information Regulator notice
- High Court
- Supreme Court of Appeal
The authority
- Name
- Information Regulator (South Africa) (Information Regulator, IR / InfoReg) Website
- How it is organised
- Independent statutory body established under POPIA, accountable to the National Assembly, with jurisdiction over both public and private sectors. It enforces POPIA and also the Promotion of Access to Information Act (PAIA). Investigated matters can be referred to its internal Enforcement Committee (s.92), which makes findings and recommendations before the Regulator decides.
- Regional authorities
- No regional regulators. Criminal offences under POPIA are prosecuted through the South African Police Service and the ordinary criminal courts; Magistrates' Courts have jurisdiction to impose any POPIA penalty (s.108).
- National law
- Protection of Personal Information Act 4 of 2013 (POPIA). Assented to 19 November 2013; main provisions commenced 1 July 2020 with a one-year grace period, so full compliance has been enforceable since 1 July 2021. Text
Complaining
- How
- Any person may complain to the Regulator 'in the prescribed manner and form' (s.74), using the form prescribed in the POPIA Regulations, lodged with the Regulator by email or its online channels. No fee was confirmed. Complaints may also be lodged against the determination of an adjudicator under an industry code of conduct (s.74(2)).
- Contact the organisation first?
- POPIA does not require the complainant to approach the responsible party first. However, the Regulator may decide to take no action where the complainant has not exhausted a complaints procedure under an applicable code of conduct when it was reasonable to do so (s.77).
- Deadlines
- No fixed time limit for filing, but the Regulator may decline a complaint where so much time has passed that an investigation is 'no longer practicable or desirable' (s.77). No statutory deadline for the Regulator to decide was confirmed; it must inform both parties of its chosen course of action 'as soon as is reasonably practicable' (s.76).
- The complainant's position
- The complainant is informed of the outcome and may appeal to the High Court within 180 days of receiving the result of the investigation (s.97(2)). The Regulator must give reasons if it decides to take no action (s.77).
Procedure
- Complaint (s.74) or own-initiative investigation (s.76(2)); the Regulator may conduct a pre-investigation (s.79), act as conciliator, decide to take no action (s.77), or open a full investigation.
- Optional referral to the Enforcement Committee (s.92), which makes findings and recommends action to the Regulator (s.93).
- Enforcement notice (s.95) requiring specified steps or a stop to processing within a set period (31 days in published cases); compliance is suspended during the 30-day appeal window and any appeal, unless the notice is marked urgent, in which case compliance can be required after no less than 3 days.
- Failure to comply with an enforcement notice is an offence; the Regulator may then serve an infringement notice with an administrative fine of up to ZAR 10 million (s.109).
- Within 30 days the infringer pays, agrees instalments, or elects to be tried in court, in which case the matter goes to the South African Police Service for criminal prosecution (s.109).
- Who decides
- The Information Regulator (its members), acting on recommendations of the Enforcement Committee where a matter was referred.
- Limitation
- No POPIA-specific limitation period confirmed; the Regulator has a discretion to decline stale complaints (s.77).
Fines
- Who imposes them
- The Regulator imposes the administrative fine itself by infringement notice (s.109), so 'regulator'. In practice fines have followed non-compliance with an enforcement notice rather than the original breach. The infringer can refuse and elect to be tried in court, which turns the matter into a criminal prosecution; an unpaid fine becomes recoverable through the courts.
- Public bodies
- Yes. The first fines were imposed on national government departments (Justice and Constitutional Development, Basic Education), and fines have also been reported against the Electoral Commission and a local municipality.
- National specifics
- Fixed cap of ZAR 10 million per infringement notice, not turnover based (s.109). Separate criminal offences carry a fine or imprisonment of up to 10 years (for example obstructing the Regulator, failing to comply with an enforcement notice or misusing account numbers) or up to 12 months for lesser offences such as breach of confidentiality (s.107). Other sanctions are enforcement notices ordering specific steps, including a stop to processing (s.95).
Appeals
- First court
- The High Court having jurisdiction (s.97). On appeal the court may review findings of fact and may set aside or substitute the notice or decision if it was not in accordance with the law or the Regulator's discretion ought to have been exercised differently (s.98). Departments have also used review applications to challenge both notices.
- Deadline
- 30 days from receipt of an information or enforcement notice for the responsible party (s.97(1)); 180 days from receiving the result for a complainant (s.97(2)).
- Does it hold payment?
- Yes for enforcement notices: a notice need not be complied with until the appeal period ends and, if an appeal is brought, until it is determined or withdrawn, unless the Regulator declared the notice urgent (s.95(3)-(4)). For the fine itself, electing trial in court within 30 days stops it becoming recoverable (s.109).
- Further appeal
- Ordinary appeal route from the High Court, with leave, to a full bench or the Supreme Court of Appeal, and then the Constitutional Court on constitutional matters.
- If the authority does nothing
- A complainant informed of the result of an investigation, or of a decision to take no action, may appeal to the High Court within 180 days (s.97(2)). Judicial review of administrative action is also available in principle.
Suing the organisation directly
- Courts
- Yes. A data subject, or the Regulator at the data subject's request, may sue the responsible party for damages in the civil courts (s.99), so 'yes' for private action.
- Compensation
- Strict liability: damages are recoverable whether or not there was intent or negligence, subject to limited defences such as vis major, the plaintiff's consent or fault, compliance not being reasonably practicable, or a Regulator exemption (s.99). The court may award a just and equitable amount covering patrimonial and non-patrimonial loss, aggravated damages, interest and costs.
- Collective actions
- POPIA has no class action provision of its own. Where the Regulator sues for a data subject, awards go into a trust account and are paid to the data subject after costs (s.99). No POPIA-based class action outcome was confirmed.
Cases worth knowing
- Department of Justice and Constitutional Development, ZAR 5 million fine 2023
After a 2021 ransomware attack, the Regulator found that the department had let its anti-virus, SIEM and intrusion detection licences lapse. It issued an enforcement notice on 9 May 2023 and, when the department did not comply within 31 days, the first POPIA infringement notice and a ZAR 5 million fine on 3 July 2023. The department launched a High Court review application in September 2023 to set aside both notices; no final judgment was confirmed. Source - Department of Basic Education, matric results, ZAR 5 million fine set aside 2024-2026
The Regulator ordered the department in November 2024 to stop publishing matric results in newspapers without learner consent and, on non-compliance, issued an infringement notice with a ZAR 5 million fine on 23 December 2024. A full bench of the Gauteng High Court, Pretoria, set aside both the enforcement and infringement notices on 12 December 2025, holding that examination numbers published without names are not personal information, and ordered the Regulator to pay costs. Leave to appeal was refused on 3 June 2026. Source - Smaller fines: Lancet Laboratories, Electoral Commission, Blouberg Local Municipality 2024-2026
Reported fines include ZAR 100,000 against Lancet Laboratories for failing to report security compromises (paid), ZAR 100,000 against the Electoral Commission, and ZAR 500,000 against Blouberg Local Municipality, reportedly reduced to ZAR 250,000 on court confirmation. Several other enforcement notices (Dis-Chem, TransUnion, SAPS) were closed after compliance with no fine. These come from a secondary tracker and were not checked against Regulator statements. Source
Worth knowing
- Fines are in practice a second step: the Regulator first issues an enforcement notice and fines only for non-compliance with it, so the original breach alone has rarely led straight to a fine.
- The fined party can refuse to pay and 'elect to be tried in court', which converts the matter into a criminal prosecution handled by the police and prosecutors (s.109).
- An appeal against an enforcement notice automatically suspends it unless the Regulator marked it urgent (s.95(3)-(4)).
- Civil damages are strict liability and the Regulator itself can sue on a data subject's behalf (s.99).
- The Regulator's first big fine to be tested in court was set aside: the High Court held that exam numbers without names were not personal information.
Sources (18) research confidence: medium
- POPIA s.109 Administrative fines (consolidated text) secondary
- POPIA s.97 Right of appeal secondary
- POPIA s.98 Consideration of appeal secondary
- POPIA s.99 Civil remedies secondary
- POPIA s.95 Enforcement notice secondary
- POPIA s.107 Penalties secondary
- POPIA s.108 Magistrate's Court jurisdiction secondary
- POPIA s.74 Complaints secondary
- POPIA s.76 Action on receipt of complaint secondary
- POPIA s.77 Regulator may decide to take no action secondary
- POPIA s.92 Matters referred to Enforcement Committee secondary
- Information Regulator media statement: infringement notice to DBE (Dec 2024)
- Information Regulator media statement: infringement notice to DoJ&CD (Jul 2023), reproduced by Polity
- ITWeb: Justice dept takes on InfoReg over R5m POPIA fine secondary
- IOL: High Court sets aside R5 million fine against DBE secondary
- Werksmans: Leave to appeal refused in matric results privacy dispute secondary
- MJK Inc POPIA enforcement tracker secondary
- Wikipedia: Protection of Personal Information Act, 2013 (commencement dates) secondary
IndiaDPBIAsia-Pacific
In plain words
From May 2027, if a company mishandles your data you must first complain to the company; if that fails, you can complain online to the Data Protection Board, which can investigate, broker a settlement or fine the company up to INR 250 crore, with appeals going to the telecoms tribunal. You will not get compensation from the Board and cannot sue in a civil court under this law. Until May 2027 the Board exists but the rules it would enforce are not yet in force.
Route of a fine
- Data Protection Board (from May 2027)
- TDSAT
- Supreme Court
The authority
- Name
- Data Protection Board of India (भारतीय डेटा संरक्षण बोर्ड, DPBI)
- How it is organised
- Statutory board established by the central government (DPDP Act section 18) on 13 November 2025, with four members under the DPDP Rules, seated in the National Capital Region and designed as a digital office; section 28 says it functions as an independent body, but members are appointed by the central government. It adjudicates complaints and penalties rather than issuing guidance; rule-making stays with the Ministry of Electronics and Information Technology (MeitY).
