Fine of 624.68 billion won (about $457 million) and 16.8 million won in administrative penalties
Regulator cites inadequate security management as cause of breach affecting 37.5 million people
Coupang vows to challenge ruling in court; trade tensions with US may follow
Coupang Inc has been hit with a fine of nearly 624.7 billion won ($457 million) — the largest data-breach penalty in South Korean history — after a leak exposed the personal information of 37.5 million customers.
The government's decision to respond with a record fine to what has been called the worst data leak in the country's history is expected to set off significant repercussions.
Coupang Inc said it plans to immediately contest the fine and file an administrative lawsuit. The dispute also carries the potential to spill over into trade tensions between South Korea and the United States.
The Personal Information Protection Commission announced Thursday that it would impose a total fine of 624.681 billion won and an administrative penalty of 16.8 million won on Coupang Inc for violating its obligation to implement security measures and collecting personal information without a legal basis. The commission also voted to issue a corrective order, public disclosure, a referral for criminal charges and a recommendation for improvement.
The penalty is the largest ever imposed for a data breach in South Korea. The previous record was the 134.8 billion won fine levied against SK Telecom over its SIM card data leak.
Under the current Personal Information Protection Act, companies can be fined up to 3 percent of their sales when a data breach occurs. Coupang Inc's sales last year totaled 45.5 trillion won, meaning the maximum statutory fine would have been approximately 1.3637 trillion won.
Some observers had initially expected a fine exceeding 1 trillion won, but the actual penalty is calculated by weighing the scale of the damage and the company's response to the incident. Industry officials say the commission's decision nonetheless represents a firm response.
The commission concluded that the Coupang breach — which exposed the personal information of some 37.5 million people — stemmed from inadequate basic security management, including lax handling of authentication signing keys and insufficient access controls.
Investigators also found additional violations: failure to notify affected individuals and to delete data as required, failure to guarantee the independence of the company's chief privacy officer, and obstruction of the investigation.
In response, the commission issued corrective orders requiring Coupang Inc to strengthen security measures to prevent similar incidents, notify non-member data subjects of the breach, and ensure the chief privacy officer has a substantive role. The commission also recommended improvements to the company's system for handling the personal data of withdrawn members and said it would verify compliance within three months.
The commission also found that Coupang had covertly collected the online activity records of approximately 11.17 million members who visited third-party websites and apps, storing the data in a database with individuals identified.
Investigators further confirmed that Coupang had failed to properly manage advertising partners that ran deceptive ads — known as "hijack ads" — causing users' Coupang service activity records to be collected against their wishes. The commission issued a corrective order requiring Coupang Inc to guarantee users a genuine choice over targeted advertising.
The commission also found that Coupang Fulfillment Services violated rules on the collection, use and handling of sensitive personal information, and imposed a separate fine totaling 248 million won.
The commission determined that Coupang Fulfillment Services had collected a list of 71 Korean National Police Agency press corps reporters — none of whom had ever worked at a logistics center — and registered them on an employment restriction list, constituting a violation of personal data collection and use rules.
Meanwhile, a joint public-private investigation by the Ministry of Science and ICT released in February found that the attacker behind the data breach was a former Coupang developer who had stolen a signing key during their employment and used it to forge electronic access credentials, gaining unauthorized access to the company's internal network. The breach exposed customer names, email addresses and shared building entry passwords, among other information.
sjpark@heraldcorp.com
