South Korea's revised privacy statute triples the maximum fine and adds a 72 hour notification clock, but offers a 40% credit for companies that already invest in prevention.
The cap on South Korean data breach fines moved from 3% to 10% of revenue on Friday, and the regulator built a 40% off-ramp into the same statute for companies that already invested in prevention.
Under the revised Personal Information Protection Act (PIPA), the Personal Information Protection Commission can now fine a company up to 10% of total revenue when a breach exposes the data of 10 million or more people through intent or gross negligence, or when a company that has already been ordered to fix a problem then suffers another breach. The old cap was 3% of sales. On the same set of facts, that is more than a threefold increase in the metric the fine is calculated against. The fine is calculated from the nature and severity of the breach, the circumstances, and the scale of the damage.
Coupang's June 2026 fine is the cleanest test of what the new ceiling can do. The Commission fined Coupang, South Korea's largest e-commerce platform, 624.6 billion won (about $466.3 million) for a 2022 breach that exposed data on 37.55 million users. That ruling landed under the old 3% cap. Under the new 10% cap, the same user count and the same kind of negligence would push the fine into the trillions of won, even before any repeat-offender escalation is applied. The size of the multiplier is why the regulator is willing to talk about the statute in trillion-won terms.
The statute also shortens the clock. A company that detects a likely breach now has 72 hours to notify affected users, even when the company itself has not confirmed that any data was actually exposed. The old framework waited for confirmation. The new one does not, which means the notification decision has to be made on partial evidence inside a three-day window. The 72-hour clock is the operational shift: the cap is the visible change, and the clock is the part that changes what a security team has to do on day one.
The statute also includes a credit. Companies that can show prior investment in data-protection budgets, staffing, equipment, and a working chief privacy officer can have the fine reduced by up to 40% on a graduated scale, with the credit scaling up as the investment grows. Read alongside the new ceiling, the regime is two-sided: a higher price for bad behavior, and a lower price for companies that already built the prevention function. The credit is graded, not all-or-nothing, and the regulator is signaling that a real prevention program, not a written policy, is what earns the discount.
Retail and telecommunications are the repeat-offender sectors the Commission named on Thursday, when Secretary General Yang Cheong-sam briefed reporters on the new rules. Yang framed the package as a behavior-change tool rather than a fine-collector; the prevention credit is what makes that framing operative. The regulator wants the new ceiling to be expensive enough to be deterrent and the credit to be generous enough to be worth chasing.
The next data point to watch is the first 10-million-user breach filed under the new rules, and the size of the prevention credit the Commission grants the company that asks for one.