- Regional authorities
- No state authorities. Until 13 May 2027, section 43A of the IT Act 2000 and the 2011 SPDI Rules remain the operative privacy regime, with compensation claims before IT Act adjudicating officers; CERT-In enforces cyber incident reporting, and sector regulators (for example the Reserve Bank of India) impose data rules on their sectors.
- National law
- Digital Personal Data Protection Act 2023 (DPDP Act) and DPDP Rules 2025 (notified 13 November 2025, G.S.R. 846(E)). Phased commencement: from 13 November 2025 sections 1(2), 2, 18 to 26, 35, 38 to 43 and 44(1) and (3) (definitions, Board set-up, RTI and TRAI Act amendments) and Rules 1, 2 and 17 to 21; from 13 November 2026 section 6(9) and 27(1)(d) (consent manager registration and the Board's powers over consent managers) and Rule 4; from 13 May 2027 the substantive duties and enforcement (sections 3 to 17, the rest of 27, 28 to 34, 36, 37, 44(2)) and Rules 3, 5 to 16, 22 and 23. A January 2026 MeitY consultation on compressing the timeline to 12 months was reported, but no change has been notified. Text
Complaining
- How
- From 13 May 2027, a data principal complains to the Board online through a portal and mobile app (the Board is a digital office); any fee was not confirmed. A data principal who files a false or frivolous complaint breaches their own duties (section 15) and risks a penalty of up to INR 10,000.
- Contact the organisation first?
- Yes: under section 13(3) the data principal must first exhaust the grievance redress mechanism of the data fiduciary or consent manager; the Rules give fiduciaries up to 90 days to respond to grievances (secondary source).
- Deadlines
- No statutory deadline for the Board to decide a complaint was confirmed. As of 2 October 2026 the Board exists but the substantive duties and its complaint and inquiry powers (section 27 except 27(1)(d), and section 28) are not yet in force; some commentators say complaints can already be filed, which is hard to reconcile with the commencement notification.
- The complainant's position
- The complainant is a party to a Board proceeding conducted under principles of natural justice (section 28), but penalties go to the Consolidated Fund of India, not to the complainant.
Procedure
- Complaint by a data principal, breach intimation by a data fiduciary, reference from the central or a state government, or a court direction (section 27).
- Board determines whether there are sufficient grounds to inquire; it may close the matter or proceed (section 28), with the powers of a civil court to summon and examine.
- During or instead of inquiry: direction to attempt mediation (section 31) or acceptance of a voluntary undertaking, which ordinarily bars further proceedings on its contents (section 32); urgent remedial directions are possible.
- After a hearing, a penalty order (section 33) taking account of factors such as nature, gravity, duration and mitigation. Repeat penalised fiduciaries can be referred to the central government for blocking (section 37).
- Who decides
- The Data Protection Board of India (chairperson and members).
- Limitation
- Not confirmed.
Fines
- Who imposes them
- Once section 33 commences on 13 May 2027, the Board imposes monetary penalties itself by order, per the Schedule: up to INR 250 crore for failing to take reasonable security safeguards, INR 200 crore for failing to notify a breach and for children's data violations, INR 150 crore for significant data fiduciary obligations, INR 50 crore for other breaches, and INR 10,000 for data principals. Until then no body can penalise under the DPDP Act (map: none-yet), apart from Board powers over consent managers from 13 November 2026.
- Public bodies
- Not confirmed whether penalties apply to government bodies in practice: the State acting as a data fiduciary is within the Act, but the central government can exempt its instrumentalities wholly or partly by notification (section 17(2)).
- National specifics
- The maximums are fixed amounts per breach category, not turnover-based. The DPDP Act creates no criminal offences; penalties are civil.
Appeals
- First court
- The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) as Appellate Tribunal (section 29).
- Deadline
- 60 days from receipt of the Board's order, with power to condone delay for sufficient cause; the Tribunal is to endeavour to dispose of appeals within six months.
- Does it hold payment?
- Not confirmed.
- Further appeal
- Further appeal to the Supreme Court (via the TRAI Act framework; not confirmed against the text).
- If the authority does nothing
- No route under the Act; a person could seek a writ in a High Court under Article 226 of the Constitution against the Board as a public authority.
Suing the organisation directly
- Courts
- Section 39 bars civil courts from any matter the Board is empowered to determine, so there is no private damages action under the DPDP Act once it is in force. Until 13 May 2027, section 43A of the IT Act allows compensation claims against a body corporate negligent in protecting sensitive personal data (before adjudicating officers or civil courts depending on value); section 44(2) omits 43A from that date.
- Compensation
- None under the DPDP Act: penalties go to the government and the Board cannot award compensation to data principals.
- Collective actions
- No class action mechanism under the Act. Public interest litigation in the High Courts and Supreme Court on the constitutional right to privacy remains available against the State.
Cases worth knowing
- No Board decisions yet 2025-2026
The Board was constituted on 13 November 2025 but its inquiry and penalty powers start on 13 May 2027, so no DPDP penalty has been imposed as of 2 October 2026. Source - Phased commencement notification 2025
Commencement notification (G.S.R. 843(E)) and DPDP Rules (G.S.R. 846(E)) of 13 November 2025 set the 12- and 18-month phases, and on 13 May 2027 section 43A of the IT Act will be omitted, ending the only existing statutory compensation route for data protection failures. Source
Worth knowing
- On 2 October 2026 India has a data protection board but almost no law for it to enforce: substantive duties and penalties start on 13 May 2027.
- Individuals cannot obtain compensation under the DPDP Act, civil courts are barred, and the existing compensation route under IT Act section 43A disappears when the Act fully commences.
- Data principals have duties too, and can be fined up to INR 10,000 for false or frivolous complaints.
- Appeals go to the telecoms tribunal (TDSAT), not to a general court, and penalties are fixed caps per breach type rather than a percentage of turnover.
Sources (7) research confidence: medium
- Digital Personal Data Protection Act 2023 (MeitY)
- PIB: DPDP Rules 2025 notified (Board, penalties, TDSAT, online complaints)
- Mondaq: DPDP Act and Rules phased commencement (section-level dates) secondary
- Shardul Amarchand Mangaldas: enforcement of the DPDP Act and notification of the Rules secondary
- ProtectComply: DPDP Rules timeline (rule numbers, G.S.R. numbers, January 2026 consultation) secondary
- DLA Piper Data Protection Laws of the World: India (IT Act regime until May 2027) secondary
- TCSA: DPDP Rules implementation roadmap (90-day grievance period) secondary
ChinaCACAsia-Pacific
In plain words
You report a company to the cyberspace administration or the industry ministry, usually online, and you are told the result but play no further part. The authority investigates, may summon the company's bosses for a talk, order fixes, pull its app from stores or fine it, and in serious cases fine managers personally. You can also sue the company yourself, and prosecutors can sue on behalf of the public.
Route of a fine
- CAC or other department
- Reconsideration or people's court
- Higher people's court
The authority
- Name
- Cyberspace Administration of China (国家互联网信息办公室, CAC) Website
- How it is organised
- Government office under the State Council (it shares its leadership with the Communist Party's Central Cyberspace Affairs Commission office); it is not an independent authority. Under PIPL Article 60 the CAC coordinates personal information protection, while relevant State Council departments supervise within their own sectors.
- Regional authorities
- Provincial and municipal cyberspace administrations enforce locally. In practice the Ministry of Industry and Information Technology (MIIT, mobile app rectification campaigns), the State Administration for Market Regulation (SAMR, consumer protection), the Ministry of Public Security and local police (criminal cases), and sector regulators also enforce; procuratorates bring public interest litigation (PIPL Article 70).
- National law
- Personal Information Protection Law of the PRC (PIPL), adopted 20 August 2021, in force 1 November 2021 (Article 74). It sits alongside the Cybersecurity Law 2017 (first amendment in force 1 January 2026), the Data Security Law 2021, the Network Data Security Management Regulations (in force 1 January 2025) and the Personal Information Protection Compliance Audit Measures (in force 1 May 2025). Text
Complaining
- How
- Anyone may complain about or report unlawful processing to the departments with personal information protection duties (PIPL Article 65), in Chinese; in practice through the CAC's online illegal and harmful information reporting centre (12377) or MIIT complaint channels. No fee is charged as far as confirmed.
- Contact the organisation first?
- Not required for a complaint or report to an authority. For a court action under Article 50, the individual first makes a rights request to the handler and may sue if it is rejected.
- Deadlines
- PIPL Article 65 only says the department shall handle complaints promptly and according to law and tell the complainant the outcome; no fixed statutory deadline for the regulator or for the complainant was confirmed.
- The complainant's position
- A complainant is a reporter, not a party: they are told the outcome (Article 65) but have no formal role in the penalty proceedings.
Procedure
- Complaint, report, security review or sector-wide inspection campaign (for example MIIT app rectification campaigns).
- Investigation with powers to question parties, inspect records and premises, and seal or seize equipment (PIPL Article 63).
- Regulatory interview (yuetan) with the handler's legal representative or principal person in charge, and orders to rectify or to commission a compliance audit (Article 64).
- Administrative penalty procedure under the Administrative Penalty Law: notice of proposed penalty, right to make representations and, for large fines, to request a hearing; then a written penalty decision. Violations are entered in credit records and published (Article 67).
- Who decides
- The competent department (CAC or sector regulator) decides. Penalties in the serious tier of Article 66(2) may only be imposed by a department at provincial level or above.
- Limitation
- Under the Administrative Penalty Law (Article 36) the general limitation period is two years, extended to five years where the violation involves citizens' life, health or financial security and has harmful consequences.
