Policy

Repeated and Large-Scale Breaches Face Fines of Up to 10% of Revenue as Revised Privacy Law Takes Effect Today

IT DAILY ·

At the full meeting of the Personal Information Protection Commission held at the Government Complex Seoul in Jongno-gu, Seoul, on August 29, Chairperson Song Kyung-hee of the Personal Information Protection Commission is seen tapping a gavel. [Photo: Personal Information Protection Commission]

✦ AI Summary

The Personal Information Protection Commission said the revised Personal Information Protection Act, amended in March, took effect on the 11th, strengthening companies' responsibility for personal data protection and the level of sanctions.

Under the revised law, fines of up to 10% of total revenue are now possible when deliberate or grossly negligent incidents are repeated or when large-scale damage affecting more than 10 million people occurs, and users must be notified within 72 hours if the likelihood of a breach is high.

It also made clear that employers and CEOs bear ultimate responsibility for personal data protection, while strengthening CPO authority and introducing board reporting, resolution, and reporting obligations.

The Personal Information Protection Commission said the revised Personal Information Protection Act, amended in March, took effect on the 11th, strengthening companies' responsibility for personal data protection. The government pushed ahead with the revision amid growing public concern over large-scale personal data breaches, aiming to reinforce corporate responsibility for protecting personal information.

Under the revised law, fines can now be imposed when deliberate or grossly negligent incidents are repeated or when large-scale damage occurs, with the cap set at up to 10% of total revenue. As the revised Personal Information Protection Act took effect on the 11th, companies' obligations for personal data protection and the level of sanctions were strengthened together.

If the risk of a breach is judged to be objectively high, companies must notify users, and the deadline for doing so is within 72 hours of becoming aware of the fact. Meanwhile, on August 29, a plenary meeting of the Personal Information Protection Commission was held at the Government Complex Seoul in Jongno-gu, Seoul, and Commission Chairperson Song Kyung-hee struck the gavel at the meeting.

Changes to the special rules on personal data-related fines are drawing attention. The core of the system overhaul is to significantly strengthen fines for repeated or large-scale serious violations with major damage. Companies that repeat violations within 3 years on the premise of intent or gross negligence can be fined up to 10% of total revenue. Companies that suffer damage affecting more than 10 million people can also face fines of up to 10% of total revenue. In addition, if a personal data breach occurs while a corrective order remains unfulfilled, the case becomes subject to punitive fines.

On the other hand, a system will take effect that reduces fines by up to 40% for companies that have actively invested in personal data protection. When calculating fines, the scale, ratio, and continuity of investments such as budgets and personnel for personal data protection are taken into account. The level of the protection system, including CEO and personal information protection officers (CPO), is also included among the factors considered in calculating fines.

Prompt response efforts after an incident are also reflected in fine reductions. Companies that operate response systems in preparation for incidents can receive reductions. Companies that detect and report problems early can also receive reductions. Companies that quickly restore and improve their personal data protection systems are likewise eligible for reductions.

To help the rules for applying these reduction standards in the field, the commission has posted the 'Guidance on Fine Reductions for Investment' on its website.

Tving suffered a system hacking incident in May this year, exposing 39.54 million user accounts. However, because the Tving breach occurred before the law took effect, it is excluded from the newly introduced special provisions. The newly introduced special provision allows fines of up to 10% of revenue.

Administrative actions vary by case. The Ministry of Science and ICT plans to impose a fine of up to KRW 30 million in relation to exceeding the statutory deadline for reporting a breach incident. Fines related to personal data breaches are subject to a decision after the Personal Information Protection Commission completes its investigation.

Tving's account structure allows a single person to hold multiple accounts. Accordingly, the figure of 39.54 million accounts includes duplicates. The exact scale of the damage will be announced after a detailed analysis by the commission.

The revised Personal Information Protection Act moved up the timing for notifying users about the risk of personal data breaches. The previous rule required notifying users at the time a breach was confirmed, but the revised law has advanced the notification point. Going forward, even before a breach is finally confirmed, notification obligations toward data subjects arise if the likelihood is high. This is a system change intended to minimize harm to the public.

