(123rf)
(123rf)

Despite a staggering 88.54 million cases of personal data being compromised across Korea’s public and private sectors over the past five years, the average financial penalty per leaked record stood at a mere 1,019 won ($0.73), prompting growing concerns over the country’s insufficient regulatory response.

According to data disclosed Monday by Rep. Min Byung-deok of the ruling Democratic Party, who serves on the National Assembly’s Political Affairs Committee, a total of 88.54 million records of personal information were compromised in 451 separate data breach incidents from 2021 to July 2025, based on figures from the Personal Information Protection Commission.

Among the reported incidents, 125 were subject to administrative fines totaling 87.7 billion won, while 405 incurred administrative surcharges amounting to 2.5 billion won. On average, each breach resulted in a fine of 700 million won and a surcharge of 6.17 million won.

While the per-record penalties have gradually risen -- from 41 won in 2021 to 8,302 won in 2024 -- the 2025 figure, as of July, has dropped to 2,743 won, reinforcing skepticism about the deterrent power of Korea’s current data protection framework.

Although a 2023 revision to the Information and Communications Network Act now requires companies to report hacking incidents within 24 hours, violators face a maximum surcharge of only 30 million won.

Experts argue that such a limit is insufficient to ensure timely reporting or hold corporations accountable.

In comparison, the European Union’s General Data Protection Regulation allows for fines of up to 20 million euros ($23.5 million) or 4 percent of a company’s global annual revenue -- whichever is greater.

In 2021, Amazon faced a 746-million-euro penalty under GDPR, while in the US, the Federal Trade Commission fined Meta, formerly Facebook, $5 billion in 2019 for mishandling the data of 87 million users.

Rep. Min cited recent breaches involving SK Telecom’s USIM data and KT’s personal information leaks, which reportedly enabled unauthorized mobile payments, as evidence of regulatory failure.

He called on the government to consider adopting class-action mechanisms, punitive damages and European-level fines to strengthen enforcement and restore public trust.

“The recent wave of data leaks makes it evident that our current regulatory response is too weak,” the lawmaker said. “We need to adopt stronger, globally aligned penalties to ensure accountability and rebuild public trust in information security.”


yeeun@heraldcorp.com