Fines
- Who imposes them
- The CAC and other competent departments impose fines themselves by administrative decision (map: regulator). Ordinary tier (Article 66(1)): rectification order, warning, confiscation of illegal gains, suspension of apps, and a fine up to CNY 1 million if the handler refuses to rectify, plus CNY 10,000 to 100,000 on directly responsible individuals. Serious tier (Article 66(2)): fine up to CNY 50 million or 5% of the previous year's turnover, suspension of business, revocation of licences, and CNY 100,000 to 1 million on responsible individuals, who can also be barred from serving as director, supervisor, senior manager or personal information protection officer.
- Public bodies
- No fines on state organs: under PIPL Article 68 the superior authority orders rectification and the directly responsible officials are disciplined.
- National specifics
- Criminal liability runs in parallel: Criminal Law Article 253-1 (infringing citizens' personal information) carries up to three years' imprisonment, or three to seven years in particularly serious cases. Large cases are often decided under several laws at once (PIPL, Cybersecurity Law, Data Security Law), as in the Didi decision.
Appeals
- First court
- A penalty decision can be challenged by administrative reconsideration (to the reviewing authority under the Administrative Reconsideration Law) or by administrative litigation in the people's courts under the Administrative Litigation Law.
- Deadline
- Generally 60 days to apply for reconsideration and six months to sue in court from the time the party knew of the decision (general administrative law rules; not confirmed for every CAC decision).
- Does it hold payment?
- Generally not suspensive: the decision remains enforceable during reconsideration or litigation unless the authority or court orders a stay.
- Further appeal
- Two-instance court system: first instance in an intermediate or basic people's court, appeal to the higher court. Contested administrative appeals against CAC penalties are rarely reported.
- If the authority does nothing
- Not confirmed. A complainant has no specific PIPL route to challenge a regulator's refusal to act; general administrative litigation for failure to perform a statutory duty may be possible in principle.
Suing the organisation directly
- Courts
- Individuals can sue handlers in the people's courts for infringement of personal information rights (PIPL Article 69, Civil Code Articles 1032 to 1039) and, under Article 50, for refusal of rights requests.
- Compensation
- Fault is presumed: a handler that cannot prove it was not at fault must compensate, measured by the individual's loss or the handler's gain, or as the court determines (Article 69). No statutory minimum damages; awards reported so far are small.
- Collective actions
- Article 70 lets the people's procuratorates, consumer organisations designated by law and organisations designated by the CAC bring public interest litigation where many individuals' rights are infringed. Procuratorates are the most active claimants; there is no opt-out damages class action.
Cases worth knowing
- Didi Global 2022
On 21 July 2022 the CAC fined Didi CNY 8.026 billion after a cybersecurity review, applying the Cybersecurity Law, Data Security Law, PIPL and Administrative Penalty Law together; chairman and CEO Cheng Wei and president Liu Qing were each fined CNY 1 million personally. No court challenge was reported. Source - Guo Bing v Hangzhou Safari Park (facial recognition) 2019-2021
A park visitor sued over a switch to compulsory facial recognition for annual pass holders; the Hangzhou courts ordered deletion of his facial (and fingerprint) data and awarded modest compensation. It is the leading civil case on biometric data, decided under contract and personal information rules just before the PIPL took effect. Source
Worth knowing
- The regulator is a government and Party body, not an independent authority, and enforcement is often campaign-based (mass app inspections, public naming lists) rather than complaint-driven.
- Managers face personal fines and director bans under the PIPL itself, and serious misuse of personal data is a crime prosecuted by public security and procuratorates.
- Procuratorates act as public interest claimants in civil courts, a role with no real GDPR equivalent.
- There is no one-stop-shop: several ministries can sanction the same conduct, and decisions often cite several statutes at once.
Sources (6) research confidence: medium
- PIPL translation (DigiChina, Stanford) secondary
- CAC announcement of the Didi penalty, 21 July 2022
- BCLP: Penalties and liabilities under China's data protection laws secondary
- Bloomberg Law: China PIPL FAQs (enforcing authorities and penalty tiers) secondary
- DLA Piper Data Protection Laws of the World: China (law and enforcement) secondary
- PIPL Article 66 (XL Law and Consulting) secondary
South KoreaPIPCAsia-Pacific
In plain words
You report a privacy problem to the national privacy hotline or website, and the privacy commission may investigate and fine the company a share of its revenue, which the company can contest in the Seoul Administrative Court. Separately, you can ask the commission's mediation committee for compensation, alone or together with other victims, or sue the company yourself, where the law sets minimum damages of up to KRW 3 million without proof of loss.
Route of a fine
- PIPC surcharge
- Seoul Administrative Court
- Seoul High Court
- Supreme Court
The authority
- Name
- Personal Information Protection Commission (개인정보보호위원회, PIPC) Website
- How it is organised
- Central administrative agency under the Prime Minister with a chair, vice-chair and commissioners deciding as a collegial commission; since August 2020 it is the single privacy regulator for both public and private sectors.
- Regional authorities
- No regional authorities. The Korea Internet and Security Agency (KISA) runs the Personal Information Infringement Report Center (phone 118) and supports investigations; the PIPC's Personal Information Dispute Mediation Committee handles individual and collective mediation; the Korea Consumer Agency's Consumer Dispute Settlement Commission also mediates mass claims; police and prosecutors handle criminal offences.
- National law
- Personal Information Protection Act (PIPA, 2011), with major amendments in force 15 September 2023 (turnover-based surcharge, single regime for online and offline) and an amendment dated 10 March 2026 whose main provisions took effect on 11 September 2026 (surcharge up to 10% in aggravated cases). Sector laws such as the Credit Information Act and Location Information Act also apply. Text
Complaining
- How
- Individuals report infringements online to the Personal Information Infringement Report Center run by KISA (privacy.kisa.or.kr) or by calling 118, free of charge and in Korean (PIPA Article 62). For compensation they can instead apply to the Personal Information Dispute Mediation Committee.
- Contact the organisation first?
- Not required for a report to the PIPC or KISA.
- Deadlines
- No statutory deadline for handling infringement reports was confirmed. The Dispute Mediation Committee must prepare a draft mediation within a fixed period (60 days under Article 44, extendable; not confirmed against the current text).
- The complainant's position
- The reporter is not a party to PIPC enforcement proceedings; in mediation the applicant is a party and decides whether to accept.
Procedure
- Report to KISA, breach notification, media reports or the PIPC's own initiative.
- Fact-finding and investigation with requests for materials and on-site inspections (Article 63).
- Plenary commission deliberation and decision: corrective recommendation or corrective order (Article 64), penalty surcharge (Article 64-2), administrative fine (Article 75), publication of the violation and the measures (Article 66).
- Referral of criminal offences to investigative authorities and recommendation of disciplinary action against responsible officers (Article 65).
- Who decides
- The PIPC plenary meeting decides surcharges and orders.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- The PIPC imposes penalty surcharges itself by administrative decision (map: regulator). Since 15 September 2023 the cap is 3% of total turnover, excluding revenue unrelated to the violation (Article 64-2), with a fixed cap (understood to be KRW 2 billion) where turnover is absent or hard to calculate. Since 11 September 2026 the cap rises to 10% of total turnover for repeated wilful or grossly negligent violations within three years, violations affecting 10 million or more data subjects, or failure to comply with a corrective order.
- Public bodies
- Public institutions are subject to corrective orders, publication and administrative fines; whether surcharges can be imposed on central government bodies was not confirmed.
- National specifics
- Administrative fines (gwataeryo, Article 75) are separate from surcharges and capped in the tens of millions of won (for example up to KRW 30 million for breach of a corrective order). Criminal offences carry up to five years' imprisonment or KRW 50 million for unlawful provision of personal information to third parties.
Appeals
- First court
- An administrative appeal under the Administrative Appeals Act, or an administrative lawsuit in the Seoul Administrative Court under the Administrative Litigation Act.
- Deadline
- 90 days from receipt of the written decision.
- Does it hold payment?
- Not suspensive by default; the company must apply to the court for a stay of execution.
- Further appeal
- Seoul High Court on appeal, then the Supreme Court.
- If the authority does nothing
- Not confirmed. In practice individuals who are dissatisfied turn to dispute mediation or civil suits rather than challenging the PIPC.
Suing the organisation directly
- Courts
- Civil courts. Article 39 reverses the burden of proof: the controller must show it was not intentional or negligent.
- Compensation
- Actual damages, punitive damages of up to five times the loss for intentional or negligent leaks (Article 39(3)), or statutory damages of up to KRW 3 million per person without proof of loss (Article 39-2).
- Collective actions
- Collective dispute mediation through the Dispute Mediation Committee (Article 49), whose accepted outcome has the effect of a court settlement; a group action (Article 51) can be brought by qualifying consumer or non-profit organisations, but only for an injunction and only after collective mediation fails. There is no damages class action, so victims bring mass joint lawsuits.
Cases worth knowing
- Google and Meta (behavioural advertising) 2022, upheld 2025
On 14 September 2022 the PIPC fined Google KRW 69.2 billion and Meta KRW 30.8 billion for collecting behavioural data for personalised advertising without valid consent, and ordered them to fix their consent flows. The Seoul Administrative Court dismissed both companies' challenges on 23 January 2025. Source - SK Telecom (USIM data breach) 2025
On 28 August 2025 the PIPC imposed a record KRW 134.8 billion surcharge plus a KRW 9.6 million administrative fine after a cyberattack exposed data of about 23 million people, including unencrypted SIM authentication keys. In parallel, the PIPC mediation committee proposed KRW 300,000 each to about 4,000 claimants (rejected by SK Telecom) and the Korea Consumer Agency's commission proposed KRW 100,000 per user in December 2025. Source - Coupang (data breach) 2026
On 11 June 2026 the PIPC imposed a record KRW 624.7 billion on Coupang: KRW 423.6 billion for an insider breach by a former engineer affecting about 37.5 million users, KRW 201.2 billion for collecting 11.17 million users' activity on other apps and websites without authorisation, and KRW 248 million on a subsidiary. Coupang said it would contest the decision through legal procedures. Earlier comparators include Kakao (KRW 15.1 billion, 2024). Source
Worth knowing
- Statutory damages of up to KRW 3 million per person and punitive damages of up to five times the loss exist, which is unusual in privacy law.
