기사 메일전송
[Kim Dong-soo Column] Urgent Measures Needed to Strengthen Personal Information Protection
  • 김동수
  • December 12, 2025 at 3:52 PM
기사수정


Yonhap News TV 

Professor at Wonkwang Digital UniversityFollowing SK Telecom, Lotte Card, Interpark, and KT, Coupang has also experienced continuous personal information leaks due to hacking incidents in various places over the past seven months. The leaked personal information amounts to over 63 million cases. With more personal information than the entire population being leaked sequentially, there is a significant concern that individuals are left defenseless against secondary damages and financial fraud. Strengthening the Personal Information Protection Act is urgent.

 

The Personal Information Protection Act was enacted with the purpose of protecting individuals' freedom and rights and, furthermore, realizing individuals' dignity and value by stipulating matters concerning the processing and protection of personal information. With the development of technology and industry in the AI era, the types and scope of collection of personal information are rapidly expanding beyond general personal details to include biometric information, and concerns about the infringement of individuals' fundamental rights are also growing due to the increase in big data utilization.

 

Companies are so focused on expanding their business scale that their security insensitivity has reached an extreme. The government and the National Assembly must take full responsibility. In a parliamentary inquiry regarding the Coupang personal information leak incident, the government stated that according to log analysis, the attack period for over 30 million accounts was from June 24 to November 8.

 

Both companies and the government were unaware of the leak, which began five months prior, and only learned about it through customer reports. It is utterly absurd when considered deeply. While the government states it will strengthen monitoring due to concerns about secondary damages like smishing, it is only reacting belatedly and haphazardly after the crisis has already escalated.


Inadequacies in related laws and systems, as well as lenient penalties, have always been a point of contention, yet progress remains stagnant. Even SK Telecom, which had 23 million cases of personal information leaked, was only fined approximately 134.8 billion won. It is necessary to consider not only actualizing the fine, which can be up to 3% of sales for legal violations, but also institutionalizing measures for companies to provide substantial compensation to consumers.

 

Since the SK Telecom incident, 23 amendments to the Personal Information Protection Act, including provisions for prompt notification and investigation, and strengthened fines and penalties, have been proposed since March 12 of this year, but they have repeatedly stalled in the legislative review stage. The National Assembly and the government's mere calls for enhanced personal information security amount to dereliction of duty.

 

Damages from personal information leaks manifest in various forms such as smishing, financial fraud, and identity theft after a certain period. Since leaked personal information is transferred, processed, and resold through multiple channels, it is practically difficult for victims to directly prove the causal link between the leak and the damage.

 

The current law does not impose an obligation on personal information processors to inform data subjects of their rights to access, correct, delete, or suspend the processing of their personal information. When processing personal information collected from third parties, the source of collection and purpose are only disclosed upon a 'data subject's request.' Consequently, many victims are unable to exercise their rightful claims when damages occur.

 

Furthermore, the mandatory personal information impact assessment is not applied to large-scale private personal information processors, except for public institutions. This means that even for personal information processors handling large amounts of sensitive personal information, assessments of risks of personal information infringement are not properly conducted.


It is necessary to comprehensively re-examine and establish follow-up measures for revised laws that strengthen personal information protection, such as enhancing the procedures for notifying data subjects of their rights from the initial stages of personal information processing and collection, and expanding the scope of mandatory personal information impact assessments to include private businesses that handle large volumes of sensitive information, beyond just public institutions.

 

Professor at Wonkwang Digital University 


What do you think of this article?
recommend
0
great
0
moved
0

This article has 1comments.

  • Profile
    guest2025-12-12 19:53:23

    멍청도  꼴통 견찰은 공무원이 민원인 개인정보를 훔쳐서 무단유출 및 은닉해도 불송치함 ㅋ 

정기구독배너
Go to Mobile Site