Compliance · · 3 min read
South Korea introduces tougher penalties for repeat data breaches
Revised privacy rules raise potential fines, expand breach notifications and give companies reductions when they invest in prevention and respond quickly.
South Korea has brought in a revised data-protection regime that can penalise companies with fines reaching 10% of their total revenue in serious cases. The measures target repeat breaches, failures to follow corrective orders and incidents linked to intent or gross negligence, while offering substantial reductions to organisations that have invested in protecting personal information.
The Personal Information Protection Commission said on the 10th that the amended Personal Information Protection Act and its revised enforcement decree would take effect the following day. According to reporting by en.sedaily.com, the changes are intended both to deter large-scale leaks and to encourage businesses to strengthen their security before an incident occurs.
Higher penalties for serious or repeated failures
The maximum fine applies when a company commits a similar violation again within three years through intent or gross negligence, when more than 10 million people are harmed, or when another breach occurs after the organisation has ignored a corrective order. The eventual penalty will reflect the nature of the breach and the extent of the damage.
The rules also increase the additional surcharge applied to repeat violations. A first repeat offence can attract a surcharge of 20%, rising to 40% for a second repeat and 80% for a third or subsequent repeat. The previous rates were 15% for a first repeat and 30% for two or more repeats.
Businesses that fail to report and notify people within the required period, while also failing to limit the spread of the damage, can face an extra charge of up to 30%. The provision links the consequences not only to the original security failure but also to how an organisation handles the incident once it becomes aware of it.
The commission is also widening the circumstances in which users must be told about a possible breach. Notification is required when an exposure is judged objectively to be highly probable, even if investigators have not established conclusively that data was taken.
That obligation begins within 72 hours of a company learning about suspected illegal access to a personal-information system. It also applies when some personal information has been unlawfully traded and there is a possibility that data belonging to other users was exposed. The revised rules additionally cover the forgery, alteration or destruction of personal information.
Prevention can reduce the bill
The framework is designed to distinguish between companies that neglect security and those that can demonstrate sustained preventive work. Regulators may reduce the base fine by as much as 40% after considering the amount and proportion of a company’s spending on security budgets, personnel, facilities and equipment.
The assessment can also take account of whether those investments have continued or grown, and whether the organisation has established a protection structure involving its chief executive, chief privacy officer and specialist employees. A separate reduction of up to 40% may be available to a company with an incident-response system that detects a breach early, reports and notifies promptly, and acts to contain further harm.
The approach makes preparedness a factor in calculating sanctions rather than treating every breach in the same way. It also places pressure on firms to maintain security programmes over time, instead of increasing spending only after an incident has occurred.
Greater responsibility for senior management
The revised law expressly identifies the chief executive as ultimately responsible for data protection and gives the chief privacy officer broader authority over specialist staff and relevant budgets. For certain large organisations, the board must approve the appointment, replacement or dismissal of the chief privacy officer, and the organisation must report the decision to the commission.
The board-level requirement covers businesses with annual revenue or income above 180 billion won that handle personal information belonging to at least 1 million people. It also applies to organisations processing sensitive or unique identifying information for 50,000 or more people. Universities with at least 20,000 enrolled students, tertiary general hospitals and operators of major public systems are included as well.
The commission’s chairperson, Song Kyoung-hee, said the revised rules should promote a prevention-led approach and a stronger system for managing safety. She argued that spending on privacy protection should be viewed as an early investment in customer trust and business growth, rather than simply an expense.
For companies, the changes therefore create two parallel incentives: failures involving large numbers of people or repeated disregard for regulatory action can become considerably more costly, while documented investment, effective leadership and rapid incident response can reduce the eventual penalty.