databreaches.net 10 Sept 2026, 13:36 UTC

South Korea Raises Data Breach Fines to 10% of Revenue

CyberSIXT Evidence Panel Source marked as original reporting

KOREA’S privacy regulator is sharply increasing the penalties for data breaches, aiming to deter lax data protection by making non-compliance financially consequential. From now, companies found to have leaked the personal data of 10 million or more people—whether through intentional wrongdoing or gross negligence—can be fined up to 10% of their total revenue under the revised Personal Information Protection Act, which takes effect on the same day the changes are implemented. Even in cases where a breach hasn’t been officially confirmed, firms must notify users within 72 hours if the risk of exposure is high.

Under the enforcement decree, the 10% cap is applied to organisations that repeatedly commit intentional or grossly negligent violations within three years, or those that fail to comply with a corrective order and subsequently suffer a breach as a result. Fines are calculated based on the nature and severity of the violation, the circumstances involved, and the scale of the damage.

The policy represents a shift toward treating data protection as a preventive investment rather than a routine cost of doing business, with authorities signalling that large-scale breaches will carry substantial penalties. Read more at Korea JoongAng Daily.

View full article

Article by CyberSIXT