Back
South Korea raises data-breach fines to 10 percent of revenue
SiTech AI Team3 წთ. საკითხავი

South Korea raises data-breach fines to 10 percent of revenue

Under a revised privacy law, Korean companies that leak the personal data of ten million or more people through intent or gross negligence can now be fined up to 10 percent of total revenue.

South Korea's privacy regulator is sharply raising the cost of large data breaches, aiming to push companies into treating data protection as a preventive investment rather than a routine cost of doing business. Starting Friday, a company found to have leaked the personal data of ten million or more people through intent or gross negligence can be fined up to 10 percent of its total revenue under the revised Personal Information Protection Act.

Who the cap applies to

Under the enforcement decree, the ceiling applies to companies that repeatedly commit intentional or grossly negligent violations within three years, or that fail to comply with a corrective order and then suffer a breach as a result. Fines are calculated from the nature and severity of the violation, the circumstances involved and the scale of the damage. Before the revision, the maximum was 3 percent of sales.

What it means in practice

The gap between the old and new rules is visible in a real case. E-commerce giant Coupang was fined 624.6 billion won, or $466.3 million, in June after leaking the personal data of 37.55 million people; under the new standard that penalty could run into the trillions of won, although the actual fine will still depend on intent, negligence, the scale of damage and mitigating factors.

Companies that invested in protection beforehand get credit. Regulators will weigh the scale and continuity of investment in data protection budgets, staffing and equipment, together with the broader protection system including the chief privacy officer, and can reduce a fine by up to 40 percent. A company that detects a breach early, reports and notifies users promptly and prevents the damage from spreading can receive a further reduction of up to 40 percent.

Earlier warnings and stronger privacy officers

The revision also introduces a "potential data breach notification system". If a company determines there is a high likelihood that personal data was exposed — for instance after illegal access to its data processing systems, or after discovering that some personal data was illegally traded in a way suggesting others' data may have leaked too — it must notify affected individuals within 72 hours of learning of it.

Chief privacy officers at large organisations gain authority and responsibility too. Companies with annual revenue above 180 billion won that process the personal data of a million or more people, or the sensitive or unique identifying information of 50,000 or more people, must get board approval before appointing, changing or dismissing a privacy officer and report the decision to the commission. Universities with 20,000 or more students, tertiary general hospitals and operators of major public systems face the same requirement. Commission chairperson Song Kyung-hee said she expects companies to begin treating data protection as a proactive investment that builds customer trust rather than as a cost.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.