- Mass mediation is a real alternative to litigation: mediation proposals in large breaches are priced per person and, if the company accepts, have the effect of a court settlement.
- The surcharge base is total company turnover (minus unrelated revenue), not just the turnover of the service concerned, and from 11 September 2026 it can reach 10% in aggravated cases.
- Breach of the law can lead to criminal prosecution of employees and officers, and the PIPC can recommend disciplinary action against responsible executives.
Sources (9) research confidence: medium
- PIPA English text (Korea Legislation Research Institute)
- PIPC English website
- DLA Piper Data Protection Laws of the World: South Korea enforcement and 2026 amendment secondary
- TechCrunch: Google and Meta fined in South Korea, 14 September 2022 secondary
- Digital Policy Alert: Seoul Administrative Court upholds PIPC fines against Google and Meta secondary
- Korea Herald: SK Telecom hit with record privacy fine secondary
- Korea Times: SK Telecom fined, comparison with Kakao and Google, 90-day appeal window secondary
- Korea Herald: Korea Consumer Agency mediation decision on SK Telecom secondary
- CPO Magazine: Coupang record fine secondary
JapanPPCAsia-Pacific
In plain words
If a company misuses your data, you can call the regulator's consultation line, but it will not decide your case; it may quietly guide the company, publicly recommend changes, or as a last resort order it to stop. Only if the company ignores an order can prosecutors take it to a criminal court for a fine. For compensation you sue the company yourself in the ordinary courts.
Route of a fine
- PPC guidance, recommendation, order
- Breach of an order: prosecution
- Criminal court
The authority
- Name
- Personal Information Protection Commission (個人情報保護委員会, PPC) Website
- How it is organised
- Independent administrative commission (chair and commissioners) attached to the Cabinet Office; since 2022 to 2023 it supervises both the private sector and public bodies under a single APPI.
- Regional authorities
- No regional DPAs for the private sector. Other bodies matter in practice: the Ministry of Internal Affairs and Communications issues administrative guidance under the Telecommunications Business Act (as with LY Corporation in 2024), the Japan Fair Trade Commission handles platform conduct, accredited personal information protection organisations handle complaints for member businesses, and police and public prosecutors handle APPI offences.
- National law
- Act on the Protection of Personal Information (APPI, Act No. 57 of 2003), fully in force April 2005, with major amendments in force 2017, April 2022 (2020 amendment) and 2022 to 2023 (public sector integration). A further amendment introducing an administrative surcharge was passed by the Diet on 10 July 2026 and promulgated on 17 July 2026; it enters into force within two years of promulgation and was not yet in force on 2 October 2026. Text
Complaining
- How
- There is no formal complaint-and-decision procedure. Individuals can call the PPC's APPI consultation line, in Japanese, free of charge, and the PPC uses the information to decide whether to act; complaints can also go to an accredited personal information protection organisation if the business is a member.
- Contact the organisation first?
- Not a legal precondition for contacting the PPC, but the system expects it: businesses must endeavour to handle complaints properly and promptly (APPI complaint-handling duty), and a court claim for disclosure, correction or cessation of use requires a prior request to the business.
- Deadlines
- No statutory deadline for the PPC to deal with a consultation or complaint was confirmed.
- The complainant's position
- The individual is an information source, not a party; the PPC does not issue a decision on the individual's complaint.
Procedure
- Information gathering from consultations, breach reports (mandatory since April 2022) or the PPC's own monitoring.
- Request for reports and on-site inspection (APPI Article 146).
- Guidance and advice (Article 147), the most common outcome, sometimes published.
- Recommendation (Article 148(1)) to stop the violation or take corrective measures, usually with periodic progress reports.
- Order (Article 148(2)) if a recommendation is not followed without justifiable grounds and serious infringement is imminent, or an emergency order (Article 148(3)); orders can be published. Breach of an order is a criminal offence referred for prosecution.
- Who decides
- The PPC as a collegial commission; criminal penalties are decided by the criminal courts after prosecution by public prosecutors.
- Limitation
- Not confirmed: no specific APPI limitation period for PPC action was found; criminal offences follow the general rules of the Code of Criminal Procedure.
Fines
- Who imposes them
- Today the PPC cannot impose monetary penalties. Money penalties come only through criminal prosecution: breach of a PPC order carries up to one year's imprisonment or a fine up to JPY 1 million for individuals (Article 178) and a fine up to JPY 100 million for the company (Article 184); false reporting carries a fine up to JPY 500,000 (map: court). The 2026 amendment adds an administrative surcharge imposed by the PPC itself (new Articles 148-3 to 148-17), equal to the financial benefit from certain designated serious violations, with exemptions for small-scale cases (reported as fewer than 1,000 individuals affected), reasonable care or insignificant harm; it will start within two years of 17 July 2026.
- Public bodies
- Administrative organs and local governments are covered by the APPI since the 2021 reform took effect, but the PPC's tools against them are requests for reports and recommendations rather than penalties (article numbers not confirmed).
- National specifics
- Unlawfully providing a personal information database for illicit gain is itself an offence (up to one year or JPY 500,000 for individuals, up to JPY 100 million for companies). The 2026 amendment also raises criminal maxima and adds offences such as obtaining personal information by fraud or violence (Articles 178 to 180 as amended; amounts not confirmed).
Appeals
- First court
- A PPC order is an administrative disposition: it can be challenged by a request for review under the Administrative Complaint Review Act or by a revocation suit in the district court under the Administrative Case Litigation Act. Whether guidance and recommendations are challengeable dispositions is doubtful (not confirmed).
- Deadline
- Generally three months for a request for review and six months for a revocation suit from knowledge of the disposition (general administrative law rules).
- Does it hold payment?
- Not suspensive by default; a stay of execution must be requested separately.
- Further appeal
- High court appeal and final appeal to the Supreme Court. No reported court challenge to a PPC order was found.
- If the authority does nothing
- No specific remedy: since there is no complaint decision, an individual cannot appeal PPC inaction and must instead sue the business directly.
Suing the organisation directly
- Courts
- District courts (summary courts for small claims). Individuals sue in tort under Civil Code Article 709 for privacy infringement, and can sue to enforce APPI rights to disclosure, correction and cessation of use after first making the request to the business.
- Compensation
- Ordinary compensatory and consolation damages only; no statutory or punitive damages. Awards in data leak cases are typically small per person (for example the Benesse leak litigation; amounts not confirmed here).
- Collective actions
- No general privacy class action. Japan's consumer collective redress scheme is narrow; giving qualified consumer organisations injunction and damages claims for APPI breaches was discussed in the triennial review, but its adoption was not confirmed in the 2026 amendment.
Cases worth knowing
- Rikunabi (Recruit Career and Recruit) 2019
On 4 December 2019 the PPC issued recommendations to Recruit Career and Recruit, and guidance to client companies, over a service that predicted the likelihood of job seekers declining offers from browsing data and supplied it to employers without valid consent, affecting 26,060 people. No fine was possible. Source - LY Corporation (LINE) 2024
On 28 March 2024 the PPC issued a recommendation under Article 148(1) for failures in organisational security (Article 23) after a breach through systems shared with Naver affecting about 520,000 people, requiring progress reports through March 2025; it gave separate guidance under Article 147 over an exposure affecting about 2.52 million Yahoo Auction sellers. The telecoms ministry issued its own administrative guidance. No monetary penalty. Source
Worth knowing
- Until the 2026 amendment takes effect (by July 2028 at the latest), Japan's privacy regulator has no fining power at all; enforcement is guidance, recommendation, order and, only after an order is breached, criminal prosecution.
- Most enforcement is soft and reputational: published guidance and recommendations with progress reporting, and no fine even for large breaches such as LY Corporation.
- The planned surcharge equals the financial benefit obtained from the violation, not a percentage of turnover, and small-scale cases (reported as fewer than 1,000 people affected) are excluded.
- The PPC does not resolve individual complaints; consultations feed its supervision, and redress for individuals is a matter for the civil courts.
Sources (9) research confidence: medium
- PPC: 2026 amendment to the APPI (passage 10 July 2026, promulgation 17 July 2026)
- PPC: outline of measures to ensure effective enforcement (surcharge design)
- PPC press release on Recruit (Rikunabi), 4 December 2019
- PPC press release on LY Corporation, 28 March 2024
- LY Corporation: progress on measures under the PPC recommendation
- PwC Japan: amendments to the APPI (passed 10 July 2026) secondary
- Baker McKenzie: Japan APPI reform key changes (surcharge exemptions) secondary
- One Asia Lawyers: overview of the APPI amendments (Articles 148-3 to 148-17) secondary
- DLA Piper Data Protection Laws of the World: Japan enforcement secondary
ThailandPDPCAsia-Pacific
In plain words
You complain to the PDPC office, and an expert committee examines the case, may try to settle it, and can order the company to fix things and fine it. Serious misuse is also a crime handled by the police. You can sue the company in court for your loss, and the court can add up to double that amount as punishment.
Route of a fine
- PDPC expert committee
- Administrative Court
- Supreme Administrative Court
The authority
- Name
- Personal Data Protection Committee, supported by the Office of the Personal Data Protection Commission and expert committees (คณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล), PDPC) Website
- How it is organised
- A committee chaired by an appointed expert with ex officio government members, working within the remit of the Ministry of Digital Economy and Society, served by a government office. Complaints and fines are handled by expert committees appointed by the PDPC, which can order remedies and impose administrative fines.
- Regional authorities
- No regional regulators. The police and public prosecutors handle the criminal offences; the PDPC runs a 'PDPC Eagle Eye' unit that works with police and other authorities on breaches and data leaks.
