Page title background (PC version)Page title background (mobile version)

Case Analysis / Legal Updates

Daeryun Law LLC, with expertise across practice areas,
provides analysis of court rulings and legal issues.

Violation of the Personal Information Protection Act | Card Company W, Which Used Merchants' Personal Information Without Authorization, Faces a Penalty Surcharge of 13.4 Billion Won

Card Company W was ordered to pay a penalty surcharge of 13.4 billion won for a violation of the Personal Information Protection Act.


The Personal Information Protection Commission imposed a penalty surcharge on Company W, which had used merchants' personal information for card-issuance marketing without authorization.

CONTENTS
  • 1. Violation of the Personal Information Protection Act, Company W's Use of Merchants' Personal Information
    • - Company W's Violations of the Personal Information Protection Act
  • 2. Violation of the Personal Information Protection Act, a Penalty Surcharge of 13.4 Billion Won
  • 3. Violation of the Personal Information Protection Act, Daeryun's Strategy

1. Violation of the Personal Information Protection Act, Company W's Use of Merchants' Personal Information

Card Company W was subject to a penalty surcharge for a violation of the Personal Information Protection Act.


In April 2024, the Personal Information Protection Commission opened an investigation after a media report that Card Company W was using the personal information of merchant representatives (hereinafter "merchants") to solicit new card subscriptions.

The investigation found that Company W had used merchants' personal information, without their consent, for marketing aimed at issuing new credit cards, and that an employee of Company W's Incheon Sales Center had passed this information to card solicitors.

To increase its sales performance, Company W's Incheon Sales Center entered merchants' business registration numbers into the merchant management program from July 2022 to April 2024 and thereby looked up the personal information (name, resident registration number, mobile phone number, address, and the like) of at least 131,862 merchants.

In addition, after entering merchants' resident registration numbers into the card-issuance review program, it checked whether each merchant held a Company W credit card and recorded that information on printouts or photographed it and shared it in a KakaoTalk group chat in which card solicitors and others participated.

In particular, beginning in September 2023, it used a data-query command in the database (DB) holding the personal information of merchants and cardholders to look up merchants' personal information and whether they held cards, generated the results as files, and, on 100 occasions from January 8 to April 2, 2024, transmitted the personal information of 75,676 individuals to card solicitors by email.

In this way, the personal information of at least 207,538 merchants was looked up and transmitted to card solicitors, and that information was used for Company W card-issuance marketing.

However, 74,692 of these merchants had given no consent of any kind to such use for marketing.

Company W's Violations of the Personal Information Protection Act

The Personal Information Protection Act provides that personal information must not be used beyond the scope of the purpose for which it was collected and used.


Nevertheless, Company W used personal information collected for purposes such as merchant management for the purpose of credit-card-issuance marketing, which violated Article 18(1) of the Personal Information Protection Act (restriction on use or provision beyond the original purpose).

In addition, the processing of resident registration numbers without a legal basis in this course was also found to violate Article 24-2(1) of the Personal Information Protection Act (restriction on the processing of resident registration numbers).

Moreover, Company W effectively delegated to its sales centers (individual departments) the operation of DB access privileges, file-download privileges, and privileges to view personal information including resident registration numbers, while failing to properly carry out even basic internal controls such as ascertaining the status of granted access privileges and reviewing access logs.

In fact, it granted DB access privileges unrelated to the work of sales center employees so that they could look up merchant information, and even though more than 30 million instances of personal information were looked up and downloaded per month at the sales centers, it did not properly review or address this.

In the end, it effectively left merchants' and credit card members' personal information open to indiscriminate lookup and use.

2. Violation of the Personal Information Protection Act, a Penalty Surcharge of 13.4 Billion Won

Company W, which received a penalty surcharge of 13.4 billion won for a violation of the Personal Information Protection Act

For Company W's 🔗violation of the Personal Information Protection Act, the Personal Information Protection Commission imposed a total penalty surcharge of 13,451,000,000 won and issued corrective orders, including measures to strengthen internal controls to prevent the misuse and abuse of personal information, to comply with safety obligations such as minimizing and reviewing access privileges, and to strengthen the management and supervision of personal-information handlers.

In response, Company W stated that it would organize employees' access privileges to internal terminal systems and establish a management system requiring approval from the information protection department before any external email transmission.

It also appears that, to prevent the recurrence of similar cases, the company will strengthen internal controls, including employee training and ongoing review of its information protection systems.

The Commission emphasized that "even where consent is obtained at the time personal information is initially collected, processing personal information beyond the scope of that consent is unlawful," and that it is necessary to periodically check whether handlers' privileges are properly granted and managed and whether any unlawful lookups have occurred.

3. Violation of the Personal Information Protection Act, Daeryun's Strategy

This was the first time the Commission had imposed a penalty surcharge on a card company.

The Commission added that it would review the response plan submitted within 90 days of the formal notice of the corrective order to the card company and would consider whether the matter would lead to the imposition of an administrative fine and a criminal accusation.

As this shows, a violation of the Personal Information Protection Act may result in a penalty surcharge ranging from hundreds of millions to tens of billions of won, and if the violation is intentional or repeated, it may lead to criminal punishment.


In addition, because a party may face not only an administrative disposition but also a civil claim for damages, a criminal accusation, and an order to make the matter public, it is most important to respond from the early stages of a case with the help of an experienced attorney.

This disposition against Company W was a case showing that processing personal information beyond the purpose for which it was collected and used is a clear violation of the law.

It is also a case showing that an organization should maintain a sound internal control system, periodically reviewing the access privileges of personal-information handlers such as employees and checking access logs to confirm that no unnecessary lookups or uses of personal information have occurred.

At Daeryun Law Firm LLP, attorneys experienced in numerous related cases form teams to develop response strategies for personal-information breach incidents.

The firm also provides assistance in designing personal-information protection organizations and procedures, designing internal audit processes and review items, and establishing support systems for the chief privacy officer, in order to build a corporate personal-information compliance framework.

Background

Daeryun's Key Strengths

Daeryun's exclusive AI · IT
litigation strategies
Over 240
key members
1,200+ cases
handled monthly

* January 2026 Bar Association Transit Permit Issuance Criteria

*Complies with Korean Bar Association Advertising Regulations Article 4 Paragraph 1

Attorney
Legal consultation booking

All consultations are conducted by specialized lawyers after reviewing the case. It is carried out on a reservation basis to ensure a professional process.We encourage you to make an early reservation for consultation, and request adherence to the scheduled time. We will do our best to provide a satisfying consultation.

Phone
consultation 1800-7905

Available 24/7, 365 days
for consultation requests

Phone booking

KakaoTalk
consultation

KakaoTalk channel

Daeryun Law Firm Attorneys

KakaoTalk booking

Online
consultation

We provide tailored
legal services.

Online booking
Related Information
Quick Menu

KakaoTalk