South Korea Scales Data Breach Fines to 10% of Revenue

AI-generated image · US National Wire
New privacy rules shift data protection from a routine business cost to a material P&L risk for major firms.
South Korea has significantly increased the financial penalties for large-scale data leaks, moving the maximum fine from 3 percent of sales to up to 10 percent of total annual revenue. According to reporting from Korea JoongAng Daily, the revised Personal Information Protection Act took effect Friday.
The new rules target companies that leak the personal data of 10 million or more individuals through gross negligence or intent. The Personal Information Protection Commission (PIPC) is implementing these changes to compel companies to view data security as a preventive investment rather than a standard cost of business. PIPC Secretary General Yang Cheong-sam noted that breaches have grown in scale within the telecommunications and retail sectors.
To illustrate the impact, Korea JoongAng Daily noted that e-commerce giant Coupang was fined 624.6 billion won ($466.3 million) in June for leaking the data of 37.55 million people; under the new standards, such a fine could potentially reach into the trillions of won.
Companies can mitigate these risks through proactive investment. PIPC Chairperson Song Kyung-hee stated the goal is to shift corporate perspectives toward investments that build customer trust. Regulators may reduce fines by up to 40 percent based on a company's staffing, equipment, and data protection budgets. An additional 40 percent reduction is available for companies that detect breaches early and notify users promptly.
The overhaul also introduces a "potential data breach notification system," requiring companies to alert users within 72 hours if there is a high likelihood of exposure. Furthermore, companies with annual revenue over 180 billion won that process data for 1 million or more people must now obtain board approval before appointing or dismissing a chief privacy officer.

