Hacker News front pageNews Team3 min readintermediate
Korea raises data breach fines to 10% of revenue
Summary
South Korea’s privacy regulator will fine companies up to 10 % of revenue for large‑scale data breaches, a jump from the previous 3 % cap. The rule applies to intentional or grossly negligent leaks affecting 10 M+ people, with reductions for proactive security investments and rapid breach response. Companies must also notify users within 72 hours of a high‑risk exposure.
- Fines rise from 3 % to 10 % of total revenue for breaches affecting ≥10 M users, or for repeat intentional/gross‑negligent violations.
- Fine reductions of up to 40 % are available for companies with documented security budgets, staffing, and rapid breach containment/reporting.
- New “potential breach” rule forces 72‑hour notification when a high likelihood of exposure is identified, even without confirmed loss.
- Large firms (≥180 B won revenue) processing ≥1 M users’ data must get board approval for chief privacy officer appointments and report changes to the regulator.
The regime turns data protection from a compliance checkbox into a financial risk driver, forcing enterprises to budget for security tooling, staff, and incident‑response processes. Early breach detection and reporting now have a direct monetary incentive, which should shift investment toward preve…
3/10





