Korea raises data breach fines to 10% of revenue
3 hours ago
- Korea's privacy regulator raises maximum fine for data breaches to 10% of revenue, up from 3%.
- The new rules apply to intentional or grossly negligent leaks of personal data of 10 million or more people.
- Companies must notify users within 72 hours if there's a high risk of data exposure, even without a confirmed leak.
- Penalties can be reduced by up to 40% for prior investment in data protection and another 40% for early detection and prompt response.
- New mandatory notification requirements cover potential breaches, including illegal access and ransomware attacks.
- Chief privacy officers at large companies require board approval and PIPC reporting for appointments, changes, or dismissals.
- The revision aims to shift company perspective from seeing data protection as a cost to a proactive investment.
- Example: Coupang's fine for leaking 37.55 million people's data could exceed the previous 624.6 billion won under the new standard.