Korea raises data breach fines to 10% of revenue
throw7
298 points
90 comments
September 18, 2026
Related Discussions
Found 5 related stories in 173.3ms across 7,105 title embeddings via pgvector HNSW
- US seeks share of Korean chipmakers' 'excess profits' scrlk · 26 pts · July 17, 2026 · 51% similar
- France's tax authority had data stolen on 680k taxpayers rzk · 53 pts · August 14, 2026 · 49% similar
- Korean Stocks Plunge 16% in Two-Day Burst of Retail Selling emsidisii · 13 pts · July 29, 2026 · 47% similar
- LG accused of 'egregious invasion of privacy' over TV data collection beardyw · 12 pts · September 09, 2026 · 46% similar
- EU fines Google €890M for competition breaches over search and apps Stevvo · 165 pts · July 23, 2026 · 44% similar
Discussion Highlights (17 comments)
quickthrowman
I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
prologic
Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
jmclnx
Sounds great if all the following is true. * Before Tax Revenue * If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent. * Includes Worldwide Revenue * Includes companies based in all other Countries. I would have went for 20%, but if he above applies I wish the US would do the same.
augment_me
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function. Minimizes money usage and does not require any security investments
SoftTalker
"through intent or gross negligence" I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
rectang
It's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic.
ggarnhart
This feels like a really odd way to incentivize data breaches and/or not reporting data breaches.
nosmokewhereiam
Imagine 10% of Samsung! Edit: "That'll be $23B. Cash or card?"
__natty__
Huge fines but reasonable. Especially now with all the people doing blind vibe coding
roundup
Assuming global adoption, this would also have the side effect of increasing bug bounty payouts. Consider the recent OpenAI compromise: an attack RCE, an SSO configuration flaw, and subsequent employee account takeover, for a mere $6500 bounty for a trillion-dollar company.
xp84
I'm assuming the intent is to protect customers. Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all. I'm thinking: (The following example is in "American" terms, I assume some other countries have similar ideas as SSN though) - Name and address or name and phone number leak: $100 per customer affected. - Email: $50 per customer affected, or $100 if tied to any other data. - Social Security numbers: $2000 per customer affected - Unsalted or plaintext passwords: $500 per customer affected. - Cap is the greater of 200% of annual EBITDA, or 20% of revenue Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users. This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse. My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.
aucisson_masque
GDPR in Europe puts it at 4%, and yet we are seeing leaks every week. 10% maximum mean nothing if it’s not enforced, you got to make examples.
hn_submit
This is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets. Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
guillybarres
Will they uphold this law when DPRK threat actors use it as a form of economic sabotage?
_the_inflator
And what about the governments like Berlin for example? Massive data breach, and guess what happens? Nothing to those who are responsible for the breach. So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass. If the Berlin incident remotely had happened to any private company - hell would have been loose. Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked.
markhahn
This is wonderful, though a little low. Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously.
pstoll
About f’ing time a government made this have real consequences.