- National law
- Personal Data Protection Act B.E. 2562 (2019), published 27 May 2019, fully in force 1 June 2022 after two postponements Text
Complaining
- How
- Complaint to the Office of the PDPC, which passes it to an expert committee; details of the form, fee and language were not confirmed.
- Contact the organisation first?
- Not confirmed.
- Deadlines
- Not confirmed.
- The complainant's position
- Not confirmed; the expert committee can mediate between the parties or order the controller to act.
Procedure
- Complaint, breach notification (72 hours) or own-initiative inquiry, including through the PDPC Eagle Eye unit.
- Examination by an expert committee, which may mediate or reject the complaint.
- Expert committee order to the controller or processor (for example to remedy security or stop processing) and administrative fine.
- Separate criminal prosecution and civil claims in the courts.
- Who decides
- The expert committees decide complaints and impose administrative fines; the PDPC announces the outcomes.
- Limitation
- Not confirmed for administrative fines.
Fines
- Who imposes them
- Expert committees under the PDPC impose administrative fines themselves (sections 82 to 90), so the map value is regulator. Fines are fixed amounts per violation in tiers up to THB 1 million, 3 million and 5 million (THB 5 million for the most serious, such as sensitive data breaches), but several violations can be stacked: a 2024 fine reached THB 7 million.
- Public bodies
- Yes: in August 2025 a government agency and its software contractor were each fined over THB 150,000 after a breach of about 200,000 records.
- National specifics
- Criminal offences (section 79 onwards) cover unlawful use or disclosure of sensitive data likely to cause harm (up to 6 months and/or THB 500,000) or for unlawful gain (up to 1 year and/or THB 1 million), and directors or managers can be personally liable. Processors are fined directly and sometimes more heavily than controllers.
Appeals
- First court
- Not confirmed from the statute; as administrative orders of state officials, expert committee orders and fines are generally challengeable in the Administrative Court.
- Deadline
- Not confirmed.
- Does it hold payment?
- Not confirmed.
- Further appeal
- Supreme Administrative Court (general route; not confirmed in a PDPA case).
- If the authority does nothing
- Not confirmed.
Suing the organisation directly
- Courts
- Yes: controllers and processors are liable in civil courts for damage caused by non-compliance unless they prove force majeure or the data subject's own act (section 77).
- Compensation
- Actual damages plus punitive damages of up to twice the actual damages (section 78); limitation reported as 3 years from knowledge of the damage and the liable person or 10 years from the violation (not confirmed from the statute text).
- Collective actions
- Class actions are available under the Civil Procedure Code; no PDPA class action confirmed.
Cases worth knowing
- First PDPA fine: online retailer 2024
On 21 August 2024 the expert committee fined a large online shopping platform THB 7 million for failing to appoint a DPO (s 41), weak security (s 37(1)) and failing to notify a breach linked to call-centre scams (s 37(4)), and ordered a comprehensive security review, with a report to the PDPC within 7 days of the order. Source - August 2025 enforcement round 2025
On 1 August 2025 the PDPC announced eight fines in five cases totalling about THB 14.5 million, including THB 7 million for an IT retailer, THB 3 million for a toy company's processor and fines on a government agency and a private hospital. Source
Worth knowing
- Courts can add punitive damages of up to twice the actual loss, which no EU law provides.
- Fines are fixed amounts per violation, but stacking several violations has produced a fine above the THB 5 million headline cap.
- The regulator is a committee linked to a government ministry, with fining delegated to expert committees.
- Enforcement started slowly: the first fine came more than two years after full entry into force, and some case details stay confidential.
Sources (6) research confidence: medium
- Office of the Personal Data Protection Commission (Thailand)
- DLA Piper Data Protection Laws of the World: Thailand enforcement secondary
- Legal 500 / Gala Law: Thailand's PDPC signals tougher enforcement secondary
- Nishimura & Asahi: Personal data protection update (2024 fine) secondary
- Silk Legal: PDPA bares its teeth secondary
- Japan-Thailand Law: Thai PDPA guide 2026 secondary
VietnamMPS / A05Asia-Pacific
In plain words
A person can report a misuse of their data to the police ministry, which supervises data protection, or file a formal complaint or denunciation. The ministry can inspect and fine the company, and serious data trading is prosecuted as a crime. Separately, the person can sue in the People's Court for compensation.
Route of a fine
- Ministry of Public Security (A05)
- Complaint or People's Court
The authority
- Name
- Ministry of Public Security, Department of Cybersecurity and High-Tech Crime Prevention (Bộ Công an, Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao, MPS / A05) Website
- How it is organised
- A police ministry department, not an independent authority. The MPS is the state management focal point for personal data protection (Article 36 PDPL); A05 receives impact assessments and transfer filings, runs the national personal data protection portal and investigates.
- Regional authorities
- Provincial police units act under the MPS. The police also investigate the criminal offence of illegally trading or using personal data, and sector ministries keep their own rules.
- National law
- Law on Personal Data Protection No. 91/2025/QH15, adopted 26 June 2025, in force 1 January 2026; implementing Decree 356/2025/ND-CP (in force 1 January 2026, replacing Decree 13/2023/ND-CP of 17 April 2023, which applied from 1 July 2023); sanctions Decree 330/2026/ND-CP dated 19 August 2026 Text
Complaining
- How
- Data subjects may file complaints and denunciations, sue and claim compensation (Article 4 PDPL). Violations can be reported to the MPS, including through the national personal data protection portal; general complaints follow the Law on Complaints and Law on Denunciations.
- Contact the organisation first?
- Not confirmed as a requirement before going to the MPS.
- Deadlines
- Not confirmed for data protection complaints specifically.
- The complainant's position
- Not confirmed; under Vietnamese administrative law a denouncer is informed of the outcome but is not a party to the sanction proceedings.
Procedure
- Report, denunciation or own-initiative inspection by the MPS (A05 or provincial police), often triggered by an incident or a filed impact assessment.
- Record of administrative violation drawn up by a competent officer.
- Sanction decision under Decree 330/2026/ND-CP, with fines and remedial measures such as deletion of data or suspension of processing.
- Where the conduct is a crime, transfer for criminal investigation and prosecution under the Penal Code.
- Who decides
- Competent officers of the MPS and police impose administrative fines by decision under the Law on Handling of Administrative Violations; the full list of competent officers in Decree 330 was not confirmed.
- Limitation
- 1 year for administrative sanctions in cybersecurity and personal data protection (Decree 330/2026/ND-CP, Article 3(1)).
Fines
- Who imposes them
- The MPS imposes fines itself by administrative decision under Decree 330/2026/ND-CP (issued and in force 19 August 2026), so the map value is regulator. Maximums (Article 8 PDPL): 5% of the previous year's revenue for unlawful cross-border transfers, 10 times the proceeds for buying or selling personal data, and VND 3 billion for other violations by organisations, with individuals facing half; Decree 330 sets lower bands for specific breaches (for example up to VND 70 million for consent failures).
- Public bodies
- Not confirmed.
- National specifics
- Before Decree 330 the PDPL and Decree 13/2023 had no penalty schedule of their own; only scattered personal information breaches were fineable under the older telecoms and information sanctions decree (Decree 15/2020). Criminal liability for illegal provision or use of information on networks (Penal Code Article 288) carries fines of VND 30 million to 1 billion or 6 months to 7 years' imprisonment per secondary sources. Small enterprises and start-ups get a five-year deferral of some assessment duties.
Appeals
- First court
- A sanctioned party can file an administrative complaint with the official who issued the decision under the Law on Complaints, or sue in the People's Court under the Law on Administrative Procedure (the court level after the 2025 court reorganisation was not confirmed).
- Deadline
- Not confirmed for data protection decisions; general administrative law gives 1 year to sue, not confirmed specifically here.
- Does it hold payment?
- Not confirmed; under general Vietnamese administrative law a complaint or lawsuit normally does not suspend execution.
- Further appeal
- Appeal within the People's Court system; not confirmed in detail.
- If the authority does nothing
- Not confirmed.
Suing the organisation directly
- Courts
- Yes: Article 4 PDPL lets data subjects sue and claim compensation, and Article 8 says violators causing damage must compensate, in the ordinary People's Courts under the Civil Code.
- Compensation
- Actual damages under the Civil Code rules on non-contractual liability; no statutory damages confirmed.
- Collective actions
- Not confirmed; Vietnam has no general class action procedure (not confirmed).
Cases worth knowing
- Criminal crackdown on personal data trading, 2023 to 2025 2023-2025
Authorities reported more than 30 criminal cases involving illegal purchase, sale and theft of personal data, with about 160 million data files unlawfully acquired from sectors including healthcare, banking and telecoms. Source - Decree 330/2026/ND-CP sanctions regime 2026
Issued 19 August 2026, it finally made the PDPL's fines enforceable; no published administrative fine under it was found as of October 2026. Source
Worth knowing
- The data protection regulator is the police ministry's cybercrime department.
- The headline 5% of revenue cap applies only to unlawful cross-border transfers; most other breaches are capped at VND 3 billion (about USD 115,000).
- Buying and selling personal data is itself a sanctioned activity, punished at up to 10 times the proceeds.
- For about seven and a half months in 2026 the law was in force but its own fines could not be applied because the sanctions decree had not been issued.
Sources (7) research confidence: medium
- Law on Personal Data Protection No. 91/2025/QH15 (LuatVietnam English)
- Decree 330/2026/ND-CP on sanctions in cybersecurity and personal data protection (LuatVietnam English)
- Tilleke & Gibbins: Vietnam issues cybersecurity and PDP sanctions decree secondary
- Viet An Law: Decree 330/2026/ND-CP penalties secondary
- DLA Piper Data Protection Laws of the World: Vietnam secondary
- Vietnam Law Magazine: tightened personal data protection requirements secondary
- Vietnam Briefing: personal data protection law guide secondary
PhilippinesNPCAsia-Pacific
In plain words
You first write to the organisation and give it 15 days to fix the problem. If it does not, you file a sworn complaint with the National Privacy Commission, which hears both sides like a tribunal and can order changes, fine the organisation and award you damages. If a crime is involved it can refer the case to the Department of Justice for prosecution.
