Korea raises data breach fines to 10% of revenue

314 points · 105 comments on HN · read original →

Points and comments are a snapshot, not live.

South Korea raises maximum data breach fines to 10% of annual revenue.

Starting Friday, South Korea's revised Personal Information Protection Act imposes fines up to 10% of total revenue for companies that negligently or intentionally leak personal data of 10 million or more people. The previous cap was 3% of sales. The new rules also require companies to notify users within 72 hours if data exposure risk is high, even without a confirmed breach. Fines can be reduced up to 40% for prior data protection investments or prompt breach detection. Chief privacy officers at large firms now require board approval and PIPC reporting.

What commenters are saying

Commenters are divided: some praise the deterrent effect, while others doubt enforcement against major conglomerates like Samsung. Skeptics argue that no system is fully secure and that companies might use undercapitalized shell firms to avoid liability. Proponents note that the fine targets gross negligence, not perfect security, and that South Korea's privacy regulator has a strong enforcement record. Some suggest requiring cyber insurance or holding parent companies liable to prevent evasion.