Korea raises data breach fines to 10% of revenue
Korea raises data breach fines to 10% of revenue
韩国将数据泄露罚款上限提高至营收的 10%
Companies behind major negligent data leaks can now face fines of up to 10 percent of annual revenue under revised privacy rules. 根据修订后的隐私法规,因重大疏忽导致数据泄露的企业,现在可能面临最高相当于其年度总营收 10% 的罚款。
Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business. 韩国隐私监管机构正在大幅提高数据泄露的代价,旨在促使企业将数据保护视为一种预防性投资,而非日常经营成本。
Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence can be fined up to 10 percent of their total revenue as part of a broader overhaul under the revised Personal Information Protection Act that is set to take effect the same day. 从周五开始,根据修订后的《个人信息保护法》,对于因故意或重大过失导致 1000 万人以上个人数据泄露的企业,最高可处以其总营收 10% 的罚款。该法案已于同日生效。
Even if a leak hasn’t been confirmed, companies must notify users within 72 hours if the risk of exposure is high. 即使尚未确认发生泄露,如果存在高风险,企业也必须在 72 小时内通知用户。
“Personal data breaches have recently occurred repeatedly and grown in scale in fields closely tied to daily life, such as retail and telecommunications,” Personal Information Protection Commission (PIPC) Secretary General Yang Cheong-sam told reporters Thursday. “We’ve improved the system to hold serious violations strictly accountable while also helping prevent breaches from happening in the first place.” 个人信息保护委员会(PIPC)秘书长杨清三(音译)周四对记者表示:“近期,在零售和电信等与日常生活密切相关的领域,个人数据泄露事件频发且规模不断扩大。我们改进了制度,旨在对严重违规行为进行严格问责,同时帮助从源头上预防泄露事件的发生。”
Under the enforcement decree, the cap applies to companies that repeatedly commit intentional or grossly negligent violations within three years, or that fail to comply with a corrective order and go on to suffer a breach as a result. Fines are calculated based on the nature and severity of the violation, the circumstances involved and the scale of the damage. 根据施行令,该上限适用于三年内多次发生故意或重大过失违规行为,或因未遵守整改命令而导致数据泄露的企业。罚款金额将根据违规性质、严重程度、相关情况及损害规模进行计算。
Before the revision, companies were subject to a penalty of up to 3 percent of sales. The gap between the old and new rules becomes clear when applied to a real case. Local e-commerce giant Coupang was fined 624.6 billion won ($466.3 million) in June after leaking the personal data of 37.55 million people. Applying the new standard to that case could push the fine into the trillions of won. 修订前,企业面临的罚款上限为销售额的 3%。将新旧规则应用于实际案例时,差距显而易见。本土电商巨头 Coupang 因泄露 3755 万人的个人数据,在 6 月被罚款 6246 亿韩元(约合 4.663 亿美元)。若按新标准计算,该罚款额可能达到数万亿韩元。
However, actual penalties will still depend on intent, negligence, the scale of damage and any mitigating factors. 当然,实际处罚仍将取决于违规意图、过失程度、损害规模以及任何减刑因素。
Companies that invested in data protection beforehand will get credit under the new rules. Regulators will consider the scale and continuity of a company’s investment in data protection budgets, staffing and equipment, along with its broader protection system, including its chief privacy officer, to reduce a fine by up to 40 percent. 根据新规,此前在数据保护方面进行过投资的企业将获得认可。监管机构将考量企业在数据保护预算、人员配备和设备方面的投资规模及持续性,以及包括首席隐私官在内的更广泛保护体系,从而将罚款金额最高降低 40%。
A company that detects a breach early, reports and notifies users promptly, and prevents the damage from spreading can also receive up to a 40 percent reduction. 如果企业能及早发现泄露、及时报告并通知用户,并防止损害扩大,同样可以获得最高 40% 的减免。
The revision also introduces a “potential data breach notification system.” If a company determines there is a high likelihood that personal data was exposed — for instance, after illegal access to its data processing systems, or after discovering that some personal data was illegally traded in a way that suggests others’ data may have leaked too — it must notify affected individuals within 72 hours of learning that. 此次修订还引入了“潜在数据泄露通知制度”。如果企业认定个人数据极有可能已泄露——例如在数据处理系统遭到非法访问后,或发现部分个人数据被非法交易,且迹象表明其他数据也可能已泄露——则必须在获悉后的 72 小时内通知受影响的个人。
Data forged, altered or damaged by ransomware and similar attacks is now also subject to the same reporting and notification requirements. 因勒索软件及类似攻击而被伪造、篡改或损坏的数据,现在也适用同样的报告和通知要求。
The authority and responsibility of chief privacy officers at major companies and institutions will also expand. Companies with annual revenue exceeding 180 billion won that process the personal data of 1 million or more people, or the sensitive or unique identifying information of 50,000 or more people, must get board approval before appointing, changing or dismissing a chief privacy officer and report the decision to the PIPC. 大型企业和机构首席隐私官的权责也将扩大。年营收超过 1800 亿韩元且处理 100 万人以上个人数据,或处理 5 万人以上敏感/唯一识别信息的企业,在任命、更换或解聘首席隐私官前必须获得董事会批准,并向 PIPC 报告该决定。
Universities with 20,000 or more students, tertiary general hospitals and operators of major public systems fall under the same requirement. 拥有 2 万名以上学生的大学、三级综合医院以及主要公共系统的运营方也适用同样的要求。
“We expect the way companies view investment in data protection to shift from seeing it as a cost to treating it as a proactive investment that builds customer trust and expands corporate profit,” PIPC’s Chairperson Song Kyung-hee said. PIPC 主席宋京熙(音译)表示:“我们期望企业对数据保护投资的看法能发生转变,从将其视为一种成本,转变为将其视为一种能够建立客户信任并扩大企业利润的积极投资。”