· via Hacker News – Front Page (native)
Korea raises negligent data breach fines to 10 percent of annual revenue
Korea's privacy regulator can now fine companies up to 10 percent of annual revenue for grossly negligent data breaches, up from 3 percent, with 72-hour notification duties and fine discounts for prior security investment.

What the new rules do
South Korea's privacy regulator can now impose fines of up to 10 percent of a company's annual revenue for serious data breaches, a sharp increase from the previous ceiling of 3 percent of sales, according to Korea JoongAng Daily. The change is part of a broader overhaul under the revised Personal Information Protection Act, which took effect Friday together with its enforcement decree.
The maximum penalty applies to leaks of personal data belonging to 10 million or more people that result from intent or gross negligence. The decree narrows the full cap further: it is reserved for companies that repeatedly commit intentional or grossly negligent violations within three years, or that ignored a regulator's corrective order and then suffered a breach as a consequence. Penalties are weighed against the nature and severity of the violation, the surrounding circumstances and the scale of the damage.
Personal Information Protection Commission (PIPC) Secretary General Yang Cheong-sam told reporters that breaches had recently occurred repeatedly and grown in scale in sectors tied closely to daily life, such as retail and telecommunications, and that the system was redesigned both to hold serious violations accountable and to prevent incidents from happening in the first place.
A Coupang-sized yardstick
The scale becomes concrete against a real case. In June, e-commerce company Coupang was fined 624.6 billion won ($466.3 million) after leaking the personal data of 37.55 million people. Applied to that case, the new standard could have pushed the penalty into the trillions of won, though actual fines will still depend on intent, negligence, the scale of damage and mitigating factors, the report notes.
Discounts for preparation
The revised framework rewards companies that took data protection seriously before an incident. Regulators will consider the scale and continuity of spending on data protection budgets, staffing and equipment, along with the company's wider protection system, including its chief privacy officer, and can reduce a fine by as much as 40 percent. A separate reduction of up to 40 percent is available to companies that detect a breach early, report and notify users promptly, and keep the damage from spreading.
72-hour notifications, even for suspected leaks
A new potential data breach notification system extends duties beyond confirmed incidents. If a company judges there is a high likelihood that personal data was exposed, for example after illegal access to its data processing systems, or after discovering illegally traded data that suggests other records leaked as well, it must notify affected individuals within 72 hours of learning of it. Data that is forged, altered or damaged by ransomware and similar attacks now falls under the same reporting and notification requirements.
Privacy officers move up the org chart
Chief privacy officers at major organizations gain authority and accountability. Companies with annual revenue above 180 billion won that process the personal data of at least 1 million people, or the sensitive or uniquely identifying information of at least 50,000, must obtain board approval before appointing, changing or dismissing a chief privacy officer, and must report the decision to the PIPC. Universities with 20,000 or more students, tertiary general hospitals and operators of major public systems fall under the same requirement.
Why it matters
PIPC Chairperson Song Kyung-hee said the regulator expects companies to stop viewing data protection as a cost and start treating it as a proactive investment that builds customer trust and corporate profit. The economics now back that framing: the downside for a grossly negligent mega-breach has jumped from a material expense to, for a large platform, potentially a company-threatening one, while documented prior investment and rapid response can together cut penalties sharply. For any company handling Korean users' data, security budgets, incident-response plans and board-level privacy governance are no longer optional overhead but direct levers on regulatory exposure. The 10 percent ceiling also places Korea among the strictest data protection regimes anywhere, exceeding the EU GDPR's maximum of 4 percent of global turnover, and points to a direction other regulators may follow.
- #privacy
- #data-protection
- #south-korea
- #regulation
- #compliance