
Coupang has been fined a total of 624.68 billion won over a personal data breach affecting 37.5 million members. The penalty is the largest ever imposed by the government on a company for a personal data leak, 4.6 times the previous record of 134.8 billion won levied on SK Telecom over its USIM data breach. The amount nearly matches Coupang's operating profit last year of 679 billion won.
The Personal Information Protection Commission said Tuesday it had approved the measure at a plenary session on Monday, addressing violations of the Personal Information Protection Act by Coupang and its subsidiaries. Coupang was fined 423.575 billion won and charged a penalty of 16.8 million won in connection with the data breach, along with a 201.106 billion won fine for infringing on users' rights. The commission also approved corrective measures to prevent recurrence, including strengthening safety measures, notifying non-member data subjects of the leak, and ensuring the substantive role of the chief privacy officer (CPO).
Coupang Fulfillment Services (CFS), the company's logistics subsidiary, was also fined 248 million won for violations involving the collection and use of personal information and restrictions on processing sensitive information.
The investigation found that the personal information of 37.5 million people was leaked because Coupang failed to establish a proper safety management system, including poorly managing the electronic signature keys used for server authentication and failing to block access by a former employee. It was also confirmed that Coupang collected the online activity records of about 11.17 million members who accessed other companies' websites and apps without their consent, and stored the data in a database (DB) in a form that could identify users.
Song Kyung-hee, chairwoman of the Personal Information Protection Commission, explained the rationale for the sanctions, saying, "This investigation confirmed that Coupang grew rapidly by providing innovative e-commerce services based on large-scale customer information, but failed to establish a security management system commensurate with that."
In response, Coupang said, "We apologize for causing concern to our customers and the public over the personal data leak," adding, "We will further strengthen our personal data protection framework and work to restore customer trust."






