South Korea's privacy watchdog imposed the largest data-protection fine in the country's history on Coupang Inc after a breach exposed the personal information of 37.5 million customers. The company plans to challenge the penalty in court, and the case has raised concerns about potential trade friction with the United States.
Coupang Inc has been hit with a record fine of 624.7 billion won (about $410 million) over a data breach that exposed the personal information of 37.5 million customers.
The government's decision to respond to what has been called the worst data leak in the country's history with an unprecedented penalty is expected to set off significant aftershocks across the industry.
Coupang Inc plans to contest the fine and is preparing to file an administrative lawsuit. The case also carries the potential to escalate into a trade dispute between South Korea and the United States.
The Personal Information Protection Commission announced Thursday that it would impose a total fine of 624.68 billion won, along with a 16.8 million won administrative penalty, on Coupang Inc for violating its obligation to implement adequate security measures and collecting personal data without a legal basis. The commission also voted to issue a corrective order, require public disclosure, file a criminal complaint and recommend improvements. The penalty is the largest ever imposed in connection with a personal data breach in South Korea. The previous record was the 134.8 billion won fine levied against SK Telecom over its SIM card data leak.
Under the current Personal Information Protection Act, companies can be fined up to 3 percent of their sales when a data breach occurs. Coupang Inc posted sales of 45.5 trillion won last year, meaning the statutory maximum fine would have been approximately 1.3637 trillion won.
Some observers had anticipated a fine exceeding 1 trillion won, but the actual penalty is determined by weighing the scale of the damage and the company's response, among other factors. Industry officials said the commission's decision nonetheless represents a stern response.
The commission concluded that the breach, which exposed the personal data of roughly 37.5 million people, stemmed from inadequate basic security management — specifically, lax handling of authentication signing keys and insufficient access controls.
Alongside this, the commission found additional violations, including failures to notify affected individuals and delete their data as required, a failure to guarantee the independence of the company's chief privacy officer, and obstruction of the investigation.
In response, the commission issued corrective orders in three areas: strengthening security measures to prevent similar incidents, notifying non-member data subjects of the breach, and ensuring the chief privacy officer can exercise a substantive role. The commission also recommended improvements to the company's system for handling the personal data of withdrawn members and said it would verify compliance within three months.
The commission also found that Coupang Inc had unlawfully collected online activity records of approximately 11.17 million members who accessed third-party websites and apps, storing the data in a database with individuals identified.
The commission further found that Coupang Inc had failed to properly manage advertising partners that ran malicious ads — known as "hijack ads" — causing users' Coupang service usage records to be collected without their consent. The commission issued a corrective order to ensure users have a genuine choice over targeted advertising.
Separately, the commission found that Coupang Fulfillment Services had violated rules on the collection and use of personal data and on the handling of sensitive information, and imposed an additional fine of 248 million won.
The commission determined that Coupang Fulfillment Services had collected a list of 71 Korean National Police Agency press corps journalists who had no history of working at its logistics centers and registered them on an employment restriction list, in violation of personal data collection and use rules.
By Park Se-jung
sjpark@heraldcorp.com
