LmCast :: Stay tuned in

Korea raises data breach fines to 10% of revenue

Recorded: Sept. 18, 2026, 9:09 p.m.

Original Summarized

South Korea raises data breach fines to 10% of revenue

Jump to main content

Newsletter

Print Edition

K-campus

Korea

Business

Lifestyle

Entertainment

Sports

Opinion

World

Search

Korea

Politics

Social Affairs

North Korea

Diplomacy

Defense

Environment

K-campus

Business

Industry

Economy

Tech

Money

Games and Webtoons

Guest Reports

Lifestyle

Food and Travel

Life and Trends

Arts and Books

Music and Theater

Korean Heritage

Entertainment

K-pop

TV and Streaming

Movies

Sports

Football

Baseball

Golf

Volleyball

Basketball

Tennis

Olympic Sports

More

Opinion

Editorials

Columns

Cartoons

Letters

Voices

World

Bilingual News

KJD Special

Why

Live

Newsletters

Multimedia News

Video

Photo

Audio

Search

Newsletter

Print Edition

K-campus

x

fb

ig

yt

naver

in

Korea

Politics

Social Affairs

North Korea

Diplomacy

Defense

Environment

K-campus

Business

Industry

Economy

Tech

Money

Games and Webtoons

Guest Reports

Lifestyle

Food and Travel

Life and Trends

Arts and Books

Music and Theater

Korean Heritage

Entertainment

K-pop

TV and Streaming

Movies

Sports

Football

Baseball

Golf

Volleyball

Basketball

Tennis

Olympic Sports

More

Opinion

Editorials

Columns

Cartoons

Letters

Voices

World

Bilingual News

KJD Special

Why

Live

Newsletters

Multimedia News

Video

Photo

Audio

Korea raises data breach fines to 10% of revenue

Companies behind major negligent data leaks can now face fines of up to 10 percent of annual revenue under revised privacy rules.

News Team

News
Team

Published
September 10, 2026 - 4:16 p.m.

Modified
September 10, 2026 - 7:00 p.m.

Personal Information Protection Commission Chairperson Song Kyung-hee speaks during a plenary session of the watchdog at the government complex in Jongno District, central Seoul, on Sept. 9.
YONHAP

Korea's privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence can be fined up to 10 percent of their total revenue as part of a broader overhaul under the revised Personal Information Protection Act that is set to take effect the same day. Even if a leak hasn't been confirmed, companies must notify users within 72 hours if the risk of exposure is high. “Personal data breaches have recently occurred repeatedly and grown in scale in fields closely tied to daily life, such as retail and telecommunications,” Personal Information Protection Commission (PIPC) Secretary General Yang Cheong-sam told reporters Thursday. “We've improved the system to hold serious violations strictly accountable while also helping prevent breaches from happening in the first place.”

Related Article

Korea to introduce strengthened penalties for large-scale data leaks

Gender Ministry considers criminal charges against Google over leaked victim data

As U.S. and Europe hit gas on Chinese smart car restrictions, Korea sits at red light

Under the enforcement decree, the cap applies to companies that repeatedly commit intentional or grossly negligent violations within three years, or that fail to comply with a corrective order and go on to suffer a breach as a result. Fines are calculated based on the nature and severity of the violation, the circumstances involved and the scale of the damage.Before the revision, companies were subject to a penalty of up to 3 percent of sales.The gap between the old and new rules becomes clear when applied to a real case. Local e-commerce giant Coupang was fined 624.6 billion won ($466.3 million) in June after leaking the personal data of 37.55 million people. Applying the new standard to that case could push the fine into the trillions of won. However, actual penalties will still depend on intent, negligence, the scale of damage and any mitigating factors.

Coupang’s headquarters in Songpa District, southern Seoul.
NEWS1

Companies that invested in data protection beforehand will get credit under the new rules. Regulators will consider the scale and continuity of a company's investment in data protection budgets, staffing and equipment, along with its broader protection system, including its chief privacy officer, to reduce a fine by up to 40 percent. A company that detects a breach early, reports and notifies users promptly, and prevents the damage from spreading can also receive up to a 40 percent reduction.The revision also introduces a “potential data breach notification system.” If a company determines there is a high likelihood that personal data was exposed — for instance, after illegal access to its data processing systems, or after discovering that some personal data was illegally traded in a way that suggests others' data may have leaked too — it must notify affected individuals within 72 hours of learning that. Data forged, altered or damaged by ransomware and similar attacks is now also subject to the same reporting and notification requirements.The authority and responsibility of chief privacy officers at major companies and institutions will also expand. Companies with annual revenue exceeding 180 billion won that process the personal data of 1 million or more people, or the sensitive or unique identifying information of 50,000 or more people, must get board approval before appointing, changing or dismissing a chief privacy officer and report the decision to the PIPC. Universities with 20,000 or more students, tertiary general hospitals and operators of major public systems fall under the same requirement.“We expect the way companies view investment in data protection to shift from seeing it as a cost to treating it as a proactive investment that builds customer trust and expands corporate profit,” PIPC's Chairperson Song Kyung-hee said. BY HAN EUN-HWA [lee.jian@joongang.co.kr]

This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.

personal information protection commission
personal information
industry
data leak
business

Read more

SK chair pays $578,000 to appeal property division settlement
SK Group Chairman Chey Tae-won paid about 850 million won ($577,800) in filing fees to appeal a 944 billion won property division order involving former wife Roh Soh-yeong.

