New Policy Triples Previous Penalty for Major Violations
The Personal Information Protection Commission (PIPC) is pursuing a plan to impose fines of up to 10% of maximum revenue on companies that cause major personal information breach incidents or repeated accidents. Additionally, the commission is reviewing a plan to introduce the class action system, currently only implemented in the securities sector, to the personal information field as well. This is intended to expand companies’ preventive investment before accidents occur.
On Dec. 12, the commission reported its 2026 work plan, which includes such content, to President Lee Jae Myung at a briefing held at the Government Sejong Convention Center. The commission first decided to establish a new provision that raises the fine standard for companies that commit repeated and serious violations from the existing 3% of revenue to 10%. Currently, the Personal Information Protection Act stipulates that fines can be imposed on companies that cause personal information breach accidents within a range not exceeding 3% of total revenue. The commission plans to raise this standard to a maximum of 10% of revenue, enabling regulations that are more than three times stronger than current ones when necessary. However, the provision allowing exclusion of revenue from unrelated sectors will be maintained, and the existing 3% fine standard will also be retained considering the fine burden on small and medium enterprises. In other words, it is a structure that introduces the 10% only when specific conditions such as intentional/gross negligence and large-scale damage are met.
In relation to this, Rep. Park Beom-gye of the Democratic Party of Korea and others proposed an amendment to the Personal Information Protection Act on Dec. 9, which includes content allowing fines of up to 10% of revenue to be imposed. The bill limited the targets for punitive fine imposition to cases such as repeated violations due to intentional or serious negligence within the past 3 years, cases causing damage to large-scale (10 million or more) information subjects due to intentional or serious negligence, and cases of personal information breach due to non-compliance with corrective orders. PIPC Chairperson Song Kyung-hee said “(We have) the same position as the National Assembly proposed bill and are pursuing it together,” adding “Since national consensus on the necessity has been formed, we expect it to proceed swiftly, and the commission is making maximum efforts.”
However, even if the bill passes, it is expected to be difficult to apply to Coupang. Song said “While we must examine each individual case, it appears difficult to apply punitive fines to incidents that occurred before the amendment.”
The PIPC is also pursuing a plan to enable damage compensation through group litigation when personal information breach accidents occur. Currently, when personal information breach accidents occur, collective dispute mediation is not conducted, so even if it moves to group litigation, damage compensation cannot be received. This is because there are no damage compensation provisions through group litigation. To receive damage compensation, individuals must apply for litigation through law firms one by one.
The commission reported that it would pursue a plan to enable damage compensation through group litigation while also participating in discussions on class action lawsuits. The class action system is a method (opt-out) where if some victims win as representatives in litigation, all consumers who did not participate in the lawsuit can also receive compensation. However, currently in our country, class action lawsuits are only permitted in the securities sector.
In relation to this, President Lee said at the meeting, “You said you would make personal information breach accidents subject to group litigation and class action lawsuits, but now all citizens are victims,” adding “If you try to sue, litigation costs will be higher, so class action lawsuits must definitely be introduced. I hope you will speed up the legislation.”
In addition, the commission is also pursuing strengthening the effectiveness of the certification system, such as strengthening on-site technical examinations when receiving Information Security Management System-Personal Information (ISMS-P) certification. By the first half of next year, a plan to legislate management obligations for corporate representatives (CEOs) as final responsible parties for safe personal information processing and protection is also being pursued. This is intended to create awareness that this is work that the entire company must participate in, not just the work of some staff members.
The commission also reported the following as major tasks for next year: establishing a technical analysis center, reducing fines for companies with active investment, operating AX innovation support help desk, and creating a safe MyData ecosystem.
Song said “At a time when personal information breach accidents are rapidly increasing and data demand is growing due to AI transformation, we must fundamentally transform the personal information protection system,” adding “We will change the paradigm from document-based to field-centered, from post-incident sanctions to pre-incident prevention.”
출처 : Businesskorea(https://www.businesskorea.co.kr)
