Even if Credit Information Leaks at Financial Firms Like Shinhan, Fine Capped at 5 Billion Won... Calls Grow for Tougher Sanctions
[Cracks in Financial Security] ④
Financial Services Commission Announces Finer Guidelines for Fine Assessment
New Standards May Apply to Shinhan Bank Data Breach
Fine Cap for Hacking-Related Leaks Remains at 5 Billion Won
Bill Introducing 3% of Total Revenue as Punitive Fine Still Pending
Amid a series of recent customer data leakage incidents in the financial sector, there is a possibility that the new credit information law's fine calculation standards, which the financial authorities are set to implement, may be applied to ongoing cases such as the one involving Shinhan Bank. However, the statutory upper limit for fines related to personal credit information leaks due to hacking remains at 5 billion won. The financial authorities' proposal to introduce punitive fines, which has been pursued since last year, is still pending in the National Assembly, and even if the law is amended, retroactive application to incidents that have already occurred is unlikely.
According to the financial authorities on October 6, the Financial Services Commission, on October 1, pre-announced proposed amendments to the 'Credit Information Business Supervision Regulations' that would establish new fine calculation criteria under the Credit Information Act. The authorities believe that the ongoing customer data leak cases, including Shinhan Bank, could be subject to the new standards in future sanction procedures. Under the Framework Act on Administrative Regulations, unless otherwise specified, if a change in statute after a violation lightens the sanction criteria, the amended standard is applied.
The core of this revision is to set up fine imposition standards that reflect the unique characteristics of the Credit Information Act. Previously, violations were categorized into three levels of seriousness, applying basic rate percentages of 50% for minor, 75% for serious, and 100% for very serious violations.
Reflecting criticism that even minor violations could result in excessive fines, the authorities subdivided the imposition rates. Under the revised proposal, violations rated as minor would be subject to rates between 1% and less than 30%, serious violations to rates between 30% and less than 65%, and very serious violations to rates between 65% and 100%. The type and nature of personal credit information, the scale and impact of the damage, and the method and duration of the violation will also be considered in the seriousness assessment.
However, the current amendment only reorganizes the fine calculation method, and does not raise the upper limit for fines in cases of personal credit information leakages due to hacking. Under the current Credit Information Act, if a company violates its security obligations and loses, has stolen, leaks, tampers with, or damages personal credit information, the fine is set at a maximum of 5 billion won.
Accordingly, if the Shinhan Bank incident—where not only personal data but also annual income, loan limits, and other personal credit information were leaked—is categorized as a 'very serious' violation and the amendments take effect, the basic fine could range between 3.25 billion won and 5 billion won. The final fine would be determined after reflecting aggravating or mitigating factors, but by law it cannot exceed 5 billion won.
The authorities consider that the recent case will primarily be governed by the Credit Information Act. It is also possible to apply the Electronic Financial Transactions Act, which obligates financial firms to adhere to IT and security standards for processing electronic financial transactions safely. However, the current upper limit for fines under this regulation stands at 50 million won for breaches of related security obligations. After the Financial Supervisory Service investigation, the authorities will also consider whether to apply industry-specific laws such as the Banking Act in case of further sanctions, such as suspension of work.
There is also the possibility of additional sanctions under the Personal Information Protection Act. Under this law, a fine of up to 3% of total revenues can be imposed in general. However, the authorities explained that it is difficult to impose overlapping fines under both the Credit Information Act and the Personal Information Protection Act for personal credit information leaks, because if personal and credit information are leaked together, the special law—the Credit Information Act—takes precedence. For additional sanctions under the Personal Information Protection Act, a separate violation in handling personal data—one not covered by the Credit Information Act—must be confirmed.
The case of Lotte Card is a representative example. Last year, financial authorities imposed a fine of 5 billion won and a 1.5-month suspension of work on Lotte Card in July this year, pursuant to the Credit Information Act and other laws, for leaking the personal credit information of 2.97 million customers. Separately, in March this year, the Personal Information Protection Committee fined Lotte Card 9.62 billion won for recording resident registration numbers in online payment logs without legal grounds and insufficient encryption.
Punitive Fine Proposal Stalled in the National Assembly
Last year, following a series of hacking incidents in the financial sector, the government announced plans to strengthen penalties for information leaks and introduce punitive fines. The financial authorities have also expressed their intention to amend the Electronic Financial Transactions Act, which sets forth security obligations for electronic financial systems, in order to toughen sanctions on hacking-related incidents.
The proposed amendment to the Electronic Financial Transactions Act, sponsored by Democratic Party lawmaker Yoo Dongsoo, would allow fines of up to 3% of total sales revenue when electronic financial transaction or personal credit information is leaked due to a security breach.
The proposed revision includes stronger fine calculation standards than those in the current Personal Information Protection Act. While that law also sets an upper limit of 3% of total sales revenue in principle, it allows for the exclusion of revenue unrelated to the violation when calculating the fine. By contrast, the Electronic Financial Transactions Act amendment contains no such exclusion clause.
An official from the financial authorities stated, "The revised bill is tougher, as it does not include an 'exclusion of unrelated sales revenue' clause like the Personal Information Protection Act." The official added, "In actual leak cases, hacking is usually detected first, and personal credit information leaks are confirmed only as the investigation into the infiltration route and damage scope progresses. More systematic regulation can be achieved through the amendment of the Electronic Financial Transactions Act, rather than the Credit Information Act."
However, the proposed amendment to the Electronic Financial Transactions Act, which contains these measures, remains pending in the National Assembly. Even if the law is amended, it will be difficult to retroactively apply the strengthened punitive fines to recently occurred information leakage cases in the financial sector, such as the Shinhan Bank case.
Hot Picks Today
[Exclusive] "Forecasts of Over 10 Billion, but Only 100 Million Earned"... 95% Followed This Pattern: Why Are KOSDAQ Special Exception IPOs Inflated? [KOSDAQ Inflated IPOs]①
- "Breakfast Now" Hits 1.41 Million Views... Burger King Expands Morning Menu Nationwide After 8x Sales Surge
- "My Debt Is 73 Million Won"... Sharing Every Repayment Led to an Unexpected Turn
- "Drinking This in the Morning Is Like Drinking Alcohol"..."Doctors Warn: Never Consume It"
- Is 'KOGUMA' Coming Too?... "Japan in Serious Trouble" - Archipelago on High Alert Ahead of Holidays
An industry insider commented, "Regulations such as fines for personal credit information leaks related to financial transactions, which cause even greater harm than ordinary personal data leaks, are overly lenient. As AI-powered hacking becomes more sophisticated, institutional improvements should be implemented swiftly to ensure that violators face real consequences for breaches."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.