South Korea's Personal Information Protection Commission announced on Thursday that companies responsible for data breaches affecting over 10 million individuals will soon face enhanced penalties. This decision follows several high-profile incidents, notably an attack on e-commerce platform Coupang that compromised the data of more than 37 million users.
The new measures are part of the government's broader push to strengthen personal data safeguards. According to the commission, the revised Personal Information Protection Act will take effect on Friday.
Under the updated rules, firms found to have caused large-scale leaks through intentional misconduct or gross negligence could be fined up to 10% of their annual sales. The same penalty applies to companies that repeatedly violate data protection laws within a three-year period, or those that fail to comply with corrective orders, leading to a breach.
Previously, the maximum fine stood at just 3% of sales. However, the regulatory body noted that penalties could be reduced by up to 40% for businesses that demonstrate adequate investments in personal information protection and other security measures, with the final amount determined based on a comprehensive review of the circumstances.