[Class Action, the Trap of Excessive Remedies] ①A Single Incident Could Threaten the Existence of SMEs as the "Grave-Digging Law" Brings Retroactive Liability
If Companies Pay 100,000 Won Per Victim for Data Leaks,
Corporate Liabilities Could Reach Hundreds of Billions
9 Out of 10 Data Breach Incidents Occur at SMEs and Mid-Sized Firms
Controversy Over Retroactive Application to Incidents Bef
Modetour, a travel agency, suffered a data breach that exposed the personal information of 3.06 million customers. In the damages lawsuit filed by the victims, the court awarded 100,000 won per person for emotional damages in both the first and second trials. While this amounts to 100,000 won for each individual, applying the same amount to all 3.06 million affected customers would result in total compensation of 306 billion won. This figure is 41.4 times Modetour’s operating profit last year (7.4 billion won) and 3.3 times its equity capital (92.5 billion won). If realized, this is a level of liability that would be difficult for the company to bear through normal business operations alone.
The financial burden increases as a company’s size decreases. The number of individuals affected by the data breach at the educational content provider Class U is about 1.6 million. Applying the same 100,000 won per person standard, the potential compensation liability would be 160 billion won, which is 42.5 times its operating profit of 3.77 billion won in 2024. Compared to its equity capital of 3.38 billion won, the figure is 47.4 times larger. Even if all of its capital were used, the company would only be able to cover a portion of the compensation.
Golfzon also experienced a personal data breach affecting 2.21 million people. Calculating potential compensation in the same way, the company could be liable for 221 billion won, which is 3.2 times last year’s operating profit of 68.1 billion won and about half its equity capital of 438.9 billion won.
This year, TVING experienced a breach affecting 19.53 million people. At 100,000 won per individual, the total would reach 1.953 trillion won. TVING posted an operating loss of 69.8 billion won last year and has equity capital of 206.8 billion won; thus, the potential compensation liability is 9.4 times greater than its equity capital. As deficits continue, this represents a level of risk difficult for the company to manage independently, and without large-scale financing or shareholder support, the business could be threatened.
These calculations are based on applying the 100,000 won per person for emotional damages recognized by the court in the Modetour case to other data breach incidents, allowing for a straightforward comparison of financial impact. In reality, the actual liability and amounts awarded may vary according to the level of harm, the company’s fault, and the court’s judgment in each individual case.
Whether these potential compensation amounts will translate into actual burdens for companies will largely depend on whether a class action system is introduced. Currently, only victims who directly participate in a lawsuit are eligible for compensation. However, if the class action system under discussion in the National Assembly is adopted, the judgment in a suit brought by some victims could be extended to all those affected, even if they did not join the litigation. As a result, in incidents involving tens of thousands or even millions of victims, the scale of damages could surge, sparking concern that the very existence of financially weaker small and medium-sized enterprises could be threatened.
Nine out of Ten Data Breach Incidents Involve SMEs and Mid-sized Companies
According to the National Assembly Research Service and industry sources on August 12, reports of cyber breaches rose nearly threefold from 640 in 2021 to 1,887 in 2024. Last year, 1,473 incidents were reported through August. Nine out of ten breaches occurred at small and medium-sized enterprises (SMEs) and mid-sized companies: in 2024, 1,716 cases or 90.9% of all reports involved such firms, and through August of last year, it was 1,334 cases or 90.6%.
Data breaches occurred regardless of company size or industry. Incidents affected not only major corporations like SK Telecom, KT, LG Uplus, Coupang, and Lotte Card, but also SMEs and mid-sized companies such as Modetour, Golfzon, Class U, Albamon, Li & Li, and Duo. This year, a large-scale breach also occurred at TVING.
The issue is that while risk of incidents is concentrated among SMEs and mid-sized companies, there is a significant gap in their ability to prevent and respond to such events depending on company size. According to the “2024 Information Security Status Survey” by the Korea Information Security Industry Association, 87% of companies with 250 or more employees have dedicated information security teams, but this figure drops to just 26.2% for those with 10 to 49 employees. The proportion with formal information security policies was 98.7% for large firms compared to 48.9% for smaller ones—about a twofold difference.
This explains why companies are highly sensitive to the potential introduction of a class action system. When the government moved to introduce a class action law in 2020, 68.6% of SMEs opposed the proposal in a survey. The Korea Federation of SMEs expressed concern at the time over the prospect of lawsuits or law firms specializing in class actions merely to secure large settlement sums. For SMEs with relatively less legal capacity, the burden of legal fees—even if they ultimately win the case—and the loss of consumer trust simply from being named in a suit, are major concerns.
There are also worries that liability insurance may not adequately serve as a safety net. Companies had previously taken out policies based on the existing compensatory framework. However, if new class action procedures are applied retroactively to incidents that occurred before the legal changes, unforeseen liability risks could arise. The industry worries that a growing amount of contingent liabilities not covered by insurance could hamper both investment and funding for affected companies.
