Korea raises data breach fines to 10% of revenue

South Korea plans to fine companies up to 10% of revenue for data breaches caused by intent or gross negligence, a level many see as potentially existential for large firms. Commenters debate whether such steep, revenue-based penalties will finally make organizations take security and data minimization seriously, or simply encourage legal arbitrage, under-reporting, and selective enforcement—especially for powerful domestic conglomerates. Comparisons to GDPR and other regimes highlight broader questions about how to align corporate incentives, define “gross negligence,” and ensure governments face similar accountability for breaches.

Law scope and deterrent goal

  • Fines of up to 10% of revenue are seen as potentially “business‑threatening” and therefore more than a cost of doing business.
  • Several commenters think this is exactly the kind of shock needed to make companies prioritize security and privacy.
  • Others note it only applies for “intent or gross negligence,” which may limit real-world use and is legally a high bar.

Enforcement, chaebols, and foreign targets

  • Skepticism that such fines will ever be fully applied to large domestic conglomerates; some expect de facto exemptions.
  • Some suspect the law is aimed mainly at foreign firms handling Korean data.
  • Unclear how aggressively regulators will apply the maximum penalties or treat repeated offenses.

Feasibility of secure systems

  • Debate over whether truly secure, usable systems are possible: some say “no system is fully secure,” others argue high security is achievable with diligence, encryption, and process.
  • Point that most breaches stem from social engineering, where even strong technical controls can fail.
  • Consensus that “perfection” isn’t required; the legal line is gross negligence and lack of due diligence.

Economics, incentives, and caring vs profit

  • Strong theme: firms optimize for profit; without large fines, skimping on security is rational.
  • Others argue professionalism, reputation, and future valuation also incentivize robust security, especially in B2B and sensitive sectors like healthcare.
  • Some see modern business culture as increasingly low‑trust and willing to treat fines as a line item.

Liability games and shell companies

  • Example of universities or firms offloading data to thinly capitalized entities that can go bankrupt after a breach, effectively dodging consequences.
  • Counterpoints: data laws (like Korea’s PIPA, compared to GDPR) and certification regimes require due diligence through the supply chain, making such tricks harder.
  • Discussion of “piercing the corporate veil” and potential legal changes to explicitly prevent liability evasion; practical effectiveness remains unclear.

Data minimization and practical limits

  • Strong support for “collect less, store less” as the only foolproof way to avoid leaks.
  • Recognition that some data retention is legally mandatory (e.g., transaction records, university records), so elimination isn’t always feasible.
  • Suggestion to treat personal data like cash: keep minimal amounts on-premise and rely on specialized, heavily audited custodians.

Comparisons and alternative penalty designs

  • GDPR’s 4% of global revenue and UK rules are cited as precedents; commenters note frequent breaches despite these caps, implying under‑enforcement.
  • Reference to the EU AI Act’s higher turnover-based penalties as evidence such frameworks are politically possible.
  • Some propose per‑person damage tariffs (e.g., fixed amounts per leaked email, SSN, password), possibly with very high values for especially sensitive identifiers, and automatic direct compensation to affected individuals.
  • Concern that tying fines to “intent or gross negligence” ignores the victim’s perspective: harm is harm regardless of the internal cause.

Unintended consequences and open questions

  • Worry that very high fines could incentivize breach under‑reporting or complex liability structures.
  • Questions about how public-sector breaches (e.g., city governments) would be handled, given they often escape meaningful punishment.
  • Some raise geopolitical risk: hostile state actors could deliberately trigger ruinous fines as economic sabotage.
  • Overall sentiment: law is a positive step if—and only if—seriously enforced and accompanied by clear standards for negligence and liability.