[Editorial] Coupang Data Breach Sanctions Must Hold It Accountable, but Be Proportionate
-
Writer
CFE
-
The Personal Information Protection Commission has decided to impose a surcharge of 62.4681 billion won—the highest level ever—and an administrative fine of 16.8 million won in the Coupang personal data leak case. This incident cannot be taken lightly, given that it involved a data breach at a platform company holding large-scale user information. However, if the surcharge is excessively large, it may violate the principle of proportionality.
Personal information is a core asset of the digital economy and the foundation of consumer trust. Since companies collect and use users’ personal information to provide services, they must bear corresponding security responsibilities and management obligations. That said, the importance of personal information protection does not automatically justify unlimited or symbolic sanctions.
Administrative sanctions must be imposed according to law and principle, not according to the intensity of public opinion or the size of the company. Surcharges should not be calculated solely based on the number of leaked records; they should comprehensively take into account factors such as the sensitivity of the leaked information, whether there was intent or gross negligence, whether actual harm or secondary harm occurred, when the incident was recognized and reported, and what post-incident responses and recurrence-prevention efforts were made. This is the kind of sanctioning approach that accords with the rule of law and the principle of proportionality.
In this case, Coupang argues that the timing of its recognition of the incident—five months—was relatively faster than in other comparable cases, and that highly sensitive information such as financial or payment information, USIM authentication keys, and government-issued identification was not leaked, and that these should be considered mitigating factors. It also states that, based on verification by a specialized firm, no circulation of the leaked information on the dark web or elsewhere, nor any secondary harm, was confirmed, and that it made its own efforts to recover the information. These circumstances cannot serve as grounds to exempt the company from responsibility, but they are factors that should be examined from the standpoint of proportionality and fairness when determining the level of sanctions.
Some public opinion has called for sanctions at the maximum level permitted by law. It is understandable to believe that a strong warning is needed in response to repeated personal data leak incidents. However, demanding the maximum legal sanction in advance risks turning administrative sanctions into a trial by public opinion.
The purpose of sanctions is not to publicly punish companies, but to raise the level of personal information protection and induce the prevention of recurrence. Excessive sanctions that go beyond the actual harm and the nature of the violation may do nothing more than increase regulatory avoidance and legal uncertainty, rather than expand corporate investment in security.
This case also invites a broader review of the direction of Korea’s personal information protection regulatory system. Until now, personal information protection policy has tended to lean toward prior regulation and formalistic compliance, such as consent forms, notice obligations, internal management plans, and adherence to various certifications and procedures. In an environment where digital platforms, cloud computing, artificial intelligence, and data combination have become routine, it is difficult for the government to define and control every risk in detail in advance. It is now necessary to shift away from formal prior regulation toward an ex post regulatory approach that centers on actual management responsibility, whether damage occurred, the speed of the response, and the effectiveness of recurrence-prevention measures when an incident occurs.
In addition, the government must not remain only in the role of an ex post punisher of individual companies. Personal data leaks and cybersecurity threats are also linked to the stability of the national digital infrastructure. The government should establish security governance at the national level and systematically support the sharing of threat information, responses to breach incidents, diagnosis of security vulnerabilities, and the strengthening of security capabilities among small and medium-sized enterprises and mid-sized firms. Punishment alone cannot raise the level of security; what is needed is a security ecosystem in which the public and private sectors work together.
This decision may become a benchmark not only for sanctions against Coupang, but also for digital platforms and companies holding large-scale user information more broadly in the future. The Personal Information Protection Commission should make clear the strictness of personal information protection while presenting reasonable standards that do not undermine legal stability and predictability. When sanctioning standards are clear and proportionate, companies will expand security investment, and consumers will be able to trust the system.
Rather than relying only on the imposition of surcharges, the government should acknowledge the failure of formal, prior regulation-centered controls and move toward ex post regulation and the establishment of national-level security governance. The effectiveness of personal information protection comes not from a race to impose the highest possible surcharge, but from consistent sanctions based on law and principle, voluntary corporate investment in security, and systematic government support for security.
Original title: [논평] 쿠팡 개인정보 유출 제재, 책임은 묻되 비례 원칙에 따라야 한다
Author: Center for Free Enterprise (CFE)
Date: 2026-06-11
Source: https://www.cfe.org/bbs/bbsDetail.php?cid=comment&pn=1&idx=29122
