Skip to content
← All news
3 min read

South Korea raises its maximum data breach fine to 10 percent of revenue

PIPC's revised privacy law lets fines reach 10 percent of a company's total revenue for the worst breaches, up from 3 percent, after the Coupang and SK Telecom cases.

Korea can now fine the worst data breaches up to 10 percent of revenue, higher than the EU's GDPR cap.

Every company that stores personal data in South Korea answers to one regulator, the Personal Information Protection Commission. On September 11, 2026, a revised Personal Information Protection Act and its enforcement decree took effect there, raising the maximum data breach fine from 3 percent of a company's total revenue to 10 percent, Korea JoongAng Daily reported. The National Assembly passed the revision on February 12, 2026.

What actually changes

It is a ceiling, not a default. The full 10 percent cap only applies when a breach involves intent or gross negligence, combined with at least one aggravating factor: a repeat violation within three years, 10 million or more people affected, or a breach that happened after the company ignored an earlier PIPC corrective order. Companies that show strong compliance investment can still cut the fine by up to 40 percent. The revision also adds a 72-hour breach notification deadline and requires board approval before a major company can appoint or dismiss its chief privacy officer.

The two breaches behind it

Reporting on the new fines names the same two cases as the trigger. Coupang's breach exposed 37.55 million people and drew a fine of roughly 624.6 billion won, about $409 million, in June 2026. SK Telecom's breach, disclosed separately, drew a fine of about 134.8 billion won, roughly $88.8 million. Both fines were calculated under the 3 percent ceiling the new law now replaces. Legal alert services including Lexology and Hunton, plus the Korea Times, independently reported the same fine increase.

The catch inside the number

On paper, Korea's new ceiling is now stricter than the European Union's General Data Protection Regulation, which caps fines at 4 percent of a company's global revenue. Whether that produces tougher outcomes is unclear. The 10 percent tier requires proving intent or gross negligence plus an aggravating factor, a higher bar than a flat percentage suggests, and the 40 percent reduction for compliance investment gives well-resourced companies a route back down. PIPC Secretary General Yang Cheong-sam described the change as closing the gap between Korea's old penalties and the scale of recent breaches, according to Korea JoongAng Daily, but the law's actual bite will show up only in how the PIPC applies it to the next major case, not in the percentage alone.

Why a build studio cares

We run the encryption verification and data-flow mapping steps in our own Deep and Full Audit tiers because a vendor's claim that its data is encrypted has never been enough on its own. A 10 percent ceiling changes the math. A buyer who never checked whether a vendor's backups actually restore, or whether personal data sits somewhere outside the promised region, is the buyer who inherits that liability first. We covered what that looks like at full scale in September, when AWS told customers that data hosted only in Bahrain and one UAE zone was gone for good, a failure mode multi-AZ design was never built to cover. This is separate from the DPDPA readiness work we do for Indian clients: Korea's law is its own regime, but the underlying lesson, that skipping verification gets more expensive every year, holds everywhere.

Next step: read the Korea JoongAng Daily report on the new fine structure, and check your own vendor contracts for what happens if their compliance costs go up. If you want a Deep or Full Audit to see what a 10 percent ceiling would actually expose in your stack, write to us at hello@gattyworks.com.

Data PrivacySouth KoreaPIPCComplianceSouthKoreaCoupangSKTelecomPIPCDataBreachDataPrivacyGDPRPrivacyLawCybersecurityCompliance

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call