Korea raises data breach fines to 10% of revenue
Recorded: Sept. 18, 2026, 9:09 p.m.
| Original | Summarized |
South Korea raises data breach fines to 10% of revenue Jump to main content Newsletter Print Edition K-campus Korea Business Lifestyle Entertainment Sports Opinion World Search Korea Politics Social Affairs North Korea Diplomacy Defense Environment K-campus Business Industry Economy Tech Money Games and Webtoons Guest Reports Lifestyle Food and Travel Life and Trends Arts and Books Music and Theater Korean Heritage Entertainment K-pop TV and Streaming Movies Sports Football Baseball Golf Volleyball Basketball Tennis Olympic Sports More Opinion Editorials Columns Cartoons Letters Voices World Bilingual News KJD Special Why Live Newsletters Multimedia News Video Photo Audio Search Newsletter Print Edition K-campus x fb ig yt naver in Korea Politics Social Affairs North Korea Diplomacy Defense Environment K-campus Business Industry Economy Tech Money Games and Webtoons Guest Reports Lifestyle Food and Travel Life and Trends Arts and Books Music and Theater Korean Heritage Entertainment K-pop TV and Streaming Movies Sports Football Baseball Golf Volleyball Basketball Tennis Olympic Sports More Opinion Editorials Columns Cartoons Letters Voices World Bilingual News KJD Special Why Live Newsletters Multimedia News Video Photo Audio Korea raises data breach fines to 10% of revenue Companies behind major negligent data leaks can now face fines of up to 10 percent of annual revenue under revised privacy rules. News Team News Published Modified
Personal Information Protection Commission Chairperson Song Kyung-hee speaks during a plenary session of the watchdog at the government complex in Jongno District, central Seoul, on Sept. 9. Korea's privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence can be fined up to 10 percent of their total revenue as part of a broader overhaul under the revised Personal Information Protection Act that is set to take effect the same day. Even if a leak hasn't been confirmed, companies must notify users within 72 hours if the risk of exposure is high. “Personal data breaches have recently occurred repeatedly and grown in scale in fields closely tied to daily life, such as retail and telecommunications,” Personal Information Protection Commission (PIPC) Secretary General Yang Cheong-sam told reporters Thursday. “We've improved the system to hold serious violations strictly accountable while also helping prevent breaches from happening in the first place.” Related Article Korea to introduce strengthened penalties for large-scale data leaks Gender Ministry considers criminal charges against Google over leaked victim data As U.S. and Europe hit gas on Chinese smart car restrictions, Korea sits at red light Under the enforcement decree, the cap applies to companies that repeatedly commit intentional or grossly negligent violations within three years, or that fail to comply with a corrective order and go on to suffer a breach as a result. Fines are calculated based on the nature and severity of the violation, the circumstances involved and the scale of the damage.Before the revision, companies were subject to a penalty of up to 3 percent of sales.The gap between the old and new rules becomes clear when applied to a real case. Local e-commerce giant Coupang was fined 624.6 billion won ($466.3 million) in June after leaking the personal data of 37.55 million people. Applying the new standard to that case could push the fine into the trillions of won. However, actual penalties will still depend on intent, negligence, the scale of damage and any mitigating factors. Coupang’s headquarters in Songpa District, southern Seoul. Companies that invested in data protection beforehand will get credit under the new rules. Regulators will consider the scale and continuity of a company's investment in data protection budgets, staffing and equipment, along with its broader protection system, including its chief privacy officer, to reduce a fine by up to 40 percent. A company that detects a breach early, reports and notifies users promptly, and prevents the damage from spreading can also receive up to a 40 percent reduction.The revision also introduces a “potential data breach notification system.” If a company determines there is a high likelihood that personal data was exposed — for instance, after illegal access to its data processing systems, or after discovering that some personal data was illegally traded in a way that suggests others' data may have leaked too — it must notify affected individuals within 72 hours of learning that. Data forged, altered or damaged by ransomware and similar attacks is now also subject to the same reporting and notification requirements.The authority and responsibility of chief privacy officers at major companies and institutions will also expand. Companies with annual revenue exceeding 180 billion won that process the personal data of 1 million or more people, or the sensitive or unique identifying information of 50,000 or more people, must get board approval before appointing, changing or dismissing a chief privacy officer and report the decision to the PIPC. Universities with 20,000 or more students, tertiary general hospitals and operators of major public systems fall under the same requirement.