South Korea: data-breach fines jump to 10% of revenue
> TL;DR: South Korea is raising data-breach fines to 10% of total revenue (from 3%) for companies that leak the data of 10 million or more people through intent or gross negligence. Coupang, fined $466M in June for 37.55 million people, could see its fine reach the trillions of won.
What changes concretely
The enforcement decree of the revised Personal Information Protection Act takes effect on September 11, 2026. Key points:
The Coupang effect
Coupang was fined 624.6 billion won ($466.3M) in June after leaking the data of 37.55 million people. Applied to that case, the new standard could push the fine into the trillions of won. The regulator wants data protection to become a preventive investment, not a routine cost.
The reward for those who invest
The most interesting point for product teams: investing in security reduces the fine. Up to a 40% reduction for companies that:
It is one of the first major markets where the security budget is explicitly deducted from the fine.
What it means for Europe and France
The GDPR already caps fines at €20M or 4% of worldwide revenue. Korea goes further on two points: the percentage (10% vs 4%) and, more importantly, the explicit reduction for security investment. That is a strong signal: security is no longer only an obligation, it is a financial lever.
What to check right now
The takeaway
South Korea just did what many companies hope for: make security financially rational. If investing in security reduces your fine, then the question "is security worth it?" becomes "by how much does it reduce the risk?". That is exactly the calculation we help our clients make.
Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
DGFiP Breached by ZeroBytes: Inside France's Biggest Tax Data Leak of 2026
France's tax authority (DGFiP) confirmed unauthorized access to its information system: impersonated agent credentials, no blanket MFA, and over 2 million people potentially exposed through the cadastral records server.
Free 2024: 24 Million Accounts Exposed, IBANs Included, and CNIL's Record Fine
A look back at the October 2024 Free/Free Mobile cyberattack: 24 million contracts exposed, IBANs leaked for dual-play subscribers, and the 42 million euro fine imposed by CNIL for security failures.
CNIL 2025: €487M in fines. What small SaaS teams should take away
Record CNIL fines in 2025. Analysis and concrete lessons for businesses.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant ActionShield audits.