"Penalties to Increase for Repeated or Negligent Violations"

Following the implementation of the revised Personal Information Protection Act, which significantly increases penalties, attention is focused on which entity will be the first to be sanctioned under the new law. Meanwhile, financial institutions that recently experienced consecutive breaches of customer and employee information have managed to avoid heavy fines.


After Tougher Personal Data Law, Banks Hit by Successive Hacks “Not Subject to Punitive Fines” View original image


According to industry sources on October 7, the Personal Information Protection Commission plans to review and initiate disciplinary procedures after confirming the facts of the information breaches at KB Kookmin Bank, BNK Busan Bank, and Hyundai Capital. An official from the commission stated, "Entities where not only customers' financial and credit information but also the personal details of employees have been leaked are subject to direct disciplinary action."


Regulatory responses differ depending on the circumstances of each incident. If a bank, such as Shinhan Bank, experiences a breach involving customer financial information related to loans and similar services, financial authorities impose sanctions for violations of the Credit Information Act or the Electronic Financial Transactions Act. However, if the personal information of internal or external employees is leaked, the Personal Information Protection Commission becomes the responsible authority. In some cases, both authorities may impose their own sanctions simultaneously.


In the case of KB Kookmin Bank, it was confirmed that the leaked sample of 153 records included personal details of employees. At Busan Bank, personal information such as the names, phone numbers, dates of birth, and email addresses of 11 outsourced development staff members was exposed. Hyundai Capital also leaked personal data of 146 mortgage loan brokers, making it subject to the Personal Information Protection Act.


Since September 11, the Personal Information Protection Act has been strengthened to allow fines of up to 10% of total revenue. However, these financial institutions are likely to avoid such punitive fines because the scale of their data breaches does not meet the criteria for severe penalties.


The law specifically requires punitive fines in instances where intentional or gross negligence affects more than 10 million individuals, or if the same violation is repeated within the most recent three-year period. Companies that ignore government corrective orders and subsequently have an incident are also subject to punitive penalties.


An official from the Personal Information Protection Commission noted, "A detailed review is necessary, but at present, there are no financial institutions that meet these specified conditions." However, the official added that if the institutions show neglect in preventing recurrence or repeat the same type of violation, the severity of any future penalties could be increased.



Additionally, financial institutions such as Shinhan Bank and Yegaram and Welcome Savings Bank, which are subject to the Credit Information Act, could face further administrative penalties—such as fines—imposed by the commission if additional violations unique to the Personal Information Protection Act, including the 'notification obligation within 72 hours,' are discovered during the government investigation. It is currently confirmed that Welcome Savings Bank and Hyundai Capital were late in recognizing and reporting the breaches.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing