Heavy Fines for Personal Data Leaks... Notification Required Even for Potential Breaches, CPO Accountability Reinforced
Amended Personal Information Protection Act and Enforcement Decree Effective from September 11
Up to 10% of Total Sales Fined for Repeated or Large-Scale Data Breaches
Notification Required Within 72 Hours Even If Leak Not Yet Confirmed
Board Approval and Commission Reporting Mandatory for CPO Appointments and Changes
Going forward, companies and institutions that repeatedly leak personal information due to intentional acts or gross negligence, or cause large-scale damages, will be subject to punitive fines of up to 10% of their total sales. Even if a leak has not been definitively confirmed, the public must be notified at the early stage when the likelihood is high, and organizations are required to report to the authorities with the approval of the board of directors whenever a Chief Privacy Officer (CPO) is appointed or changed.
The Personal Information Protection Commission announced on September 10 that amendments to the Personal Information Protection Act and its enforcement decrees and notifications, containing these core provisions, will come into full effect starting September 11. This high-intensity measure aims to address mounting public anxiety caused by a series of large-scale personal information leaks, both in the public and private sectors.
The amended law provides both strong post-violation sanctions and preventive incentives. In cases where a company or organization repeats violations with intent or gross negligence within three years, or is responsible for a large-scale breach involving more than 1,000 individuals, administrative fines may be imposed up to 10% of total sales, with the exact figure determined by considering damage size and aggravating or mitigating factors. The aggravation ratio for repeated violations has also been raised to a maximum of 80%.
At the same time, the law takes into account proactive efforts such as ongoing investments in budget, personnel, and facilities for personal information protection. The amendment allows up to a 40% reduction of the base amount of administrative fines when an organization demonstrates a robust protection system and strong security measures. However, major public institutions that handle mandatory collection and management of citizens' data cannot receive fine reductions merely due to the size or nature of their operations, as the law emphasizes the greater public responsibility they bear.
The system to guarantee the right of data subjects to defend themselves at the initial stage of an incident has also been reformed. Previously, notification was only required when a leak was finally confirmed, but from now on, organizations must inform the public within 72 hours if it is reasonably determined that the possibility of a leak is objectively high. Notification items have been expanded beyond the type of personal data involved to include methods for filing compensation claims and submitting dispute resolution requests. Cases where data has been forged, altered, or damaged due to ransomware attacks are now also subject to mandatory notification and reporting requirements.
Personal information protection management systems within organizations must pass through the highest-level decision-making body, such as the board of directors. The amendment explicitly states that ultimate responsibility lies not only with the owner or CEO, but also with the head of the respective body. In addition to organizations that process large-scale personal information with annual sales exceeding 180 billion won, universities with more than 20,000 enrolled students, tertiary general hospitals, and major public system operating institutions are all required to obtain board approval and report any CPO appointments, changes, or dismissals to the Commission within six months. To minimize initial confusion, a grace period will be in effect until the end of next year, during which no penalties will be imposed for failing to appoint a CPO.
Hot Picks Today
Why Didn't My Loan Interest Rate Drop Even After Regular Salary Transfers?… FSS Says "Check This"
- Seoul Tops London and Tokyo for the First Time... Foreign Media: "Seoul Is Becoming the New Paris"
- "Lost Vision After Wegovy and Ozempic: U.S. Patients File Lawsuits Over Sudden Sight Loss While Trying to Lose Weight"
- Individuals Load Up on Leverage, Institutions on Inverse: Diverging Fund Flows
- "Is the YouTuber Telling the Truth?" 300,000 Views in One Day... The Real Story Behind Shin Ramyun's Flavor, According to Nongshim [Tastelovers X-File]
Additionally, the mandatory certification for personal information protection (ISMS-P) for major personal information handlers in both public and private sectors has been finalized, and will take effect starting July 1 of next year, giving companies and organizations time to secure necessary budgets. Song Kyunghee, Chairperson of the Personal Information Protection Commission, stated, "With the implementation of these revised regulations, a preventive-oriented and enhanced personal information protection system will be established," adding, "I hope investments in personal information protection will be seen not as a 'cost,' but as a 'proactive investment.'"
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.