Compare with different regulatory event:

Description

Issued ruling in investigation into KARA Solution over personal data leakage

On 22 March 2023, the Korean Personal Information Protection Committee (PIPC) issued a ruling in its investigation into KARA Solution Co. (Kara), imposing a fine of imposes a fine of KRW 3.78 million and a penalty of KRW 12 million. The PIPC found that Kara failed to implement appropriate security measures for the personal data processing system and did not impose authentication methods. Additionally, Kara's administrator page leaked the personal data of 1'664 users when Kara attempted to change the authentication methods for access. The data leakage was due to the fact that the administrator page's URL was publicly exposed to search engines during that process. Finally, the access records of the processing system were not preserved for at least a year as required by law, and Kara failed to report the leakage in the time frame required.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
platform intermediary: other
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-03-22
in force

On 22 March 2023, the Korean Personal Information Protection Committee (PIPC) issued a ruling in it…