CONTENTS
- 1. Personal Information Compliance | Key Details of Coupang's 624.6 Billion Won Penalty Surcharge Case

- - The Background to the Imposition of the Largest Penalty Surcharge on Record
- 2. Personal Information Compliance | Key Types of Violations Identified in the Case

- - Violation of Safety Measure Obligations and the Personal Information Leak
- - Collection of Online Activity Records and the Issue of Personal Information Utilization
- - Issues with the Operation of the Personal Information Protection Officer and Internal Control
- - Issues with Advertising Partner Management and Sensitive Information Processing
- 3. Personal Information Compliance | Lessons the Personal Information Leak Case Left for Companies

- - Lessons Left for Companies
- 4. Personal Information Compliance | Corporate Risk and the Need for Legal Review

- - Risks Companies Should Review
- - The Assistance of a Corporate Attorney
1. Personal Information Compliance | Key Details of Coupang's 624.6 Billion Won Penalty Surcharge Case

From a personal information compliance perspective, this Coupang case is an instance in which a personal information leak incident and issues with the processing of online activity records were simultaneously found to be subject to sanctions.
In June 2026, the Personal Information Protection Commission imposed a penalty surcharge totaling 624.681 billion won on Coupang.
This amount combines the penalty surcharge for the personal information leak and the penalty surcharge for the unauthorized collection of online activity records, and a notable feature is that the management system for personal information processing as a whole was reviewed together.
This case included within its scope of investigation not only whether information was leaked as a result of hacking, but also the personal information collection and use process, the manner of advertising operations, the operating system for the personal information protection officer, and the status of sensitive information processing.
Accordingly, the Personal Information Protection Commission issued a corrective order and improvement recommendations along with the penalty surcharge.
The Background to the Imposition of the Largest Penalty Surcharge on Record
It is worth first examining the fact that this sanction recognized multiple violations together, rather than a single act of violation.
Category | Key Details | Penalty Surcharge |
|---|---|---|
Personal Information Leak | Leak of personal information of approximately 37.5 million people | Approximately 423.6 billion won |
Collection of Online Activity Records | Collection of online activity records of approximately 11.17 million people | Approximately 201.1 billion won |
Total | Multiple violations recognized | Approximately 624.6 billion won |
The Personal Information Protection Commission found that a large-scale personal information leak occurred due to violations of safety measure obligations, such as authentication signing key management and access control.
Separately, it also found that the act of collecting and storing users' online activity records likewise constituted a violation of the Personal Information Protection Act.
What draws attention more than the size of the penalty surcharge itself is that the personal information leak and the data utilization issue were each assessed as independent violations.
This also means that, even had no personal information leak incident occurred, the manner of processing online activity records alone could give rise to a separate sanction.
2. Personal Information Compliance | Key Types of Violations Identified in the Case
A personal information compliance system operates across the entire process, from the collection of personal information to its use, storage, and destruction.
In this case, the security management system, the manner of data utilization, the internal control system, and the management of external partners were all included as subjects of investigation.
Examining which aspects the Personal Information Protection Commission took issue with also reveals the areas that companies should review.
Violation of Safety Measure Obligations and the Personal Information Leak
A personal information controller shall take such technical, managerial, and physical measures as are necessary to secure safety, including the establishment of an internal management plan and the retention of access logs, as prescribed by Presidential Decree, so that personal information is not lost, stolen, leaked, forged, altered, or damaged.
The Personal Information Protection Commission found that there were problems with Coupang's authentication signing key management and access control systems.
As a result, it found that the personal information of approximately 37.5 million people was leaked and imposed a penalty surcharge of approximately 423.6 billion won.
Article 29 of the Personal Information Protection Act requires a personal information controller to put in place technical, managerial, and physical protective measures to prevent the leak of personal information.
In this case, whether the obligation to take safety measures under that provision had been fulfilled became one of the principal criteria for the determination.
Collection of Online Activity Records and the Issue of Personal Information Utilization
The Personal Information Protection Commission found that Coupang collected its members' online activity records and stored them in a database in a personally identifiable state.
The subjects of investigation included URL information, access date and time, access IP, and app usage information.
Collected Information | Details |
|---|---|
URL Information | Records of visits to third-party websites |
