South Korea's personal information protection regulator announced on Thursday that stricter punitive measures will take effect this week, targeting companies that suffer data breaches affecting over 10 million individuals. This action follows a series of high-profile incidents, including a leak at e-commerce platform Coupang that impacted more than 37 million users, prompting the government to strengthen data security regulations.
The revised Personal Information Protection Act is scheduled to come into force on Friday, according to the Personal Information Protection Commission. Companies found responsible for such large-scale breaches due to intentional misconduct or gross negligence could face administrative fines up to 10% of their annual sales.
The same heightened penalty applies to businesses that have repeatedly violated data protection laws within the past three years or that have failed to comply with corrective orders, thereby resulting in a leak. Under the previous legal framework, the maximum fine was limited to 3% of sales.
The regulator noted, however, that companies investing heavily in personal information protection and other security measures may be eligible for a reduction of up to 40% of the imposed fine, allowing for some degree of leniency based on their proactive safeguards.