Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

South Korea president orders probe into Coupang data leak case

South Korean President Lee Jae Myung has ordered a full investigation into a major customer data leak at Coupang, an ecommerce company based in Seoul.

The breach reportedly exposed information from around 34 million cases and went undetected for five months.

During a Cabinet meeting on December 2, Lee called for strict accountability, and immediate action to prevent further misuse of leaked data.

He also urged the government to introduce stronger penalties, and improved countermeasures, referencing global standards for punitive damages.

Lee highlighted the growing frequency of data leaks and called for a new digital security framework covering both private and public sectors.

🔗 Source: The Korea Times

🧠 Food for thought

Implications, context, and why it matters.

Presidential office weighs punitive damages amid PIPA criticism

  • South Korea’s Personal Information Protection Act (PIPA) caps administrative fines (regulatory penalties) at up to 3% of revenue, and analysts expect Coupang penalties could reach several hundred billion to over one trillion won 12.
  • The presidential office called PIPA enforcement ‘not functioning’ 3. Rep. Choi Min-hee labeled Coupang’s breach an internal failure despite investing 1.917 trillion won in IT and 890 billion won in information security in 2025 2.
  • Officials are reviewing punitive damages (court-ordered sums meant to punish and deter, beyond compensating for harm) after the Coupang breach 2 to raise penalties beyond the administrative fine structure.
  • A move to punitive damages mirrors global enforcement trends and could reset compliance budgets.

Foreign cybersecurity vendors see demand under domestic representative rules

  • Starting October 2, 2025, PIPA requires foreign data controllers (companies outside Korea that determine how personal data is processed) to give annual training to domestic agents (their Korea-based representatives) 4. It also adds inspections to confirm those duties.
  • That shift creates demand from foreign data controllers with local agents for training programs, audit frameworks, plus monitoring tools built for Korean data protection rules.
  • The amendment mandates supervision through documented inspections (recorded, auditable checks) 4, opening opportunities for third-party audit and certification services.
  • Vendors can offer privileged access management (tools to manage high-risk administrator accounts) and zero-trust solutions (a ‘never trust, always verify’ security model). Authentication tokens (digital credentials that keep users signed in) stayed active for up to a decade without revocation 2.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.