Page title background (PC version)Page title background (mobile version)

Case Analysis / Legal Updates

Daeryun Law LLC, with expertise across practice areas,
provides analysis of court rulings and legal issues.

Personal Information Compliance | Personal Information Protection Commission Imposes a Penalty Surcharge of 624.6 Billion Won on Coupang, Expanding the Scope of Corporate Personal Information Management

From a personal information compliance perspective, the case in which a penalty surcharge of 624.6 billion won was imposed on Coupang is regarded as an instance in which the scope of investigation expanded beyond a personal information leak to online activity records and internal control systems.

CONTENTS
  • 1. Personal Information Compliance | Key Details of Coupang's 624.6 Billion Won Penalty Surcharge Case
    • - The Background to the Imposition of the Largest Penalty Surcharge on Record
  • 2. Personal Information Compliance | Key Types of Violations Identified in the Case
    • - Violation of Safety Measure Obligations and the Personal Information Leak
    • - Collection of Online Activity Records and the Issue of Personal Information Utilization
    • - Issues with the Operation of the Personal Information Protection Officer and Internal Control
    • - Issues with Advertising Partner Management and Sensitive Information Processing
  • 3. Personal Information Compliance | Lessons the Personal Information Leak Case Left for Companies
    • - Lessons Left for Companies
  • 4. Personal Information Compliance | Corporate Risk and the Need for Legal Review
    • - Risks Companies Should Review
    • - The Assistance of a Corporate Attorney

1. Personal Information Compliance | Key Details of Coupang's 624.6 Billion Won Penalty Surcharge Case

Personal information compliance Coupang personal information leak penalty surcharge corrective order corporate attorney response

From a personal information compliance perspective, this Coupang case is an instance in which a personal information leak incident and issues with the processing of online activity records were simultaneously found to be subject to sanctions.

In June 2026, the Personal Information Protection Commission imposed a penalty surcharge totaling 624.681 billion won on Coupang.

This amount combines the penalty surcharge for the personal information leak and the penalty surcharge for the unauthorized collection of online activity records, and a notable feature is that the management system for personal information processing as a whole was reviewed together.

This case included within its scope of investigation not only whether information was leaked as a result of hacking, but also the personal information collection and use process, the manner of advertising operations, the operating system for the personal information protection officer, and the status of sensitive information processing.

Accordingly, the Personal Information Protection Commission issued a corrective order and improvement recommendations along with the penalty surcharge.

The Background to the Imposition of the Largest Penalty Surcharge on Record

It is worth first examining the fact that this sanction recognized multiple violations together, rather than a single act of violation.

Category

Key Details

Penalty Surcharge

Personal Information Leak

Leak of personal information of approximately 37.5 million people

Approximately 423.6 billion won

Collection of Online Activity Records

Collection of online activity records of approximately 11.17 million people

Approximately 201.1 billion won

Total

Multiple violations recognized

Approximately 624.6 billion won

The Personal Information Protection Commission found that a large-scale personal information leak occurred due to violations of safety measure obligations, such as authentication signing key management and access control.

Separately, it also found that the act of collecting and storing users' online activity records likewise constituted a violation of the Personal Information Protection Act.

What draws attention more than the size of the penalty surcharge itself is that the personal information leak and the data utilization issue were each assessed as independent violations.

This also means that, even had no personal information leak incident occurred, the manner of processing online activity records alone could give rise to a separate sanction.

2. Personal Information Compliance | Key Types of Violations Identified in the Case

A personal information compliance system operates across the entire process, from the collection of personal information to its use, storage, and destruction.

In this case, the security management system, the manner of data utilization, the internal control system, and the management of external partners were all included as subjects of investigation.

Examining which aspects the Personal Information Protection Commission took issue with also reveals the areas that companies should review.

Violation of Safety Measure Obligations and the Personal Information Leak

Article 29 of the Personal Information Protection Act (Obligation to Take Safety Measures)

A personal information controller shall take such technical, managerial, and physical measures as are necessary to secure safety, including the establishment of an internal management plan and the retention of access logs, as prescribed by Presidential Decree, so that personal information is not lost, stolen, leaked, forged, altered, or damaged.

The Personal Information Protection Commission found that there were problems with Coupang's authentication signing key management and access control systems.

As a result, it found that the personal information of approximately 37.5 million people was leaked and imposed a penalty surcharge of approximately 423.6 billion won.

Article 29 of the Personal Information Protection Act requires a personal information controller to put in place technical, managerial, and physical protective measures to prevent the leak of personal information.