Access Date and Time | Information on the time of use |
Access IP | Information related to the access environment |
App Usage Information | Information on the use of third-party apps |
Article 15 of the Personal Information Protection Act sets out the legal basis for the collection and use of personal information, and a personal information controller must clearly define the purpose of processing and the scope of collection.
In this case, the Personal Information Protection Commission reviewed whether the process of collecting and storing online activity records conformed to the standards of the relevant statutes, and it imposed a penalty surcharge of approximately 201.1 billion won for that violation.
Issues with the Operation of the Personal Information Protection Officer and Internal Control
Within a personal information compliance system, the personal information protection officer (CPO) performs the role of overseeing personal information protection duties.
Article 31 of the Personal Information Protection Act requires a personal information controller to designate a personal information protection officer and to have that officer carry out duties such as reviewing the status of personal information processing and establishing and operating an internal management plan.
In this investigation, the Personal Information Protection Commission found that the independence of Coupang's personal information protection officer was not sufficiently guaranteed. It also reviewed whether a system was appropriately operated under which the personal information protection officer could substantively perform the function of managing and supervising the personal information processing process.
Accordingly, in this case, the operating system of the personal information protection organization was included as a subject of investigation, in addition to the personal information leak and the issue of processing online activity records.
Issues with Advertising Partner Management and Sensitive Information Processing
The Personal Information Protection Commission stated that it confirmed that, in the course of operating Coupang's advertising partners, service usage records were collected regardless of the users' intentions.
The results of the investigation also included the process by which advertising partners collected users' website visit records and app usage records.
The Personal Information Protection Commission investigated whether Coupang had appropriately managed and supervised the processing of information collected through its advertising partners, and as a result it determined that improvement was needed in terms of securing transparency in personal information processing and guaranteeing users' right to choose, and accordingly issued a related corrective order.
In addition, the process by which Coupang Fulfillment Services (CFS) utilized workers' weight information was also included as a subject of investigation.
The Personal Information Protection Commission confirmed that CFS had utilized weight information, which it had collected and stored for the purpose of employee health management, in the course of litigation related to an industrial accident.
It accordingly regarded such information as sensitive information related to health status, and reviewed whether it had been utilized beyond the scope of the purpose of collection.
Article 23 of the Personal Information Protection Act requires that, where sensitive information such as health information is processed, there be a separate legal basis or that separate consent be obtained from the data subject.
The Personal Information Protection Commission found that the process of utilizing the weight information did not conform to these requirements for processing sensitive information, and it imposed a separate penalty surcharge in respect of this.
3. Personal Information Compliance | Lessons the Personal Information Leak Case Left for Companies
Personal information compliance is not limited to responding to personal information leak incidents.
In this Coupang case, various areas were investigated together, including the personal information leak, the collection of online activity records, the operation of the personal information protection officer, the management of advertising partners, and the processing of sensitive information.
The Personal Information Protection Commission decided on its sanctions after a comprehensive review of the obligation to take safety measures under Article 29 of the Personal Information Protection Act, the standards for the collection and use of personal information under Article 15, the restrictions on processing sensitive information under Article 23, and the provisions concerning the personal information protection officer under Article 31.
In particular, in that it examined not only the scale of the personal information leak but also the management system for the personal information processing process as a whole, there is no small amount for companies to take note of.
Lessons Left for Companies
In this case, the Personal Information Protection Commission found that a separate violation was established not only for the leak of personal information of approximately 37.5 million people but also for the process of handling online activity records.
It is also worth noting that, of the total penalty surcharge of 624.6 billion won, approximately 201.1 billion won was imposed in respect of violations related to the collection and utilization of online activity records.
In addition, the Personal Information Protection Commission did not merely confirm the fact of the personal information leak; it also investigated the operating system of the personal information protection officer, the management and supervision system for advertising partners, and the process of utilizing sensitive information.
