🧔♂️ A friendly human may check it before it goes live. More news here
South Korea denies bias in Coupang investigation
South Korean Prime Minister Kim Min-seok and US Vice President JD Vance discussed the investigation into Coupang, emphasizing that Seoul does not view the probe as unfair treatment.
The two officials exchanged direct contact numbers to establish a hotline aimed at preventing misunderstandings over the matter.
Kim clarified that the Korean government has not discriminated against US firms, including Coupang, and provided Vance with translations of relevant statements.
The discussion followed claims from US investors that petitioned the US Trade Representative to investigate Korea for alleged discriminatory actions against Coupang, which they say caused significant financial losses.
Kim also addressed the data breach involving 33.7 million customers and the delayed reporting, stating that Korea’s legal system is involved in the case.
🔗 Source: The Korea Times
🧠 Food for thought
Implications, context, and why it matters.
The diplomatic dispute adds pressure, but Coupang’s core exposure remains regulatory and litigation risk
- Talks between officials have focused on claims of “discriminatory treatment,” while the legal basis for South Korea’s review of Coupang’s breach response is still being weighed.
- Under South Korea’s Personal Information Protection Act (PIPA), notice to the regulator and affected individuals is generally required within 72 hours after a personal data breach is discovered 1.
- Unauthorized access was said by Coupang to have started as early as June 2025, and awareness was reported on Nov. 18, 2025; 33.7 million South Korea customer accounts were later said to have been likely exposed 2.
- Fines of up to 3% of total revenue could be assessed under the amended PIPA, depending on regulatory findings, and past cases are expected to be used for comparison 3.
- A KRW 7.5 billion (about $5.2 million) administrative penalty was issued to Golfzon by the Personal Information Protection Commission (PIPC) in May 2024 after a data breach; it was described as the largest penalty imposed on a domestic company 3.
Coupang case underscores compliance demand for foreign tech firms operating in South Korea
- Investors and compliance software providers may see more buying interest from foreign firms that operate in South Korea.
- The PIPC says PIPA can apply to foreign businesses in some situations, including when goods or services are offered to Korean data subjects or when there is a direct and significant impact, based on its April 2024 guidelines 4.
- That pushes demand for tools that fit local rules, such as workflows to hit the 72-hour breach notice window after discovery; certain large foreign entities may also need help naming a domestic representative (a locally based point of contact for regulators and data subjects) 1, 3.
- Penalties tied to cross-border data transfer problems, including cases involving Apple Distribution International Limited, also support the need for South Korea focused compliance support 3.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