Route of a fine
- NPC decision
- Motion for reconsideration
- Court of Appeals
- Supreme Court
The authority
- Name
- National Privacy Commission (Pambansang Komisyon sa Pagkapribado (National Privacy Commission), NPC) Website
- How it is organised
- Independent body attached to the Department of Information and Communications Technology for budget purposes, headed by a Privacy Commissioner and two deputies. It adjudicates complaints as a quasi-judicial body, runs own-motion (sua sponte) investigations and compliance checks, and imposes administrative fines.
- Regional authorities
- No regional regulators. The Department of Justice prosecutes the criminal offences in the Data Privacy Act on NPC recommendation or direct complaint; sector regulators such as the central bank (BSP) supervise data security in finance.
- National law
- Data Privacy Act of 2012 (Republic Act No. 10173), with its 2016 Implementing Rules and Regulations; NPC Circular 2022-01 on administrative fines in force from 27 August 2022 Text
Complaining
- How
- Notarised complaints-assisted form or verified complaint with evidence and witness affidavits, filed with the NPC (online channels and email are offered); forms exist in English and Filipino. Applications for a temporary ban on processing can be filed alongside.
- Contact the organisation first?
- Yes: the complainant must first inform the organisation in writing and may file only if it does not respond within 15 calendar days (or responds inadequately).
- Deadlines
- No specific filing deadline beyond the Act No. 3326 prescription periods the NPC applies. The investigating officer reports within 30 days of the last memoranda; the Commission must decide breach matters within 30 days, with no fixed deadline for other complaints.
- The complainant's position
- Full party: the complainant and respondent litigate before an investigating officer and the Commission, and the NPC can award damages, including nominal damages, to the complainant.
Procedure
- Complaint after exhausting the 15-day step with the organisation, or NPC sua sponte investigation, breach notification or compliance check.
- Evaluation by an investigating officer: dismissal or continuation; mediation is offered in suitable cases.
- Adversarial proceedings with submissions, possibly e-hearings, then a decision by the Commission en banc.
- Orders (compliance, cease and desist, temporary ban), administrative fines after notice and hearing, damages, and recommendation of criminal prosecution to the Department of Justice.
- Motion for reconsideration to the NPC, then appeal to the courts.
- Who decides
- The Commission (Privacy Commissioner and deputies) decides and imposes fines by administrative decision.
- Limitation
- The NPC applies the prescription periods for offences under special laws in Act No. 3326, which vary with the penalty (2021 Rules of Procedure).
Fines
- Who imposes them
- The NPC imposes administrative fines itself under Circular 2022-01, so the map value is regulator. Grave infractions carry 0.5% to 3% and major infractions 0.25% to 2% of annual gross income, with fixed amounts of PHP 50,000 to 200,000 for other infractions, but the total for a single act may not exceed PHP 5 million, so the binding ceiling is a fixed amount (map value fixed).
- Public bodies
- Government agencies are personal information controllers under the Act and are not excluded from Circular 2022-01; whether the NPC has fined one was not confirmed. The NPC has recommended prosecution of public officials (COMELEC).
- National specifics
- Criminal offences in sections 25 to 33 of the Act (unauthorised processing, negligent access, improper disposal, concealment of breaches, malicious disclosure) carry 6 months to 7 years' imprisonment and fines of PHP 100,000 to 5 million, prosecuted by the DOJ before the regular courts; responsible officers of companies can be jailed. The NPC also issues cease and desist orders and temporary bans.
Appeals
- First court
- After a motion for reconsideration, an NPC decision is appealed 'to the proper courts' (2021 Rules of Procedure, Rule VIII s 7); in practice this is a petition for review to the Court of Appeals, which upheld the NPC in Pieceland Corporation v Manila New Life Church (14 December 2021).
- Deadline
- NPC decisions become final 15 calendar days after notice unless one motion for reconsideration is filed within that period (2021 Rules of Procedure); a petition for review under Rule 43 is generally due within 15 days (not stated in NPC rules).
- Does it hold payment?
- No: decisions imposing fines are immediately executory unless restrained by a court, and an appellant must post a bond equal to the fine to stay enforcement (Circular 2022-01).
- Further appeal
- Supreme Court on a petition for review (general route; not confirmed in an NPC case).
- If the authority does nothing
- A complainant whose complaint is dismissed may move for reconsideration and then appeal; no specific remedy for inaction confirmed.
Suing the organisation directly
- Courts
- Yes: data subjects have a statutory right to damages for inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorised use of personal information (section 16(f)), claimable before the NPC or in the regular courts; the writ of habeas data is also available from the courts.
- Compensation
- Actual, moral and nominal damages under general civil law; the NPC has awarded nominal damages in complaint decisions. No statutory damages.
- Collective actions
- Class actions are possible but rare according to secondary sources; not confirmed in a decided data privacy case.
Cases worth knowing
- COMELEC 'Comeleak' breach 2016-2017
In a decision dated 28 December 2016 on the breach of over 75 million voter records, the NPC found the Commission on Elections in breach of the Act and its chairman Andres Bautista criminally liable for negligent access (s 26), and recommended his prosecution to the Department of Justice. Source - Cease and desist order against Tools for Humanity (World App) 2025
On 8 October 2025 the NPC ordered Tools for Humanity to stop all personal data processing linked to World App and Orb iris verification in the Philippines, holding that consent obtained by paying people is not freely given. Source
Worth knowing
- The NPC is a quasi-judicial tribunal: complaints are adversarial cases with captioned parties, and it can award damages to the complainant.
- Percentage-of-income fines exist but are capped at PHP 5 million (about EUR 75,000) per act.
- Many breaches are also crimes with prison terms for responsible officers, prosecuted by the Department of Justice.
- A complainant must first write to the organisation and wait 15 days before filing.
Sources (7) research confidence: medium
SingaporePDPCAsia-Pacific
In plain words
You first raise the problem with the organisation; if that fails you fill in the PDPC's online form. The PDPC may broker a fix or investigate, and if it finds a breach it can order changes and fine the organisation itself, publishing the decision. You can separately sue in court for your own loss, including distress.
Route of a fine
- PDPC direction
- Reconsideration or Appeal Panel
- High Court
- Court of Appeal
The authority
- Name
- Personal Data Protection Commission (Personal Data Protection Commission, PDPC) Website
- How it is organised
- Statutory commission administered within the Info-communications Media Development Authority (IMDA), so it is a government body rather than an independent authority in the EU sense. It handles complaints, investigates, issues directions and imposes financial penalties itself, and also enforces the Do Not Call rules.
- Regional authorities
- No regional regulators. Public agencies are outside the PDPA and are governed by the Public Sector (Governance) Act 2018 and internal government rules; sector regulators such as the Monetary Authority of Singapore impose their own data and technology risk requirements.
- National law
- Personal Data Protection Act 2012 (PDPA), data protection obligations in force 2 July 2014; amended by the Personal Data Protection (Amendment) Act 2020 (mandatory breach notification and offences from 1 February 2021; higher financial penalty cap of 10% of Singapore turnover from 1 October 2022) Text
Complaining
- How
- Online 'raise a data protection concern' form on the PDPC website, free of charge, in English. The PDPC assesses each concern and decides whether to facilitate a resolution, refer it to mediation, investigate or take no further action.
- Contact the organisation first?
- Encouraged in practice: individuals are expected to raise the issue with the organisation first, and the PDPC may redirect concerns that have not been raised with the organisation. A strict statutory requirement was not confirmed.
- Deadlines
- Not confirmed: no statutory time limit for lodging a concern or for the PDPC to decide was found.
- The complainant's position
- The complainant is a source of information rather than a party; the investigation and any decision are between the PDPC and the organisation. A person aggrieved by a PDPC direction or decision can seek reconsideration (s 48N) or appeal (s 48Q), which are alternatives (s 48Q(3)), and a final PDPC finding supports a private action under s 48O.
Procedure
- Concern lodged or PDPC starts its own investigation, often after a mandatory breach notification (Part 6A, 3 calendar days after assessing a notifiable breach).
- Preliminary assessment: facilitation with the organisation, referral to mediation, or a formal investigation under s 48I.
- Organisation may offer a voluntary undertaking (s 48L) or accept the expedited decision procedure by admitting the breach.
- PDPC decision: finding of breach, directions (for example to fix security measures) and, where warranted, a financial penalty under s 48J; most decisions are published.
- Reconsideration by the PDPC (s 48N) or appeal to the Data Protection Appeal Panel (s 48Q), then the High Court (s 48R).
- Who decides
- The Commission (in practice the Commissioner and deputy commissioners within IMDA) decides and imposes the penalty by administrative direction, without going to court.
- Limitation
- Not confirmed: no statutory limitation period for PDPC enforcement was found.
Fines
- Who imposes them
- The PDPC imposes financial penalties itself by direction under s 48J, so the map value is regulator. Since 1 October 2022 the maximum is SGD 1 million or 10% of the organisation's annual turnover in Singapore where that turnover exceeds SGD 10 million, whichever is higher (turnover-based). Section 48J(6) lists the factors the PDPC must weigh, and the PDPC applied a five-step culpability and harm method in Marina Bay Sands (2025).
- Public bodies
- No. The PDPA does not apply to public agencies; public officers face criminal offences under the Public Sector (Governance) Act 2018 instead.
- National specifics
- Individuals commit offences for knowing or reckless unauthorised disclosure, improper use and re-identification of personal data (ss 48D to 48F), with fines of up to SGD 5,000 and/or imprisonment of up to 2 years, prosecuted in the criminal courts. Directions to stop collecting, to destroy data or to comply with obligations are common, and penalty decisions are published by name.
