Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang’s US HQ faces class-action lawsuit over data breach

Coupang’s global headquarters in Seattle faces a class-action lawsuit after a major data breach that compromised information from 33.7 million customers.

Coupang is a South Korea-based ecommerce company with operations in the US.

The US branch of Daeryun law firm, SJKP, announced plans to file a lawsuit seeking punitive damages, following a press conference on November 7.

Daeryun plans to pursue litigation against Coupang in both South Korea and the US.

On November 29, Coupang reported that names, phone numbers, email addresses, and delivery details of 33.7 million customers were exposed.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

PIPA exposure includes up to 3% revenue penalties, KRW 50 million fines, and punitive damages up to five times

  • South Korea’s Personal Information Protection Act (PIPA) allows administrative surcharges and penalties up to 3% of sales for defined violations, plus prison terms up to five years and criminal fines up to KRW 50 million 12. For breaches affecting 1,000 or more data subjects, controllers (the entities that determine the purposes and means of processing) must notify regulators within 72 hours 2. Coupang’s incident meets the reporting threshold, and any penalties will depend on the Personal Information Protection Commission (PIPC) investigation.
  • Punitive damages can reach five times actual losses when a controller’s intentional act or negligence causes a breach 2. Recent cases set the scale. Temu paid KRW 1.386 billion for undisclosed overseas data transfers, and its app had about 2.9 million Korean daily users in 2023 3.
  • The PIPC has been active. It fined travel company Modutour KRW 757.2 million 4. It also fined Temu affiliates Whaleco Technology KRW 879 million and Elementary Innovation KRW 490 million 3.

Identity protection vendors should target Coupang’s 33.7 million affected users and South Korean enterprises prioritizing breach response

  • PIPA requires notice to affected data subjects within 72 hours 5. That creates immediate demand for breach response support among Coupang customers. Vendors with Korean-language tools can help organizations meet these duties.
  • After SK Telecom’s breach, which its CEO called the worst in telecom history 6, enterprises face more scrutiny and new insurance expectations. Security providers should offer support for PIPA security duties, including encryption 5, strong access controls, and data discovery.
  • The government plans to toughen certification screening for information security systems after the Coupang incident 6. That opens space for vendors aligned with Korea’s required technical, physical, and organizational security measures 5.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.