Korea raises data breach fines to 10% of revenue
South Korea's privacy regulator is raising the maximum fine for large-scale data breaches to 10% of a company's revenue, effective immediately. The change targets cases involving intent or gross negligence where at least 10 million people's personal data is exposed.
Why this matters: Fines set as a flat penalty are easy to treat as a line item. A percentage of revenue is harder to ignore, especially for large companies where a flat cap barely registers. Korea is making the math personal: the bigger you are, the more a breach costs you. That is a meaningful shift. It pushes companies to spend on protection before something goes wrong, not just pay up after. Other regulators will be watching to see if it actually changes behavior.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.