Appeals
- First court
- An aggrieved organisation or person, including the complainant, may either apply to the PDPC for reconsideration (s 48N) or appeal to an Appeal Committee of the Data Protection Appeal Panel (s 48Q); a reconsideration decision can itself be appealed, and applying for reconsideration withdraws any pending appeal (s 48Q(3)). Appeal Committee decisions go to the General Division of the High Court on a point of law or on the amount of a financial penalty (s 48R).
- Deadline
- The prescribed period, reported as 28 days, for both a reconsideration application (s 48N(4)) and an appeal to the Appeal Panel (s 48Q); the PDPC may extend the reconsideration period in exceptional circumstances (s 48N(5)).
- Does it hold payment?
- No for directions, yes for penalties: unless the PDPC or the Appeal Committee decides otherwise, a reconsideration application or appeal does not suspend a direction, but one against a financial penalty does (ss 48N(3), 48Q(4)).
- Further appeal
- From the High Court a further appeal lies to the Court of Appeal, as in Bellingham v Reed (a private action case).
- If the authority does nothing
- Any organisation or individual aggrieved by a PDPC direction or decision can seek reconsideration and appeal under ss 48N and 48Q; there is no specific remedy for inaction other than judicial review in the High Court (not confirmed as used).
Suing the organisation directly
- Courts
- Yes: s 48O gives a statutory right of private action for loss or damage suffered directly from a contravention of the main data protection obligations, heard in the ordinary civil courts (State Courts or High Court depending on value). Where the PDPC has already made a decision on the same matter, the action can only be brought once that decision is final after any appeal.
- Compensation
- Damages, injunctions and declarations are available. In Bellingham v Reed [2022] SGCA 60 the Court of Appeal held that loss of control of data alone is not enough but emotional distress can count as loss; Piper v Singapore Kindness Movement [2025] SGHC 173 stressed a strict causal link. No statutory damages.
- Collective actions
- No dedicated class action regime; representative actions under the Rules of Court are possible in principle but no PDPA class action was confirmed.
Cases worth knowing
- SingHealth and Integrated Health Information Systems (IHiS) 2019
After the 2018 cyberattack exposing data of about 1.5 million patients, the PDPC fined IHiS SGD 750,000 and SingHealth SGD 250,000, then the largest PDPA penalties (both under the old SGD 1 million cap). Source - Marina Bay Sands Pte Ltd [2025] SGPDPC 6 2025
On 28 October 2025 the PDPC imposed SGD 315,000 (from a starting figure of SGD 450,000, reduced for mitigation) for breach of the protection obligation (s 24) during a software migration; the second-largest PDPA penalty to date and the first decision to set out a five-step penalty method. Source - Bellingham, Alex v Reed, Michael [2022] SGCA 60 2022
The Court of Appeal confirmed that emotional distress is 'loss or damage' under the private action provision, opening the door to s 48O claims without financial loss; it upheld an injunction against a former employee's misuse of investor data. Source
Worth knowing
- The regulator sits inside a government agency (IMDA), and the whole public sector is outside the PDPA.
- Penalties are linked to Singapore turnover only, not worldwide turnover, and actual fines remain modest: most are in the thousands or tens of thousands of dollars.
- There is no general lawful-basis menu like Article 6 GDPR; consent, deemed consent and listed exceptions such as legitimate interests do that job.
- Organisations can avoid a full investigation by offering a voluntary undertaking or by admitting liability for an expedited decision.
Sources (7) research confidence: medium
- Personal Data Protection Act 2012 (Singapore Statutes Online)
- PDPC website (concerns, enforcement decisions)
- Drew & Napier: PDPC clarifies penalty framework in Marina Bay Sands decision (Nov 2025) secondary
- Chambers Data Protection & Privacy 2026: Singapore trends and developments secondary
- CMS: higher financial penalties from 1 October 2022 secondary
- RPC: Fines for PDPA breaches (s 48J(6) factors) secondary
- ComplyHQ: PDPA penalties and fines (SingHealth/IHiS) secondary
IndonesiaLembaga PDPAsia-Pacific
In plain words
There is no data protection regulator yet, so a person with a complaint usually goes to the ministry for digital affairs, a sector regulator such as the financial services authority, or the police if a crime is involved. You can also sue the organisation for compensation in the civil courts. Once the planned agency is created it will be able to fine organisations up to 2% of revenue.
Route of a fine
- Komdigi now, PDP agency planned
- Objection, then State Administrative Court
The authority
- Name
- Personal Data Protection Agency (not yet established); interim: Ministry of Communication and Digital Affairs (Lembaga Pelindungan Data Pribadi (not yet established); interim: Kementerian Komunikasi dan Digital (Komdigi), Lembaga PDP (planned); Komdigi (interim)) Website
- How it is organised
- The PDP Law foresees an agency set up by the President and answerable to the President (Articles 58 to 61), not an independent authority. As of October 2026 the Presidential Regulation creating it has not been issued and the agency does not exist; Komdigi (the former Kominfo, renamed in October 2024), through its Directorate General of Digital Space Supervision, supervises electronic system operators in the meantime.
- Regional authorities
- Sector regulators enforce their own confidentiality rules, notably the Financial Services Authority (OJK) for banks and capital markets. The police and public prosecutors enforce the criminal offences in the PDP Law and the Electronic Information and Transactions (ITE) Law.
- National law
- Law No. 27 of 2022 on Personal Data Protection (UU PDP), enacted 17 October 2022 with a two-year transition, fully applicable from 17 October 2024; implementing Government Regulation No. 33 of 2026, signed 16 July 2026 and in force 16 January 2027 Text
Complaining
- How
- Not confirmed: with no PDP agency, there is no dedicated PDP complaint channel. In practice individuals complain to Komdigi about electronic system operators, to OJK for financial institutions, or report criminal conduct to the police.
- Contact the organisation first?
- Not confirmed as a legal requirement; data subjects have rights to request access, correction and erasure from the controller directly (Articles 5 to 13).
- Deadlines
- Not confirmed.
- The complainant's position
- Not confirmed; the agency's complaint procedure is to be set out in GR 33/2026 and future agency regulations.
Procedure
- Today: Komdigi can act against electronic system operators under the older electronic systems rules (GR 71/2019), with warnings, suspension, access blocking or deregistration.
- Criminal route: police investigation and prosecution under Articles 67 to 70 of the PDP Law, decided by the District Court.
- Once the agency exists: supervision, investigation and administrative sanctions under Article 57, with an objection to the agency within 14 working days of a sanction decision (GR 33/2026), then the State Administrative Court.
- Who decides
- Administrative sanctions under the PDP Law will be imposed by the PDP agency; criminal penalties by the District Courts on prosecution.
- Limitation
- Not confirmed.
Fines
- Who imposes them
- No body can currently impose the PDP Law's administrative fines because the agency does not exist, so penalties come in practice through criminal prosecution in the courts (map value court). Once operational, the agency may impose fines of up to 2% of annual income or revenue (Article 57; GR 33/2026 Article 185 refers to gross revenue), alongside warnings, suspension of processing and data deletion.
- Public bodies
- Not confirmed. The PDP Law applies to public bodies as controllers, but whether the agency can fine them is not confirmed.
- National specifics
- Criminal offences cover unlawful collection, disclosure and use of personal data and creating false personal data (Articles 67 and 68), with 4 to 6 years' imprisonment. Law No. 1 of 2026 (penalty adjustment for the new Criminal Code, in force 2 January 2026) cut the maximum fines from IDR 4 to 6 billion to IDR 200 million, or IDR 500 million for false data; corporations face up to ten times the fine plus measures such as licence revocation or dissolution (Article 70).
Appeals
- First court
- Sanction decisions of the future agency go first to an objection to the agency, then to the State Administrative Court (PTUN) under GR 33/2026. Criminal convictions follow the ordinary route: District Court, High Court, Supreme Court.
- Deadline
- Objection within 14 working days of the sanction decision (GR 33/2026, in force 16 January 2027); court deadlines not confirmed.
- Does it hold payment?
- Not confirmed.
- Further appeal
- State Administrative High Court and Supreme Court on cassation (general administrative law route; not confirmed specifically for PDP cases).
- If the authority does nothing
- A Constitutional Court petition (case 236/PUU-XXII/2024) seeking to compel the government to set up the agency was pending as of September 2026. No other remedy for regulator inaction confirmed.
Suing the organisation directly
- Courts
- Yes: data subjects have a right to sue and receive compensation for breaches (Article 12), through the District Courts, arbitration or other dispute resolution (Article 64), and general tort liability under the Civil Code also applies.
- Compensation
- Compensation for loss under Article 12 and the Civil Code; no statutory damages.
- Collective actions
- Class actions are possible under Supreme Court Regulation No. 1 of 2002 on class action procedure; no PDP-specific class action confirmed.
Cases worth knowing
- First criminal conviction under the PDP Law, Karanganyar District Court 2023
A defendant was sentenced to four years' imprisonment and an IDR 1 billion fine for personal data falsification, the first reported criminal conviction under the PDP Law. Source - Constitutional Court Decision 151/PUU-XXII/2024 2025
On 30 July 2025 the Constitutional Court read the cumulative 'and' in the data protection officer trigger (Article 53(1)) as 'and/or', so meeting one condition is enough, widening the DPO obligation. Source - Constitutional Court case 236/PUU-XXII/2024 on the missing agency pending (2026)
A petition that could push the executive to establish the supervisory agency remained pending as of September 2026; no administrative PDP fine has been imposed anywhere because the agency does not exist. Source
Worth knowing
- The law has been fully applicable since October 2024, but the regulator it creates still does not exist two years later, so the turnover-based fines are unenforceable.
- The future agency will be a presidential body, not an independent authority.
- Criminal law does the heavy lifting: individuals and companies can be imprisoned or fined for misusing personal data, even while administrative enforcement is absent.
- GR 33/2026, the main implementing regulation, only enters into force on 16 January 2027.
