"Companies Handling Personal Data Should Have Incident Response Manuals and Conduct Drills" [Choi Seokjin's Law & Biz]
Individuals Who Suffer Data Breaches
Joining a Class Action Is the Best Course
Dispute Mediation by the Personal Information Protection Commission Is Also an Option
For Companies Handling Personal Data
Continuous Budgeting and Orga
On September 4, a major data breach occurred on "Gangnam Unni," South Korea's largest beauty and medical information platform, exposing the personal information of approximately 220,000 users. As the app compares hospital prices and reviews for a wide range of cosmetic surgeries and skin treatments, there are significant concerns about secondary damages, given that not only basic personal information such as names and contact details, but also consultation records and before-and-after photos have reportedly been leaked.
Around the same time, the fan community platform "Weverse," operated by HYBE, suffered a leak of information from over 420,000 accounts. In May, an online video service (OTT) platform, TVING, experienced a hacking incident in which information from approximately 39.54 million accounts was compromised.
From the left, Tae-Wook Kang and Kanghye Lee, lawyers at Bae, Kim & Lee LLC. Bae, Kim & Lee LLC
View original imageDue to these ongoing large-scale personal data leaks, we asked two experts from Bae, Kim & Lee LLC—Taewook Kang (31st Judicial Research and Training Institute class) and Kang Hye Lee (2nd Bar Examination)—about what must be considered by companies handling personal data and by customers as information subjects, as well as what measures are needed to prevent such incidents.
Kang, who previously served as a judge, is one of the foremost experts in the field of personal data protection. In 2020, he was recognized by ALM, a global legal media outlet, as the only Asian recipient of the "Data Privacy Lawyer of the Year" award at The Asia Legal Awards. He has served as a researcher on amendments to the Personal Information Protection Act, a member of the Institutional Innovation Advisory Panel, and a Personal Information Processing Policy Evaluator at the Personal Information Protection Commission. Kang now acts as an advisory lawyer to the Commission and is an AI specialist committee member at the Ministry of Science and ICT.
Lee, who joined Bae, Kim & Lee after working at LG Electronics, received the Personal Information Protection Commission Chairman’s Commendation in 2024 for her contributions to privacy protection and was recognized as one of the Central Daily’s Best Lawyers and a Legal Times Rising Star. She is regarded as a next-generation leader in corporate law, specializing in personal information protection and IT spheres.
-Large-scale customer data breaches are happening continually. Where do you see the main causes?
▲ Kang = The primary cause is that the use of online and mobile platforms has become not just routine but essential in our everyday lives. All types of data are now digitized and easily duplicated online. However, the advancement of management systems for those data and the level of awareness regarding their protection have not kept pace. In the short term, the rapid development of AI technology has made it easier to identify security vulnerabilities that were previously hard to detect, increasing the likelihood of hackers exploiting them. On the other hand, defensive security capabilities have not been sufficiently upgraded to meet these challenges.
-How have court precedents evolved?
▲ Kang = Historically, courts have often not held companies accountable for large-scale customer data breaches resulting from hacking. This was due, in part, to the limited number of hacking cases and the difficulty in attributing general negligence for a lack of safety measures to companies. However, with persistent major breaches, regulatory agencies are steadily increasing the severity of fines, and companies are expected to shoulder greater responsibility. Notably, this trend seems more pronounced in Korea than in other countries, where a similar shift is not as evident.
-Why do courts award only hundreds of thousands of won per person in damages?
▲ Kang = When considering the per-person damages, I do not see the amount as particularly low compared to what courts have recognized in other types of damages. Most of these amounts are awarded for the mental distress caused by the leak itself, not for actual secondary damage suffered, which reinforces my view.
-At the end of last year, the Supreme Court delivered an important ruling related to damages claims for personal data leaks.
▲ Kang = There are not many Supreme Court precedents regarding Article 39-2 of the Personal Information Protection Act, which concerns statutory damages. Previously, it was argued that, in cases of a data breach, if the data subject could prove only the fact of the breach, the data handler should be liable for compensation. In this decision, however, the Supreme Court clarified that, while plaintiffs (information subjects) do not need to make specific claims or proof of damages for statutory damages, if the defendant asserts no damages occurred, the court should examine whether such a claim and supporting evidence have been presented. The ruling has clarified that, if it is evident that no actual damage occurred, the data handler can be exempted from liability by proving no mental harm deserving of compensation was suffered by the data subject. The Supreme Court also provided standards for evaluating what constitutes actual damage in such cases, making this a highly meaningful decision. Furthermore, the Court upheld the lower court’s finding that, in the case at hand, no damage could be recognized under the criteria provided, which is also significant.