In this case, whether the obligation to take safety measures under that provision had been fulfilled became one of the principal criteria for the determination.

Collection of Online Activity Records and the Issue of Personal Information Utilization

The Personal Information Protection Commission found that Coupang collected its members' online activity records and stored them in a database in a personally identifiable state.

The subjects of investigation included URL information, access date and time, access IP, and app usage information.

Collected Information

Details

URL Information

Records of visits to third-party websites

Access Date and Time

Information on the time of use

Access IP

Information related to the access environment

App Usage Information

Information on the use of third-party apps

Article 15 of the Personal Information Protection Act sets out the legal basis for the collection and use of personal information, and a personal information controller must clearly define the purpose of processing and the scope of collection.

In this case, the Personal Information Protection Commission reviewed whether the process of collecting and storing online activity records conformed to the standards of the relevant statutes, and it imposed a penalty surcharge of approximately 201.1 billion won for that violation.

Issues with the Operation of the Personal Information Protection Officer and Internal Control

Within a personal information compliance system, the personal information protection officer (CPO) performs the role of overseeing personal information protection duties.

Article 31 of the Personal Information Protection Act requires a personal information controller to designate a personal information protection officer and to have that officer carry out duties such as reviewing the status of personal information processing and establishing and operating an internal management plan.

In this investigation, the Personal Information Protection Commission found that the independence of Coupang's personal information protection officer was not sufficiently guaranteed. It also reviewed whether a system was appropriately operated under which the personal information protection officer could substantively perform the function of managing and supervising the personal information processing process.

Accordingly, in this case, the operating system of the personal information protection organization was included as a subject of investigation, in addition to the personal information leak and the issue of processing online activity records.

Issues with Advertising Partner Management and Sensitive Information Processing

The Personal Information Protection Commission stated that it confirmed that, in the course of operating Coupang's advertising partners, service usage records were collected regardless of the users' intentions.

The results of the investigation also included the process by which advertising partners collected users' website visit records and app usage records.

The Personal Information Protection Commission investigated whether Coupang had appropriately managed and supervised the processing of information collected through its advertising partners, and as a result it determined that improvement was needed in terms of securing transparency in personal information processing and guaranteeing users' right to choose, and accordingly issued a related corrective order.

In addition, the process by which Coupang Fulfillment Services (CFS) utilized workers' weight information was also included as a subject of investigation.

The Personal Information Protection Commission confirmed that CFS had utilized weight information, which it had collected and stored for the purpose of employee health management, in the course of litigation related to an industrial accident.

It accordingly regarded such information as sensitive information related to health status, and reviewed whether it had been utilized beyond the scope of the purpose of collection.

Article 23 of the Personal Information Protection Act requires that, where sensitive information such as health information is processed, there be a separate legal basis or that separate consent be obtained from the data subject.

The Personal Information Protection Commission found that the process of utilizing the weight information did not conform to these requirements for processing sensitive information, and it imposed a separate penalty surcharge in respect of this.

3. Personal Information Compliance | Lessons the Personal Information Leak Case Left for Companies

Personal information compliance is not limited to responding to personal information leak incidents.

In this Coupang case, various areas were investigated together, including the personal information leak, the collection of online activity records, the operation of the personal information protection officer, the management of advertising partners, and the processing of sensitive information.

The Personal Information Protection Commission decided on its sanctions after a comprehensive review of the obligation to take safety measures under Article 29 of the Personal Information Protection Act, the standards for the collection and use of personal information under Article 15, the restrictions on processing sensitive information under Article 23, and the provisions concerning the personal information protection officer under Article 31.

In particular, in that it examined not only the scale of the personal information leak but also the management system for the personal information processing process as a whole, there is no small amount for companies to take note of.

Lessons Left for Companies

In this case, the Personal Information Protection Commission found that a separate violation was established not only for the leak of personal information of approximately 37.5 million people but also for the process of handling online activity records.

It is also worth noting that, of the total penalty surcharge of 624.6 billion won, approximately 201.1 billion won was imposed in respect of violations related to the collection and utilization of online activity records.

In addition, the Personal Information Protection Commission did not merely confirm the fact of the personal information leak; it also investigated the operating system of the personal information protection officer, the management and supervision system for advertising partners, and the process of utilizing sensitive information.

This shows that not only the results of personal information processing but also the process of collecting and using personal information, as well as the operating status of the internal management system, may become subjects of investigation.

