Key facts
- South Korea will introduce strengthened penalties for large-scale data leaks starting Friday.
- Companies suffering leaks affecting over 10 million people can face penalties up to 10% of their sales.
- The revised law applies to leaks resulting from intentional misconduct or gross negligence.
- Previous penalties were capped at 3% of sales.
- The Personal Information Protection Commission can reduce penalties by up to 40% based on a company's protection investments.
SEOUL, Sept. 10 (Yonhap) -- South Korea is set to implement stricter penalties this week for companies experiencing large-scale personal data breaches, with the revised personal information protection law taking effect Friday. The new regulations target leaks affecting more than 10 million individuals and can impose fines up to 10% of a company's sales in cases of intentional misconduct or gross negligence. This measure aims to bolster personal information protection following significant data breaches, such as the one at e-commerce operator Coupang that impacted over 37 million users. Previously, penalties were capped at 3% of sales. The Personal Information Protection Commission, the regulatory body, stated that penalties could be reduced by up to 40% if companies demonstrate substantial investment in data protection and safety measures. The commission also noted that repeated violations within three years or failure to comply with corrective orders could also trigger the higher penalties.
