Korea to Fine Firms Up to 10% of Revenue for Repeat Data Breaches

Tougher Penalties for Intentional, Repeated or Large-Scale Leaks Up to 40% Reduction for Preventive Investment and Rapid Response CPO Authority Strengthened, Reporting to Privacy Watchdog Mandatory

Technology|
|
By Noh Hyun-seophit8129@sedaily.com
||
Yang Cheong-sam, secretary general of the Personal Information Protection Commission, speaks at a briefing at the Government Complex Seoul on Oct. 10. Photo courtesy of the Personal Information Protection Commission - Seoul Economic Daily Technology News from South Korea
Yang Cheong-sam, secretary general of the Personal Information Protection Commission, speaks at a briefing at the Government Complex Seoul on Oct. 10. Photo courtesy of the Personal Information Protection Commission

A punitive fine system that allows penalties of up to 10% of a company's total revenue takes effect for firms that repeat large-scale data breaches or, through intent or gross negligence, cause damage to more than 10 million people. Companies that invested heavily in budget, staff and security equipment for data protection before an incident, by contrast, can have the base fine reduced by up to 40%. The measures aim to toughen sanctions on data leaks while encouraging companies to invest in prevention.

The Personal Information Protection Commission said on the 10th that the revised Personal Information Protection Act, amended in March, and the revised enforcement decree specifying its delegated provisions take effect on the 11th, in a move to prevent data breaches and strengthen the protection of personal information and remedies for victims.

Under the revised law, fines of up to 10% of total revenue can be imposed — taking into account the nature of the violation and the scale of damage — when a company repeats a violation within three years through intent or gross negligence, causes damage to more than 10 million people, or suffers a data breach after failing to comply with a corrective order. The surcharge rate for repeat violations also rises to 20% for a first repeat, 40% for a second and 80% for a third or more, from the previous 15% for a first and 30% for two or more. Failing to report and notify a breach within the statutory deadline while also failing to take steps to prevent the damage from spreading adds up to 30%.

Preventive efforts by companies, on the other hand, will be actively reflected in calculating fines. The base fine can be cut by up to 40% based on an assessment of the scale and share of investment in budget, staff, facilities and equipment for data protection, the continuity and growth of that investment, and the protection framework made up of the chief executive officer, the chief privacy officer (CPO) and specialist staff. A reduction of up to 40% also applies when a company has built an incident response system and, after a breach, detects it early, reports and notifies promptly, and takes steps to prevent the damage from spreading.

Corporate accountability for data protection is also being strengthened. The revised law spells out the CEO's ultimate responsibility and expands the CPO's authority to manage specialist staff and secure related budgets. Companies and institutions above a certain size must obtain board approval and report to the commission when they appoint, change or dismiss a CPO. The requirement applies to businesses with annual revenue or income exceeding 180 billion won that handle personal information on 1 million or more people, or sensitive or unique identifying information on 50,000 or more, as well as universities with 20,000 or more enrolled students, tertiary general hospitals and operators of major public systems.

The standard for notifying users of a data breach is also being broadened. Companies must now inform users when a leak is objectively judged to be highly likely, even if an actual leak has not been definitively confirmed. When illegal access to a personal information processing system raises suspicion of a leak, or when some personal information has been traded illegally and other users' data may also have been exposed, notification must be made within 72 hours of learning of the fact. Forgery, alteration or destruction of personal information is also now subject to reporting and notification.

"With the enforcement of these revised rules, we expect a prevention-focused approach to data protection and a strengthened safety management framework to take hold, and for investment in data protection to be seen not as a 'cost' but as a 'pre-emptive investment' to secure customer trust and expand corporate profits," said Song Kyoung-hee, chairperson of the Personal Information Protection Commission.

Original reporting by Noh Hyun-seop for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
2:20

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.