Why 100,000 Won in Damages Becomes Billions
Currently, South Korea’s class action system is limited to the securities sector. The government and ruling party are working to expand the scope to include all damage claims. The class action bill sponsored in March by Park Kyuntaek of the Democratic Party, drafted in consultation with the Ministry of Justice, is regarded as the de facto government proposal. The National Assembly currently has 14 bills related to class actions under review, including this one. Among them, debate is centered on the “opt-out” mechanism and retroactive application, with both the legal community and industry expressing concern, leading to their consideration by the Legislation and Judiciary Committee’s subcommittee.
The key issue for industry is the opt-out system. Under the conventional joint litigation system, only those who directly join a lawsuit are bound by its outcome, so even if there are one million victims, only the 10,000 who participate would be affected by the verdict. The opt-out system is the opposite: unless individuals expressly declare their intent to opt out, they are deemed included and thus bound by the judgment. The bill sponsored by Park stipulates that the decision’s effect should extend to all who do not formally exclude themselves.
For businesses, this means the potential number of claimants could skyrocket. If statutory damages of 100,000 won are awarded, the liability for 10,000 people would be 1 billion won, but for 1 million, it would be 100 billion won. The potential for a massive increase in liability in cases with millions of victims is why this system is so controversial among companies.
There is also controversy over victims’ right to self-determination. The court’s decision could apply to victims who may not even be aware that litigation is ongoing. The National Court Administration has also advised caution, pointing out that some people may be included in lawsuits without sufficient knowledge, or be unable to exercise their rights, potentially infringing on their right to a fair trial.
Past Cases to Be Included, Industry Calls the Law a "Grave-Digging Bill"
The biggest point of contention is whether the new rules will be applied retroactively. This would allow new class action procedures to be applied to incidents that occurred before the effective date of the law. The reason some are derisively referring to the class action law as a “Grave-Digging Bill” is that incidents already resolved or being handled under previous laws and policies could resurface as new class action cases.
Amid growing controversy, the National Assembly’s Legislation and Judiciary Committee is currently considering applying the new law to events occurring within three years prior to its enforcement date, primarily based on Park’s bill. The ruling party’s position is that as long as the statute of limitations has not expired and no final result has been reached, retroactive application is possible. This means incidents—such as recent data breaches—where compensation claims are still pending could become subject to the new procedures.
However, the Constitution prohibits the deprivation of property rights via retroactive legislation. If the new system is applied to previous incidents, companies may face unforeseen compensation liabilities, which is why experts call for prudent consideration of retroactive application.
Industry concerns mainly center on the predictability of management. Businesses manage risk based on the legal compensatory regime and insurance coverage in effect at the time an incident occurs. If new procedures increase the potential claimants for past events, companies could face unforeseen financial burdens. The industrial sector argues that applying new procedures solely because the civil statute of limitations has not expired is a separate issue and that this could increase legal uncertainty.
There are differences with existing legislative precedents. The class action system for securities, implemented in 2005, applied only to actions occurring after the law came into force. Punitive damages under the Subcontracting Act and the Product Liability Act also apply only to violations or products supplied after those laws’ effective dates. The Statutory Damages Clause under the Credit Information Act and punitive/statutory damages under the Personal Information Protection Act also apply only to information leaks occurring after those laws were enacted.
Nevertheless, there are moves to apply the new law retroactively to past cases—unlike traditional legislative practice—without sufficient review of the financial implications for businesses. A staff member at Park’s office stated, “Neither our office nor the party has yet conducted an impact assessment on the effects for small and medium-sized companies.”
Hot Picks Today
[Exclusive] Hyundai Motor Retirees Face Crackdown on “Car-Tech”...25% Discount Benefits Also Taxed
- Will Health Insurance Premiums Rise Next Year After Five Years of Surplus End? ... Additional Premiums for Interest and Dividend Income Possible [Why&Next]
- "Though He Was a Student Like Ahn Sangho"... Kim Iknam, Who Took a Different Path Amid Controversy Over the Actress's Great-Grandfather's Pro-Japanese Past
- Chey Taewon and Noh Soyoung Face Deadline for 944 Billion Won Asset Division... Final Appeal Closes at Midnight Today
- 7,000 Stranded at Airport, Many Koreans Among Them... Emergency as Record-Breaking Rain Hits Greater Tokyo Area
Kwon Yongsoo, professor at Konkuk University Law School, commented, “Small and medium-sized companies that actively invest and take on challenges face much higher risks,” adding, “If class actions are applied retroactively, it could pose a threat to management.” He expressed support for the system’s goals of victim compensation and public interest, while also cautioning, “It is necessary to also consider the impact on other stakeholders, such as shareholders, employees, creditors, and local communities.”
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.