Naver Cloud pitches sovereign AI system to transform Korean military operations
Naver Cloud outlined a sovereign AI strategy to help South Korea’s military process battlefield information faster while keeping final operational decisions in human hands.

SK hynix’s Solidigm weighs New York NAND factory
The U.S.-based unit is considering a NAND chip plant in upstate New York as Washington presses for more domestic semiconductor production.

Samsung Exynos share climbs to 9 percent in Q2
Samsung's Exynos smartphone processor shipments reached their highest share since 2024, aided by Galaxy S26 and midrange Galaxy models.

See more articles

South Korea tops Pool D after four-set victory over Vietnam at Asian Games women's volleyball

Korea storms into Asian Games basketball final

U.S. ambassador calls alliance with South Korea linchpin of Indo-Pacific peace and security

National Museum of Korea draws 5 million visitors at record pace

Bows, guns and swords: South Korea's weapons of choice in war for 40 Asian Games golds

Wayne Thiebaud’s cakes arrive in Seoul, revealing an artist who painted order beneath every sweet surface

SK chair pays $578,000 to appeal property division settlement

Yeon Sang-ho says mother inspired new thriller 'Paradise Lost'

About Company Contact Us Newsletter Advertising Work For Us FAQ Notice Ombudsman

Terms of Use Copyright Policy Privacy Policy Juvenile Protection Policy

x
fb
ig
yt
naver
in

All materials contained on this site are protected by Korean copyright law and may not be reproduced, distributed, transmitted, displayed, published or broadcast without the prior consent of the JoongAng Ilbo | Tel: 1577-0510
JoongAng Ilbo Co., Ltd. | Address: 48-6 Sangamsan-ro, Mapo-gu, Seoul, Republic of Korea
Business registration number: 110-81-00999 | CEO & Publisher: Park Chang-hee | Executive Editor: Choi Ji-young
Mail order business report number: 2020-Seoul Mapo-3838 | Online newspaper registration No: 서울,아55177
Date of Registration: 2023. 11. 21 | Juvenile Protection Manager: Park Hyunyoung

South Korea has implemented a significant overhaul of its privacy regulations by substantially increasing the penalties for data breaches, aiming to fundamentally shift corporate behavior toward viewing data protection as a proactive investment rather than merely an operational cost. Currently, companies that cause leaks of personal data belonging to ten million or more individuals through intent or gross negligence face potential fines up to ten percent of their total annual revenue. This change is enacted under the revised Personal Information Protection Act, effective immediately.

The revision introduces stricter accountability measures. Penalties are calculated based on the nature and severity of the violation, the specific circumstances involved, and the scale of the resulting damage. This new framework applies to companies that repeatedly violate data protection rules over a three-year period or those who fail to comply with corrective orders and subsequently suffer a breach. The potential financial impact is substantial; for instance, applying the new standard to a case involving a major e-commerce company could result in fines reaching into the trillions of won.

In addition to punitive measures, the updated rules mandate proactive notification procedures. Companies must now notify affected users within seventy-two hours if there is a high likelihood that personal data has been exposed, regardless of whether the breach has been fully confirmed. This framework also extends notification requirements to incidents resulting from ransomware attacks, as data damaged or altered by such incidents is now subject to the same reporting obligations. Furthermore, a potential data breach notification system has been established to facilitate this immediate response.

To encourage preventative measures, the revised rules offer mitigation opportunities for companies that invest in data protection measures beforehand. Regulators will assess the extent of a company's investments in data protection budgets, staffing, equipment, and overall protection systems, including the role of the chief privacy officer. Companies that detect a breach early, ensure prompt notification to users, and successfully prevent the spread of damage can be eligible for a reduction in their fine, potentially by up to forty percent.

The authority and responsibility concerning privacy enforcement are also expanded. Companies with annual revenues exceeding eighteen hundred billion won that process the personal data of one million or more people, or handle sensitive or unique identifying information for fifty thousand or more individuals, must obtain board approval before appointing, changing, or dismissing a chief privacy officer, with the decision reported to the Personal Information Protection Commission. This heightened oversight extends to institutions such as universities with twenty thousand or more students, tertiary general hospitals, and operators of major public systems. The Personal Information Protection Commission Chairperson, Song Kyung-hee, articulated the goal of this revision, emphasizing the expectation that companies will transition their perspective on data protection from a cost center to a mechanism that builds customer trust and expands corporate profit.