“We expect the way companies view investment in data protection to shift from seeing it as a cost to treating it as a proactive investment that builds customer trust and expands corporate profit,” PIPC's Chairperson Song Kyung-hee said. BY HAN EUN-HWA [lee.jian@joongang.co.kr] This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom. personal information protection commission Read more SK chair pays $578,000 to appeal property division settlement Naver Cloud pitches sovereign AI system to transform Korean military operations SK hynix’s Solidigm weighs New York NAND factory Samsung Exynos share climbs to 9 percent in Q2 See more articles South Korea tops Pool D after four-set victory over Vietnam at Asian Games women's volleyball Korea storms into Asian Games basketball final U.S. ambassador calls alliance with South Korea linchpin of Indo-Pacific peace and security National Museum of Korea draws 5 million visitors at record pace Bows, guns and swords: South Korea's weapons of choice in war for 40 Asian Games golds Wayne Thiebaud’s cakes arrive in Seoul, revealing an artist who painted order beneath every sweet surface SK chair pays $578,000 to appeal property division settlement Yeon Sang-ho says mother inspired new thriller 'Paradise Lost' About Company Contact Us Newsletter Advertising Work For Us FAQ Notice Ombudsman Terms of Use Copyright Policy Privacy Policy Juvenile Protection Policy x All materials contained on this site are protected by Korean copyright law and may not be reproduced, distributed, transmitted, displayed, published or broadcast without the prior consent of the JoongAng Ilbo | Tel: 1577-0510 |
South Korea has implemented a significant overhaul of its privacy regulations by substantially increasing the penalties for data breaches, aiming to fundamentally shift corporate behavior toward viewing data protection as a proactive investment rather than merely an operational cost. Currently, companies that cause leaks of personal data belonging to ten million or more individuals through intent or gross negligence face potential fines up to ten percent of their total annual revenue. This change is enacted under the revised Personal Information Protection Act, effective immediately. The revision introduces stricter accountability measures. Penalties are calculated based on the nature and severity of the violation, the specific circumstances involved, and the scale of the resulting damage. This new framework applies to companies that repeatedly violate data protection rules over a three-year period or those who fail to comply with corrective orders and subsequently suffer a breach. The potential financial impact is substantial; for instance, applying the new standard to a case involving a major e-commerce company could result in fines reaching into the trillions of won. In addition to punitive measures, the updated rules mandate proactive notification procedures. Companies must now notify affected users within seventy-two hours if there is a high likelihood that personal data has been exposed, regardless of whether the breach has been fully confirmed. This framework also extends notification requirements to incidents resulting from ransomware attacks, as data damaged or altered by such incidents is now subject to the same reporting obligations. Furthermore, a potential data breach notification system has been established to facilitate this immediate response. To encourage preventative measures, the revised rules offer mitigation opportunities for companies that invest in data protection measures beforehand. Regulators will assess the extent of a company's investments in data protection budgets, staffing, equipment, and overall protection systems, including the role of the chief privacy officer. Companies that detect a breach early, ensure prompt notification to users, and successfully prevent the spread of damage can be eligible for a reduction in their fine, potentially by up to forty percent. The authority and responsibility concerning privacy enforcement are also expanded. Companies with annual revenues exceeding eighteen hundred billion won that process the personal data of one million or more people, or handle sensitive or unique identifying information for fifty thousand or more individuals, must obtain board approval before appointing, changing, or dismissing a chief privacy officer, with the decision reported to the Personal Information Protection Commission. This heightened oversight extends to institutions such as universities with twenty thousand or more students, tertiary general hospitals, and operators of major public systems. The Personal Information Protection Commission Chairperson, Song Kyung-hee, articulated the goal of this revision, emphasizing the expectation that companies will transition their perspective on data protection from a cost center to a mechanism that builds customer trust and expands corporate profit. |