South Korea’s Personal Information Protection Commission (PIPC) is increasing the maximum penalty for serious data breaches from three percent of sales to up to ten percent of a company’s total revenue, according to the source. The change takes effect on Friday as part of a revised Personal Information Protection Act and its enforcement decree. The higher fine applies when a company leaks the personal data of ten million or more people through intent or gross negligence, or when it repeatedly commits intentional or grossly negligent violations within three years, or fails to comply with a corrective order and subsequently suffers a breach. Fines will be calculated based on the nature and severity of the violation, the circumstances involved, and the scale of the damage, the source says. Under the previous regime, the maximum penalty was three percent of sales. The source illustrates the potential impact by referencing a June fine against e‑commerce firm Coupang, which was levied at 624.6 billion won (about $466.3 million) after leaking data of 37.55 million people. Applying the new ten‑percent standard to that case could push the fine into the trillions of won, though actual penalties will still depend on intent, negligence, damage scale, and any mitigating factors. Companies that have invested in data protection beforehand may receive credit; regulators will consider the scale and continuity of a company’s data‑protection budget, staffing, equipment, and overall protection system—including the role of a chief privacy officer—to reduce a fine by up to forty percent. Additionally, a company that detects a breach early, reports it promptly, and notifies users can also earn up to a forty percent reduction. The revision also introduces a “potential data breach notification system.” If a company determines there is a high likelihood that personal data was exposed—such as after illegal access to its data‑processing systems or after discovering that some personal data was illegally traded in a way that suggests others’ data may have leaked—it must notify affected individuals within seventy‑two hours of learning that. Data that is forged, altered, or damaged by ransomware or similar attacks is now subject to the same reporting and notification requirements. The authority and responsibility of chief privacy officers at major companies and institutions will also expand. Companies with annual revenue exceeding 180 billion won that process the personal data of one million or more people, or the sensitive or unique identifying information of fifty thousand or more people, must obtain board approval before appointing, changing, or dismissing a chief privacy officer and must report the decision to the PIPC. Universities with twenty thousand or more students, tertiary general hospitals, and operators of major public systems fall under the same requirement. PIPC Chairperson Song Kyung‑hee said the regulator expects companies to shift from viewing data‑protection investment as a cost to treating it as a proactive investment that builds customer trust and expands corporate profit.