This shows that not only the results of personal information processing but also the process of collecting and using personal information, as well as the operating status of the internal management system, may become subjects of investigation.
Review Area | Key Investigation Content |
|---|---|
Obligation to Take Safety Measures | Access control, authentication signing key management |
Collection and Use of Personal Information | Collection and utilization of online activity records |
Sensitive Information Processing | Legality of utilizing weight information |
Internal Control System | CPO independence and operating status |
External Partner Management | Advertising partner management and supervision system |
Following this case, the need has grown for companies to review, together, not only the security system for preventing personal information leaks but also the operating status of the personal information processing policy, the manner of utilizing online activity records, whether sensitive information is held, the operating system of the personal information protection officer, and the management status of entrusted parties and affiliated partners.
In particular, companies operating online services need to verify how the data utilized in the advertising and marketing process is collected and used, and whether the relevant information is appropriately disclosed to users.
4. Personal Information Compliance | Corporate Risk and the Need for Legal Review
A deficiency in personal information compliance can give rise to various legal and managerial risks for a company, regardless of whether a personal information leak incident has occurred.
As the scope of the Personal Information Protection Commission's investigation has expanded to personal information processing as a whole, companies must consider not only penalty surcharges but also the risks of damages, transactional disadvantages, and reputational decline.
In particular, platform companies, online service companies, and e-commerce companies that utilize customer data may need periodic legal review of the personal information processing process as a whole.
Risks Companies Should Review
Category | Key Risks |
|---|---|
Administrative Risk | Penalty surcharge, administrative fine, corrective order |
Civil Risk | Claim for damages, collective dispute mediation |
Transactional Risk | Counterparty inspections, contractual disadvantages |
Reputational Risk | Decline in customer trust, damage to brand image |
Operational Risk | System improvement costs, costs of strengthening internal control |
Personal information issues are not a matter for the information protection department alone.
Where violations are identified in the personal information processing process, multiple departments, including legal, marketing, IT, and human resources, may be affected simultaneously, and in some cases the company may need to address the imposition of a penalty surcharge, compliance with a corrective order, and a response to claims for damages.
Accordingly, companies need to put in place a system for periodically inspecting the personal information processing process as a whole and to verify whether the personal information processing policy matches the actual operating status.
It is also advisable to identify potential risk factors in advance through legal review of matters such as the manner of utilizing online activity records, the procedures for processing sensitive information, and the management status of entrusted businesses.
The Assistance of a Corporate Attorney
▶ Reviewing the legality of the processes for online activity records, customized advertising, affiliate marketing, and cookie and SDK operations, and diagnosing risks related to the processing of behavioral information
▶ Conducting compliance inspections of the operating system of the personal information protection officer (CPO), internal management plans, and employee training and audit systems
▶ Conducting compliance inspections of the operating system of the personal information protection officer (CPO), internal management plans, and employee training and audit systems
▶ Establishing response strategies and assisting in the preparation of written opinions for Personal Information Protection Commission investigations, requests for the submission of materials, on-site inspections, and opinion-hearing procedures
▶ Providing fact-analysis and dispute-response advice in the event of personal information leak incidents, sensitive information processing issues, claims for damages, and collective dispute mediation
Daeryun Law Firm LLP, the ninth-largest law firm in the Republic of Korea (*based on 2025 value-added tax filings with the National Tax Service), provides comprehensive legal advisory services, from diagnosing personal information processing systems to responding to Personal Information Protection Commission investigations, reorganizing internal regulations, and handling disputes, through the collaboration of legal experts in the fields of corporate law, compliance, personal information protection, information and communications, and data regulation.
If you need legal review of personal information compliance as a whole, including not only responding to personal information leak incidents but also the utilization of online activity records, the processing of sensitive information, and the operation of internal control systems, you are welcome to review your company's personal information management system through a consultation with a 🔗corporate attorney.






