hn.today

Korea raises data breach fines to 10% of revenue

koreajoongangdaily.com198 points58 comments
Screenshot of Korea raises data breach fines to 10% of revenue

South Korea sharply stiffened penalties for major data breaches by raising maximum fines to 10 percent of a company’s annual revenue for incidents caused by intent or gross negligence that expose the personal data of 10 million or more people. The revised Personal Information Protection Act also requires companies to notify affected individuals within 72 hours when there is a high likelihood of exposure, even if a leak hasn’t been confirmed, and expands reporting obligations to include data altered or damaged by ransomware. The enforcement decree targets repeat offenders (within three years) and entities that ignore corrective orders, with fines determined by the violation’s nature, severity and damage scale; the previous cap had been 3 percent of sales.

Mitigating factors can reduce penalties: firms that demonstrate sustained investment in data protection or that detect, report and contain breaches promptly can receive up to 40 percent reductions. The rules bolster the role and oversight of chief privacy officers at large data processors (companies with revenue over 180 billion won handling data on 1 million+ people or sensitive data on 50,000+), requiring board sign-off and PIPC notification for CPO appointments or dismissals. Regulators signal the change is designed to reframe data protection as a proactive investment in trust and business resilience rather than a routine cost.

Read on koreajoongangdaily.com58 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.