Review Area

Key Investigation Content

Obligation to Take Safety Measures

Access control, authentication signing key management

Collection and Use of Personal Information

Collection and utilization of online activity records

Sensitive Information Processing

Legality of utilizing weight information

Internal Control System

CPO independence and operating status

External Partner Management

Advertising partner management and supervision system

Following this case, the need has grown for companies to review, together, not only the security system for preventing personal information leaks but also the operating status of the personal information processing policy, the manner of utilizing online activity records, whether sensitive information is held, the operating system of the personal information protection officer, and the management status of entrusted parties and affiliated partners.

In particular, companies operating online services need to verify how the data utilized in the advertising and marketing process is collected and used, and whether the relevant information is appropriately disclosed to users.

4. Personal Information Compliance | Corporate Risk and the Need for Legal Review

A deficiency in personal information compliance can give rise to various legal and managerial risks for a company, regardless of whether a personal information leak incident has occurred.

As the scope of the Personal Information Protection Commission's investigation has expanded to personal information processing as a whole, companies must consider not only penalty surcharges but also the risks of damages, transactional disadvantages, and reputational decline.

In particular, platform companies, online service companies, and e-commerce companies that utilize customer data may need periodic legal review of the personal information processing process as a whole.

Risks Companies Should Review

Category

Key Risks

Administrative Risk

Penalty surcharge, administrative fine, corrective order

Civil Risk

Claim for damages, collective dispute mediation

Transactional Risk

Counterparty inspections, contractual disadvantages

Reputational Risk

Decline in customer trust, damage to brand image

Operational Risk

System improvement costs, costs of strengthening internal control

Personal information issues are not a matter for the information protection department alone.

Where violations are identified in the personal information processing process, multiple departments, including legal, marketing, IT, and human resources, may be affected simultaneously, and in some cases the company may need to address the imposition of a penalty surcharge, compliance with a corrective order, and a response to claims for damages.

Accordingly, companies need to put in place a system for periodically inspecting the personal information processing process as a whole and to verify whether the personal information processing policy matches the actual operating status.

It is also advisable to identify potential risk factors in advance through legal review of matters such as the manner of utilizing online activity records, the procedures for processing sensitive information, and the management status of entrusted businesses.

The Assistance of a Corporate Attorney

▶ Reviewing the personal information processing policy, terms of use, consent forms, and internal regulations to analyze any discrepancies between the actual status of personal information processing and statutory requirements

▶ Reviewing the legality of the processes for online activity records, customized advertising, affiliate marketing, and cookie and SDK operations, and diagnosing risks related to the processing of behavioral information

▶ Conducting compliance inspections of the operating system of the personal information protection officer (CPO), internal management plans, and employee training and audit systems

▶ Conducting compliance inspections of the operating system of the personal information protection officer (CPO), internal management plans, and employee training and audit systems

▶ Establishing response strategies and assisting in the preparation of written opinions for Personal Information Protection Commission investigations, requests for the submission of materials, on-site inspections, and opinion-hearing procedures

▶ Providing fact-analysis and dispute-response advice in the event of personal information leak incidents, sensitive information processing issues, claims for damages, and collective dispute mediation


Daeryun Law Firm LLP, the ninth-largest law firm in the Republic of Korea (*based on 2025 value-added tax filings with the National Tax Service), provides comprehensive legal advisory services, from diagnosing personal information processing systems to responding to Personal Information Protection Commission investigations, reorganizing internal regulations, and handling disputes, through the collaboration of legal experts in the fields of corporate law, compliance, personal information protection, information and communications, and data regulation.

If you need legal review of personal information compliance as a whole, including not only responding to personal information leak incidents but also the utilization of online activity records, the processing of sensitive information, and the operation of internal control systems, you are welcome to review your company's personal information management system through a consultation with a 🔗corporate attorney.

Related Practice Areas

More

Background

Daeryun's Key Strengths

Daeryun's exclusive AI · IT
litigation strategies
Over 240
key members
1,200+ cases
handled monthly

* January 2026 Bar Association Transit Permit Issuance Criteria

*Complies with Korean Bar Association Advertising Regulations Article 4 Paragraph 1

Attorney
Legal consultation booking

All consultations are conducted by specialized lawyers after reviewing the case. It is carried out on a reservation basis to ensure a professional process.We encourage you to make an early reservation for consultation, and request adherence to the scheduled time. We will do our best to provide a satisfying consultation.

Phone
consultation 1800-7905

Available 24/7, 365 days
for consultation requests

Phone booking

KakaoTalk
consultation

KakaoTalk channel

Daeryun Law Firm Attorneys

KakaoTalk booking

Online
consultation

We provide tailored
legal services.

Online booking
Related Information
Quick Menu

KakaoTalk