RC RANDOM CHAOS

South Korea can now fine data breaches up to 10% of total revenue

· via Hacker News

Original source

Korea raises data breach fines to 10% of revenue

Hacker News →

South Korea’s Personal Information Protection Commission has more than tripled its maximum penalty for data breaches, raising the cap from 3 percent of sales to 10 percent of a company’s total revenue. Effective Friday under the revised Personal Information Protection Act, the top fine applies when a firm leaks the data of 10 million or more people through intent or gross negligence — specifically repeat offenders within a three-year window or companies that ignore a corrective order and are then breached. The regulator’s stated goal is to make data protection a preventive investment rather than an accepted cost of doing business.

The scale of the shift is easiest to grasp against a live case: Coupang was fined 624.6 billion won (about $466 million) in June after exposing the records of 37.55 million people. The same breach under the new standard could theoretically reach into the trillions of won, though actual fines still turn on intent, negligence, damage, and mitigation. To reward diligence, the rules offer up to a 40 percent reduction for sustained investment in security staffing, budget, and a proper chief privacy officer, plus another possible 40 percent cut for detecting a breach early and notifying users quickly.

The overhaul also adds a “potential breach” notification duty: if a company has strong reason to believe data was exposed — after illegal system access, or signs that stolen data is being traded — it must tell affected users within 72 hours, and ransomware-driven tampering now triggers the same requirement. Governance rules tighten too, with large firms, major hospitals, and big universities required to get board approval and notify the PIPC when appointing or removing a chief privacy officer.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.