South Korea's privacy regulator, the Personal Information Protection Commission (PIPC), has enacted a new policy increasing the maximum fine for data breaches. Companies found responsible for leaking the personal data of 10 million or more individuals, through intent or gross negligence, can now face fines up to 10% of their total revenue. This revised Personal Information Protection Act took effect on Friday.
PIPC Secretary General Yang Cheong-sam stated that the change addresses repeated and large-scale personal data breaches in sectors like retail and telecommunications. The goal is to hold serious violations accountable and prevent future incidents by encouraging companies to view data protection as a necessary investment rather than a routine cost. Companies must also notify users within 72 hours if there is a high risk of data exposure, even if a leak is not yet confirmed.
The 10% revenue cap applies to companies that commit intentional or grossly negligent violations repeatedly within three years, or those that fail to comply with a corrective order, leading to a breach. Fines will be determined based on the violation's nature, severity, circumstances, and the extent of the damage. Previously, the maximum penalty was 3% of sales.
The new standard significantly increases potential penalties. For example, e-commerce company Coupang was fined 624.6 billion won ($466.3 million) under the old rules for leaking 37.55 million people's data. Applying the new standard could result in fines in the trillions of won, though actual penalties will still consider intent, negligence, damage scale, and mitigating factors.
The new regulations also provide incentives for companies that proactively invest in data protection. Regulators will consider a company's budget, staffing, equipment, and overall protection system, including the presence of a chief privacy officer, to reduce fines by up to 40%. Companies that detect, report, and notify users of a breach early will also receive credit.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
South Korea's Personal Information Protection Commission (PIPC) has raised data breach fines to 10% of total revenue for companies that leak personal data of 10 million or more people due to intent or gross negligence. This change, effective Friday, aims to encourage companies to prioritize data protection as a preventive investment.