As a string of personal information leaks at corporations continues, starting on the 11th, corporations that cause repeated or serious personal information infringements can be hit with a penalty surcharge of up to 10% of their total sales. With the sanction level rising significantly from before, there are expectations that personal information protection will emerge as a management risk that the chief executive officer (CEO) and the board must manage directly, prompting preemptive security investments by corporations.
However, among recent incidents, there have been many cases in which damage worsened not due to sophisticated hacking techniques but because basic security controls, such as account, access rights, and authentication information management, did not function properly. Accordingly, there are calls to not only strengthen penalties but also improve corporations' personnel, budgets, and security operating systems.
According to the Personal Information Protection Commission, the Personal Information Protection Act, amended in Mar., and its enforcement decree that specifies the details delegated by the law, take effect on this day.
The amended law allows the imposition of a penalty surcharge of up to 10% of total sales if violations are repeated within three years due to intent or gross negligence, or if large-scale damage affecting 10 million or more people occurs due to intent or gross negligence. It also applies when a personal information leak occurs because a corrective order by the Personal Information Protection Commission was not followed.
Previously, violations of the Personal Information Protection Act could be subject to a penalty surcharge of up to 3% of total sales, but with this amendment, the cap for serious or repeated infringements has been raised to 10%. This exceeds the European Union (EU) General Data Protection Regulation (GDPR) cap of 4% of global annual sales for serious violations.
◇ "Recognized as a risk to be managed directly by the CEO"… expected to spur more security investment
Experts say a penalty surcharge of up to 10% of total sales will incentivize security investments by corporations.
Yeom Heung-yeol, an emeritus professor in the Department of Information Security at Soonchunhyang University, said, "With this implementation, the risk of personal information leaks can be recognized not as a problem only for the security department but as a core management risk that the CEO and the board must manage directly," adding, "As penalty surcharges grow, the economic rationale for preemptive security investments—such as encryption, multi-factor authentication, anomaly detection, and securing specialized personnel—will also increase."
At first, concerns were raised that as the sanction level rose, corporations could cover up incidents or delay reporting. The government included measures in this enforcement decree to mitigate that.
If a personal information leak is not reported or notified within the statutory deadline and no measures are taken to prevent the spread of damage, the penalty surcharge can be increased by up to 30%. Conversely, if a response system is established in advance and incidents are detected early, with prompt reporting and notification or active measures to prevent the spread of damage, the penalty surcharge can be reduced by up to 40%.
◇ Personal information leaks continue… gaps even in "basic security"
Meanwhile, separate from the tougher sanctions, personal information leaks and exposure incidents have continued recently at worksites of corporations. After a large-scale personal information leak at Tving in Jun., similar incidents in which personal information was leaked or exposed externally followed from late last month at 29CM, Gangnam Unni, Hwahae, and Weverse.
The causes of the incidents vary by corporation, and some cases are still under investigation by the authorities. However, in cases where cause analysis has been completed, indications have emerged that the damage was exacerbated more by failures to properly operate existing security systems than by brand-new, highly sophisticated attack techniques themselves.
According to the public-private joint investigation team at the Ministry of Science and ICT, Tving stored access keys for development and operations environments in source code without encryption or shared them via an in-house messenger. It also emerged that access rights were not restricted to the minimum necessary for work, allowing all developers to access the entire development project. It was found in 2024 during a penetration test that there was a vulnerability where access keys were exposed in source code, but it was not remediated.
Professor Yeom said, "As digital- and cloud-based services expand, attack surfaces and supply chain risks have grown, but the security personnel and systems at some corporations, as well as access rights and security management levels at contractors, have not kept pace," adding, "Leaks occur not only through hacking but also through insider misuse or abuse, work mistakes, and configuration errors."
◇ "Penalty surcharges are a last resort"… prevention systems must be strengthened before incidents
Experts emphasize that to meaningfully reduce personal information leaks, efforts should not end with imposing penalty surcharges after incidents; corporations must strengthen prevention systems before incidents occur.
Kim Myeong-ju, a professor in the Department of Information Security at Seoul Women's University, cited "data minimization," which is not collecting or retaining personal information beyond what is necessary, as a basic principle. The idea is to reduce the information that could be leaked so that even if an incident occurs, the scale of damage is minimized. Kim explained that this should be accompanied by the principle of least privilege, multi-factor authentication, encryption of sensitive information, continuous vulnerability management, supply chain management including outsourcing and partner firms, and regular incident response drills.
Kim said, "It is important to reduce the likelihood of incidents as much as possible, detect them quickly if they occur to minimize damage, and learn from those incidents so that the same failures are not repeated," adding, "Ultimately, penalty surcharges are a last resort, and the ultimate goal is to have corporations accept personal information protection not as an expense but as ongoing management of business risk."