Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

SK Telecom challenges $91m fine over data breach impacting users

SK Telecom has filed a lawsuit with the Seoul Administrative Court to challenge a 135 billion won (US$91 million) fine imposed by South Korea’s Personal Information Protection Commission (PIPC) over a data breach last year, industry sources said on January 19.

The mobile carrier received the fine in August after disclosing a leak of USIM data affecting its 23 million users, prompting the company to offer free replacements and cooperate with regulators.

SK Telecom is expected to argue that it has invested 1.2 trillion won in user compensation and data protection reforms since the breach, and that no confirmed financial damage occurred to users.

🔗 Source: The Korea Times

🧠 Food for thought

Implications, context, and why it matters.

Recent court rulings suggest SK Telecom’s appeal faces significant hurdles

  • SK Telecom’s argument about unfair treatment versus Google and Meta is being weighed against a recent Seoul Administrative Court ruling, where a combined fine of about 100 billion won was upheld and the tech firms’ appeal was rejected 1.
  • Kakao’s bid to cancel a 151 billion won penalty was also dismissed by the Seoul Administrative Court, with the regulator’s view being accepted that required security and notification duties were not met after a data leak 2.
  • In smaller disputes, fines have been affirmed after technical gaps were examined, including weak monitoring of unusual login attempts 3.

The record fine and regulator’s 2025 roadmap create a clear market for compliance tech

  • SK Telecom’s record penalty gives technology vendors and investors a stronger reason to build and sell data security tools in South Korea.
  • The unprecedented amount may push firms that handle sensitive personal data, especially those with large consumer user bases, to spend more on breach prevention, detection, and response.
  • The Personal Information Protection Commission (PIPC), South Korea’s state data protection regulator, set a 2025 enforcement plan that targets four sectors for closer investigation, sharing platforms, digital finance, real estate, and edutech 4.
  • The regulator also listed AI services, including HR and legal tech solutions, for pre-emptive inspections, which can help vendors aim outreach at teams most likely to be reviewed 5.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.