Description

Issued PIPC ruling following investigation into alleged e-commerce data protection violations

On 24 October 2024, the Personal Information Protection Commission (PIPC) issued a ruling in an investigation into two e-commerce businesses. The PIPC determined that Neopharm and Ilhak failed to protect personal information under the Personal Information Protection Act and imposed fines and penalty surcharges totalling KRW 123.17 million. Neopharm received a fine of KRW 151.7 million for allowing unauthorised access to the personal information of 293,723 members, while Ilhak was fined KRW 18 million after a hacker's SQL injection attack led to the leak of personal information of 10’000 individuals. The Commission mandated public announcements of these rulings on the companies' websites, underscoring the need for stringent security measures and periodic security checks to prevent future breaches.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
platform intermediary: e-commerce
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-10-23
in force

On 24 October 2024, the Personal Information Protection Commission (PIPC) issued a ruling in an inv…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.