Sources (6) research confidence: medium
- Law No. 27 of 2022 on Personal Data Protection (BPK legal database)
- Komdigi (Ministry of Communication and Digital Affairs)
- Nusantara DFDL: GR 33/2026 compliance guide secondary
- Chambers Data Protection & Privacy 2026: Indonesia trends and developments secondary
- DLA Piper Data Protection Laws of the World: Indonesia secondary
- Isentia: Indonesia's PDP law in 2026 secondary
AustraliaOAICAsia-Pacific
In plain words
You first complain to the organisation and wait 30 days, then you can complain free of charge to the OAIC, which usually tries to broker a settlement and can make a determination ordering compensation. For serious breaches the OAIC cannot fine directly: it has to take the company to the Federal Court, which decides the penalty. Since June 2025 you can also sue yourself for a serious invasion of privacy.
Route of a fine
- OAIC investigation
- Federal Court civil penalty
- Full Federal Court
- High Court (special leave)
The authority
- Name
- Office of the Australian Information Commissioner (Office of the Australian Information Commissioner, OAIC) Website
- How it is organised
- Independent Commonwealth statutory agency headed by the Australian Information Commissioner, with a Privacy Commissioner. It handles complaints, runs investigations, makes determinations and brings civil penalty proceedings in the Federal Court.
- Regional authorities
- States and territories have their own regulators for state public sector bodies (for example NSW and Victorian information commissioners). Sector schemes also matter in practice: external dispute resolution schemes for finance, telecoms and utilities must usually be used before the OAIC, and the ACCC enforces consumer law against misleading privacy claims.
- National law
- Privacy Act 1988 (Cth), with the 13 Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme (Part IIIC); amended by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (higher penalties, in force 13 December 2022) and the Privacy and Other Legislation Amendment Act 2024 (in force 10 December 2024; statutory tort from 10 June 2025; automated decision transparency duties from 10 December 2026) Text
Complaining
- How
- Online complaint form on the OAIC website, free of charge, in English. The complaint must name the entity, describe the issue with dates and impact, and include evidence of the earlier complaint to the entity.
- Contact the organisation first?
- Yes. The individual must first complain to the organisation or agency and give it 30 days to respond; where an approved external dispute resolution scheme applies (banking, insurance, superannuation, telecoms, energy and water) that scheme should be used first.
- Deadlines
- The OAIC may decline a complaint made more than 12 months after the complainant became aware of the act (s 41). There is no statutory deadline for the OAIC; it states it is unlikely to substantially progress new complaints for around 6 to 12 months after lodgement.
- The complainant's position
- The complainant is a party to conciliation and to any s 52 determination, and can receive a compensation award. The OAIC can decline or stop investigating on discretionary grounds (s 41), for example where the matter is low impact or better dealt with by an EDR scheme.
Procedure
- Complaint to the entity first, then complaint to the OAIC, or a Commissioner-initiated investigation (s 40(2)) often following a notifiable data breach
- Preliminary inquiries and assessment; the OAIC may decline under s 41
- Conciliation between complainant and entity, which resolves most complaints
- Investigation, which may end in a determination under s 52 (declarations, orders to stop conduct, take steps or pay compensation) or an enforceable undertaking (s 33E)
- For serious matters, civil penalty proceedings in the Federal Court; since December 2024 the OAIC can also issue infringement notices and compliance notices for specified lower-level breaches
- Who decides
- The Information Commissioner decides complaints and determinations. Only the Federal Court (or Federal Circuit and Family Court) can order a civil penalty; infringement notices issued by the OAIC are a payable alternative that the entity can instead contest in court.
- Limitation
- Civil penalty proceedings must generally be brought within 6 years of the contravention under the Regulatory Powers (Standard Provisions) Act 2014 (not confirmed against the primary text this session).
Fines
- Who imposes them
- Regulator-court: the OAIC investigates but cannot fine for serious breaches itself; it must apply to the Federal Court, which sets the civil penalty. For a serious interference with privacy (s 13G) the maximum for a body corporate is the greatest of AUD 50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach period (since 13 December 2022). The 2024 Act added a mid-tier civil penalty for interferences that are not serious (s 13H) and an administrative tier (s 13K) for specified APP and privacy policy failures that the OAIC can enforce by infringement notice without going to court.
- Public bodies
- Australian Government agencies are bound by the APPs and can be subject to determinations; whether civil penalties are pursued against Commonwealth agencies in practice was not confirmed. Most small businesses with annual turnover of AUD 3 million or less remain exempt.
- National specifics
- The infringement notice amounts and the s 13H maximum are set in penalty units; exact dollar figures were not confirmed from a primary source this session. The court counts contraventions per affected individual, so exposure in breach cases is cumulative. Doxxing became a criminal offence under the Criminal Code in 2024 (up to 6 or 7 years imprisonment depending on the offence, secondary source).
Appeals
- First court
- Civil penalties are set by the Federal Court, so a challenge is an appeal to the Full Federal Court and then, with special leave, the High Court. OAIC determinations and other administrative decisions are challenged by judicial review in the Federal Court or Federal Circuit and Family Court.
- Deadline
- Not confirmed for each route (court rules set the time limits).
- Does it hold payment?
- Not confirmed. A s 52 determination against a private entity is not self-executing: the complainant or the OAIC must apply to the Federal Court to enforce it (s 55A), and the court hears the matter afresh.
- Further appeal
- Full Federal Court, then High Court of Australia by special leave.
- If the authority does nothing
- There is no merits appeal against the OAIC's discretionary decision to decline or stop investigating; the remedy is judicial review on legal grounds, or since June 2025 suing directly under the statutory tort where its conditions are met.
Suing the organisation directly
- Courts
- Limited. There is no general right to sue for breach of the APPs; compensation comes mainly through OAIC conciliation and determinations. Since 10 June 2025 the Privacy Act (Schedule 2) gives individuals a statutory tort for serious invasions of privacy, intentional or reckless, in the Federal Court, Federal Circuit and Family Court or state and territory courts. The first cases were filed in 2025 (Groth v Herald and Weekly Times, settled; Kurraba Group v Williams, NSW District Court interlocutory injunction).
- Compensation
- Under the tort, damages including for emotional distress, injunctions and other remedies; non-economic damages are capped (exact cap not confirmed). Under s 52 the OAIC can award compensation, including for injury to feelings.
- Collective actions
- Representative complaints can be made to the OAIC (s 38). Class actions under Part IVA of the Federal Court of Australia Act are active after major breaches, usually pleaded in contract, negligence or consumer law (for example against Medibank and Optus).
Cases worth knowing
- Australian Information Commissioner v Australian Clinical Labs Ltd 2025
First civil penalty ever ordered under the Privacy Act: on 8 October 2025 Justice Halley in the Federal Court ordered AUD 5.8 million by consent on agreed facts (AUD 4.2 million for failing to protect data under APP 11.1, AUD 0.8 million each for late assessment under s 26WH(2) and late notification under s 26WK(2)) over the 2022 Medlab Pathology breach affecting over 223,000 people ([2025] FCA 1224). The pre-2022 penalty maximums applied. Source - Meta (Facebook) Cambridge Analytica settlement 2024
Civil penalty proceedings filed in March 2020 ended on 17 December 2024 when Meta gave an enforceable undertaking to pay AUD 50 million into a compensation scheme for affected Australian users, and the Commissioner withdrew the case. The OAIC called it the largest payment ever dedicated to privacy concerns in Australia. Source - OAIC v Medibank and OAIC v Optus 2024-2025
The OAIC filed Federal Court civil penalty proceedings against Medibank on 5 June 2024 (9.7 million people, APP 11.1, up to AUD 2.22 million per contravention) and against Optus on 8 August 2025 (about 9.5 million people). Both were pending as at the latest sources found; outcomes not confirmed. Source
Worth knowing
- The regulator cannot fine for serious breaches: it must sue in the Federal Court, which is why only one civil penalty had been ordered by late 2025, more than a decade after civil penalties were introduced.
- Penalties are counted per affected individual, so a single breach can be pleaded as hundreds of thousands or millions of contraventions.
- Small businesses with turnover of AUD 3 million or less are largely outside the Privacy Act, and employee records held by private employers are exempt.
- An OAIC determination ordering compensation is not directly enforceable; it needs a Federal Court order.
- The new statutory tort is separate from the APPs: it covers serious intrusions and misuse of information by anyone, including individuals, with exemptions such as journalism.
Sources (9) research confidence: medium high
- OAIC: Australian Clinical Labs ordered to pay penalties (first for Privacy Act)
- OAIC: Landmark settlement of $50m from Meta
- OAIC: Meta Platforms enforceable undertaking
- OAIC takes civil penalty action against Medibank
- Privacy Act 1988 (Federal Register of Legislation)
- DMAW Lawyers: Optus faces OAIC legal action secondary
- LK Law: Privacy in the Courts (statutory tort cases) secondary
- Wotton Kearney: Cyber, Privacy and Technology Report Issue 11 (POLA 2024 commencement dates) secondary
- Captain Compliance: OAIC complaint handling secondary
Method and limits
Each jurisdiction was researched from its statute, the regulator's own pages and published decisions, with law firm and press sources used to locate facts and marked secondary in the source lists. A second, independent pass re-read the cited sources and corrected 71 points, among them a Nigerian fine that had been set aside by consent, a Korean record fine whose amount and date were wrong, and a Singapore appeal route described as sequential when the statute makes it a choice.
- Many statute portals refuse automated reading, so some section numbers rest on consolidated copies or secondary summaries. The source lists say which.
- Appeal deadlines and whether an appeal holds payment are the least certain fields, as on the European page.
- Laws in transition are described as they stood on 2 October 2026. Anything after that date is not reflected.
- The map and the comparison compress paragraphs into one label. Read the section before relying on one.
Related on this site: GDPR enforcement in Europe for the EEA, the Cookie Compliance Digest for cookie and tracking rules in these jurisdictions, and the Practical Privacy playbook.