Even at a stage where a personal data breach has not been confirmed, if certain conditions are met, rules and procedures will be established for judging the possibility of a breach and notifying users first. If an unauthorized external access suggests a personal data breach but it is difficult to identify the data subject, a user notification obligation is imposed within 72 hours of awareness. If partial leakage is confirmed through illegal trading of personal information and there is a possibility of damage spreading, a user notification obligation is also imposed within 72 hours of awareness.

User notifications must include the categories of personal information, the time and circumstances of suspicion, ways to minimize damage, damage relief procedures, and contact information for reporting damage. The notice must also state that an additional notice will follow if a breach is confirmed.

Afterward, depending on the results of the verification, if the actual breach is confirmed within the deadline, it can be replaced with a breach notification instead of a separate suspicion notice. Conversely, if it is determined that there was no breach, a correction notice is needed to ease user confusion and anxiety.

In addition, the scope of reporting and notification will expand from loss, theft, and leakage to forgery, alteration, and damage. Personal data damage caused by ransomware and similar threats is also included. In addition, the breach notification items will include legal remedies for damage, such as claims for damages and applications for dispute mediation.

The Personal Information Protection Commission revised the 'Guidance on Responding to Personal Data Breaches' to respond more quickly to personal data breach incidents and speed up relief for the public. In this revision, guidance on specific criteria and cases was reinforced.

Yang Cheong-sam, secretary general of the Personal Information Protection Commission, held a briefing on Thursday, September 10, at the Government Complex Seoul in Jongno-gu, Seoul. At the briefing, the revised guidance and the major changes in the revised Personal Information Protection Act were explained.

The revised Personal Information Protection Act clearly states that employers and CEOs bear ultimate responsibility for personal data protection. It also strengthens the authority and responsibilities of CPOs.

The strengthened CPO authority includes management of specialized personnel and securing budgets. The revised Personal Information Protection Act also imposes a duty on CPOs to report to the board of directors.

Accordingly, companies and institutions that meet certain requirements must obtain board approval when appointing, changing, or dismissing a CPO. In such cases, they are also required to report to the commission.

The entities subject to board resolution and reporting in connection with CPO appointment, change, or dismissal are the same as those currently subject to the statutory obligation to appoint a specialized CPO. The qualifying requirements include annual revenue or income exceeding KRW 180 billion, processing sensitive information or unique identifying information of 50,000 or more people, or processing personal information of 1 million or more people, and also include universities with 20,000 or more students, upper-tier general hospitals, and public system operators.

The reporting deadline is within 6 months from the date the cause arises. For CPOs designated before the revised law took effect, a separate board resolution is exempted. However, CPOs designated before the revised law took effect are required to report to the commission within 6 months from the effective date.

However, if there is a compelling reason recognized by the commission, the reporting period may be extended upon request. An example of a compelling reason is difficulty convening a board meeting. The maximum extension is up to 1 year. The commission revised the existing notice on recognition of CPO experience to establish forms for reporting CPO appointments, changes, and dismissals and to specify the reporting procedure. A CPO appointment report is filed by accessing the personal information portal, selecting 'CPO Report' from the 'Corporate and Public Services' menu, entering the relevant items, and attaching supporting documents.

The commission will operate a grace period to ease the burden of the new system. The grace period ends on December 31, 2027. During the grace period, fines will not be imposed for violations of the relevant law, including failure to designate a CPO, failure to meet CPO qualification requirements, violation of the duty to obtain board resolution, and failure to report.

The revised Personal Information Protection Act includes provisions making ISMS-P certification mandatory for major personal information processors in the public and private sectors, but implementation has been deferred to allow companies and institutions time to secure budgets for obtaining ISMS-P certification. As a result, the effective date for those revised provisions is July 1, 2027, rather than immediately after promulgation.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241542

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.