CONTENTS
- 1. Why the U.S. Courts Became the Forum for Examining "Substantive Responsibility"

- - The Strategic Significance of the Choice of Jurisdiction
- - The Expansion of "Standing as a Defendant" and the Legal Theory of Chairman Bom Kim's Personal Liability
- 2. The Issue of Violation of the New York General Business Law (N.Y. GBL §349)

- - Discovery Strategy and the Identification of Governance Failure
- - Equitable Relief and the Significance of Declaratory Relief and Injunctions
- - The Class and Subclass Strategy
- - Punitive Damages and the Possibility of a Precedent
- 3. What Is the Scope of Management Responsibility in the Digital Age?

1. Why the U.S. Courts Became the Forum for Examining "Substantive Responsibility"

The recent Coupang incident, in which a leak of personal information affecting as many as 33 million people has been confirmed, has prompted active legal discussion both in Korea and abroad.
While civil and criminal proceedings are being prepared in Korea, SJKP, LLP, a U.S. law firm, filed a separate class action before the United States District Court for the Eastern District of New York (EDNY).
This has raised the question of why a U.S. court was chosen for an action against a company that generates most of its revenue in Korea.
SJKP stated that the central aim of this litigation is to hold Coupang's U.S. parent company, Coupang Inc., to substantive account and to compel structural improvements in its security governance.
The Strategic Significance of the Choice of Jurisdiction
Coupang Inc. is an entity incorporated under U.S. law, and it is the parent company that holds 100% of the equity in the Korean entity.
This carries significant meaning in that the company's policy decisions and governance structure are subject to the U.S. legal system.
SJKP's filing of an action against the U.S. headquarters in a U.S. court appears to have been driven by the following factors.
First, U.S. law tends to recognize broad liability for violations of personal information protection duties.
Second, a punitive damages system exists, which makes it possible to impose substantive liability for serious negligence or managerial neglect.
Third, through "discovery," a core procedure of U.S. civil litigation, internal decision-making materials can be compelled to be produced.
To identify substantive responsibility in cross-border data breach cases, procedural means that allow the decision-making structure to be confirmed through objective evidence, beyond a claim for compensation, are necessary.
In this respect, U.S. litigation may be regarded as a strategic judicial battleground.
The Expansion of "Standing as a Defendant" and the Legal Theory of Chairman Bom Kim's Personal Liability
A noteworthy point is that not only Coupang Inc. but also Chairman Bom Kim has been named as a co-defendant.
Under U.S. federal law and the relevant precedents, where a company's unlawful conduct results from direct approval, substantive control, or serious managerial neglect by management, the officer in question may bear personal liability separately from the corporation.
SJKP has put forward the legal position that Chairman Bom Kim, as the ultimate decision-maker over security policy and budget, should bear substantive responsibility for the failure of internal controls.
The complaint sets out grounds including Negligence, Negligence Per Se, Unjust Enrichment, breach of implied contract, and violation of New York State statutes.
This case raises the important legal issue of how far the scope of a chief executive's responsibility for data security should be recognized.
2. The Issue of Violation of the New York General Business Law (N.Y. GBL §349)
Section 349 of the New York General Business Law prohibits acts or practices that deceive consumers.
Where the information a company provides to consumers differs from the facts or is capable of misleading them, such conduct may be assessed as unlawful.
If Coupang continuously conveyed the impression to the outside world that it maintained an adequate security system, there may be room to find a deceptive practice where the security framework actually in operation fell significantly short of that.
In that event, legal responsibility may extend beyond the question of a system error to the overall decision-making structure that oversaw security policy.
Ultimately, beyond the data leak incident, the question is whether the "trust in security" that the company provided to consumers was justified.
Discovery Strategy and the Identification of Governance Failure
The most important procedural device in U.S. litigation is discovery.
Through it, the production of various documents, such as internal emails, meeting minutes, security vulnerability reports, and budget allocation materials, can be demanded.
If circumstances are confirmed indicating that, despite internal awareness of a security vulnerability, remediation was delayed for reasons of cost reduction or the maintenance of profitability, the matter is assessed as serious managerial neglect rather than mere negligence.
At this point, the matter expands into a determination of whether there was a structural failure of corporate governance, and this may serve as an important precedent in similar cases going forward.
Equitable Relief and the Significance of Declaratory Relief and Injunctions
Unlike Korean civil litigation, which focuses mainly on monetary compensation, U.S. courts can compel specific corporate conduct through Declaratory Relief and Injunctive Relief.
In this litigation, measures such as the establishment of a top-tier security system, the mandating of multi-factor authentication, the provision of long-term identity theft monitoring services, and enhanced protection for vulnerable groups have been requested.
The purpose of this is to structurally reorganize the company's security framework.
Equitable relief is significant in that it does not stop at after-the-fact compensation but serves as a means of compelling the prevention of recurrence on an institutional level.
The Class and Subclass Strategy
SJKP designated New York residents as representative plaintiffs among the affected individuals while establishing Korea-resident victims as a separate subclass.
A subclass is a mechanism for procedurally protecting the rights of a group with a different place of residence or applicable law.
Through this, Korean consumers may also share in the effect of a U.S. court's judgment, and the benefits of equitable relief, such as orders to strengthen security, may likewise be extended to them indirectly.
This is noteworthy as a cross-border consumer protection strategy.
Punitive Damages and the Possibility of a Precedent
A punitive damages system exists in the United States. Where serious negligence is found, the scale of compensation expands considerably.
In the past large-scale personal information leak case involving T-Mobile, a settlement amounting to hundreds of millions of dollars was reached, together with a separate commitment to invest in strengthening the security system.
In this case as well, if serious managerial neglect is found, there is the possibility that an order to improve the company's overall security framework will accompany the scale of compensation.
3. What Is the Scope of Management Responsibility in the Digital Age?
The leak of the personal information of 33 million people may be assessed as a problem of the company's internal control system and governance structure.
This litigation appears likely to serve as an occasion confirming that a global company cannot avoid responsibility on the ground of national borders, and it is expected to become an important forum for legal discussion that makes clear that a chief executive's decisions bear directly on the protection of personal information.
In the digital age, the protection of personal information is not an optional cost but a core element of corporate survival.
This case once again raises the question of the scope of that responsibility.
Daeryun Law Firm provides comprehensive advisory on domestic and international personal information protection regulations on the basis of its cooperative framework with SJKP.
Specifically, it supports companies in managing legal risks in advance through measures such as ▲diagnosing personal information protection governance ▲reviewing management oversight duties ▲organizing security policies and internal rules ▲designing internal control systems that meet the standards for overseas listed companies ▲preparing response scenarios in the event of a breach.
For the protection of personal information, advance design is far more important than after-the-fact response.
In particular, for companies with a global business structure, integrated advisory that takes into account not only domestic law but also U.S. and other overseas regulations is necessary.
Daeryun, within such a complex environment, focuses on helping companies examine structural risks and design systematic preventive strategies so that the same incident does not recur.
If you need assistance, you are welcome to address potential risks through a 🔗corporate legal consultation booking with Daeryun Law Firm.











