Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang founder to skip parliamentary hearing over data breach

Coupang founder Kim Bom-suk will not attend a parliamentary hearing this week regarding a major data breach at the ecommerce firm, according to South Korean lawmakers.

Coupang, which is listed in the US and operates one of South Korea’s largest online shopping platforms, reported in late November that personal data belonging to 33.7 million users had been exposed.

The breach included names, phone numbers, emails, and delivery information.

Kim, who also chairs Coupang’s board, cited business obligations as the reason for his absence in a statement sent to lawmakers.

Two former CEOs of Coupang’s Korean unit, Park Dae-jun and Kang Han-seung, also said they would not appear.

Members of the parliamentary science, ICT, broadcasting, and communications committee criticized the decision, and said they plan to seek legislation to prevent executives of large platform companies from evading responsibility.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

PIPA penalties tie to total revenue and violation type

  • Meta paid $15.67 million for violations affecting about 980,000 users 1. Temu was fined $978,000 over undisclosed data transfers, and its app drew 2.9 million Korean users per day in 2023 2. Golfzon received a $5.2 million penalty for a breach, the largest domestic penalty 3.
  • The 2023 PIPA revision now bases administrative fines on total revenue, excluding unrelated sales 3. Coupang’s breach hit 33.7 million users. Penalties can reach 3% of total revenue for some security failures, depending on findings 43.

Vendors can pitch firms facing Korea’s 2025 domestic representative rule

  • From October 2, 2025, foreign entities must appoint a domestic representative if they meet set thresholds 3. This party handles regulatory communications and compliance. Triggers include over KRW 1 trillion in annual revenue, daily processing of more than one million Korean data subjects on average in the last three months of the previous year, or a request under PIPA article 63(1) 3.
  • The regulator is building a forensic lab and a dedicated litigation team 5. PIPC will run proactive inspections in 2025 5. It is pursuing legislation for statutory certifications and security-certified IP cameras, while expanding Privacy by Design certifications for IT devices, which embeds privacy protections into products from the outset 5.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.