← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

South Korea increases data breach fines to 10% of revenue for major incidents

🔄 Updated 5d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Fines for data breaches increased to 10% of total revenue.
  • Applies to leaks affecting 10 million+ people due to intent/gross negligence.
  • Companies must notify users within 72 hours if high risk of exposure.
  • Previous maximum fine was 3% of sales.

New Fine Structure Implemented

South Korea's privacy regulator, the Personal Information Protection Commission (PIPC), has enacted a new policy increasing the maximum fine for data breaches. Companies found responsible for leaking the personal data of 10 million or more individuals, through intent or gross negligence, can now face fines up to 10% of their total revenue. This revised Personal Information Protection Act took effect on Friday.

Rationale Behind the Change

PIPC Secretary General Yang Cheong-sam stated that the change addresses repeated and large-scale personal data breaches in sectors like retail and telecommunications. The goal is to hold serious violations accountable and prevent future incidents by encouraging companies to view data protection as a necessary investment rather than a routine cost. Companies must also notify users within 72 hours if there is a high risk of data exposure, even if a leak is not yet confirmed.

Conditions for Maximum Penalties

The 10% revenue cap applies to companies that commit intentional or grossly negligent violations repeatedly within three years, or those that fail to comply with a corrective order, leading to a breach. Fines will be determined based on the violation's nature, severity, circumstances, and the extent of the damage. Previously, the maximum penalty was 3% of sales.

Impact on Fines

The new standard significantly increases potential penalties. For example, e-commerce company Coupang was fined 624.6 billion won ($466.3 million) under the old rules for leaking 37.55 million people's data. Applying the new standard could result in fines in the trillions of won, though actual penalties will still consider intent, negligence, damage scale, and mitigating factors.

Incentives for Data Protection Investment

The new regulations also provide incentives for companies that proactively invest in data protection. Regulators will consider a company's budget, staffing, equipment, and overall protection system, including the presence of a chief privacy officer, to reduce fines by up to 40%. Companies that detect, report, and notify users of a breach early will also receive credit.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

South Korea's Personal Information Protection Commission (PIPC) has raised data breach fines to 10% of total revenue for companies that leak personal data of 10 million or more people due to intent or gross negligence. This change, effective Friday, aims to encourage companies to prioritize data protection as a preventive investment.