Urgent.News

What's breaking now, across thousands of outlets.

Tech

Korea raises data breach fines to 10% of revenue

Starting Friday, the cost of significant data breaches in South Korea will be up to 10 percent of a company's annual revenue. The stricter privacy rules, part of a revised Personal Information Protection Act, aim to encourage companies to prioritize data protection as an investment rather than a regular expense. If a company leaks the personal data of 10 million or more individuals due to intent or gross negligence, it could face the steep fine.

Previously, the penalty was capped at 3 percent of sales. The Personal Information Protection Commission (PIPC) Secretary General Yang Cheong-sam explained that recent data breaches have become more frequent and extensive, particularly in sectors like retail and telecommunications. To enforce the new rules, companies must notify users within 72 hours if the risk of exposure is high.

The fines are determined by the severity of the violation, context, and damage caused. Companies that invest in data protection systems, have strong protection measures, and report breaches promptly could see fines reduced by up to 40 percent. Additionally, a new "potential data breach notification system" requires companies to inform affected individuals within 72 hours if they suspect personal data may have been compromised due to illegal access or trading.

Companies with specific revenue and data processing thresholds must also establish a chief privacy officer, approved by the board, and inform the PIPC of the decision.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at koreajoongangdaily.com →

More in Tech

More from Friday 18 September →