-How should victims respond if their personal data is breached?
▲ Lee = For individuals whose data is leaked, joining a group action as a plaintiff is, in practice, almost the only option—much like a group purchase. It is possible to file a lawsuit individually, but the costs and time involved must be considered, and, as indicated in the Supreme Court decision, one must also be prepared to counter arguments by defendants claiming "no damage." Therefore, this is not an easy course to take. Alternatively, individuals may use the dispute mediation procedures provided by the Personal Information Protection Commission.
-What should people pay attention to on a daily basis to protect their personal data?
▲ Kang = Developing the habit of changing one’s password regularly is necessary. Whenever personal data is provided, one must carefully check the notices included in consent forms. The Personal Information Protection Act requires multiple consent boxes, so it is important to understand the reasons for granting consent. Additionally, to guard against spam emails containing ransomware, users should avoid clicking emails or consent buttons automatically and always thoroughly verify the sender and content.
▲ Lee = I also believe it is important to make a habit of shutting down the PC after use. For IT professionals, who often work on weekends or holidays, special attention should be given to ensuring that security policies are not loosened during these times.
-What preemptive measures should companies handling personal data take?
▲ Kang = From a corporate perspective, it is necessary to implement the statutory safety measures required by law. Because information security demands ongoing management, it is crucial to secure continuous budgets and dedicated personnel, rather than treating it as a one-time investment. Regular external compliance inspections are also required for the management of customer information.
▲ Lee = When incidents occur, companies may find themselves in a state of confusion and struggle to respond quickly. To reduce this confusion and ensure an adequate response, I recommend preparing an incident response manual and conducting simulation drills.
-What is the most urgent action a company should take after a data breach?
▲ Lee = First and foremost, it is crucial to assess the scale and severity of the incident. The company should then establish a taskforce and maximize reporting efficiency in line with its internal management plans and data breach response manual. Taking prompt measures to resolve security issues is paramount. Companies should also swiftly and accurately ascertain the situation, prepare for an effective response, and honestly inform customers about the incident so they can take appropriate measures.
-Does voluntary compensation for affected customers by a company influence subsequent lawsuits?
▲ Lee = Voluntary compensation by companies is extremely important—not only from a policy perspective for customer protection, but also regardless of the amount of compensation determined in court. Such measures are also likely to be taken into active consideration when calculating damages in a lawsuit, since they represent actual compensatory actions taken toward customers.
-What are the key points to know in the latest amendments to data protection laws?
▲ Lee = With the revision of the Act in March of this year, the "Notification Obligation of Potential Data Breach" system was introduced, which, as of the 11th, requires data controllers not only to notify information subjects when a data leak is confirmed, but also, in certain cases, when there is a risk of a leak. The notification must include what personal data may be affected, when and how the breach is suspected or has occurred, and the circumstances. Additionally, a punitive fine system for personal data breaches has been introduced so that, in cases of repeated or intentional/grossly negligent breaches, the maximum fine was raised substantially—from 3% of total sales revenue to up to 10%. Further, a recent amendment has established a special provision for AI, which comes into force March 9 next year, under which data controllers meeting specific conditions will be able to use lawfully collected personal information for purposes other than the original intent, subject to the review and approval of the Protection Commission, for the development of AI technology.
-What policies should the government promote, or laws should the National Assembly enact, to address data breaches?
▲ Kang = Sanctions for personal data leaks are important, but it is even more vital to establish systems for preemptive investment, stronger security measures, and the development of personnel and governance structures. While increasing the liability of top management, like the CEO or Chief Privacy Officer (CPO), is important, it is crucial to create policies that incentivize increased investment and proactive strengthening of security measures. Moreover, while accountability matters when data breaches occur, it is equally important to create a working environment in which leaders, responsible parties, and team members in charge of personal information protection can take pride in their work and dedicate themselves fully to responding to incidents.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.