Back to blog
regulationGDPRdata breachcompliancefines

South Korea: data-breach fines jump to 10% of revenue

Published on 2026-09-185 min readActionShield

> TL;DR: South Korea is raising data-breach fines to 10% of total revenue (from 3%) for companies that leak the data of 10 million or more people through intent or gross negligence. Coupang, fined $466M in June for 37.55 million people, could see its fine reach the trillions of won.

What changes concretely

The enforcement decree of the revised Personal Information Protection Act takes effect on September 11, 2026. Key points:

  • Fine up to 10% of total revenue (from 3%) for a leak of 10 million or more people, through intent or gross negligence.
  • Notification within 72 hours even if the breach is not yet confirmed, as soon as the risk of exposure is high.
  • Up to a 40% reduction of the fine for companies that invest in data protection (budget, staff, equipment, CPO) and that detect or notify quickly.
  • Stronger CPO powers: appointment, change and dismissal of the CPO require board approval at large companies.
  • The Coupang effect

    Coupang was fined 624.6 billion won ($466.3M) in June after leaking the data of 37.55 million people. Applied to that case, the new standard could push the fine into the trillions of won. The regulator wants data protection to become a preventive investment, not a routine cost.

    The reward for those who invest

    The most interesting point for product teams: investing in security reduces the fine. Up to a 40% reduction for companies that:

  • Invest continuously (budget, staff, equipment).
  • Detect the breach early.
  • Notify users quickly.
  • Prevent the damage from spreading.
  • It is one of the first major markets where the security budget is explicitly deducted from the fine.

    What it means for Europe and France

    The GDPR already caps fines at €20M or 4% of worldwide revenue. Korea goes further on two points: the percentage (10% vs 4%) and, more importantly, the explicit reduction for security investment. That is a strong signal: security is no longer only an obligation, it is a financial lever.

    What to check right now

  • Your exposure in a breach: how many people, what revenue, what potential fine?
  • Your ability to notify within 72 hours (or the GDPR deadline): do you have the process, the data, the contacts?
  • Your documented security investment: budget, staff, tooling. It is now a fine-reduction argument.
  • The role and mandate of your DPO/CPO: is it clearly defined, approved, and resourced?
  • The takeaway

    South Korea just did what many companies hope for: make security financially rational. If investing in security reduces your fine, then the question "is security worth it?" becomes "by how much does it reduce the risk?". That is exactly the calculation we help our clients make.

    Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Want to know what your AI agent can do?

    Tell us about your agent, its tools, and client context. We will come back with the right review scope.

    Discuss your audit