메뉴
HN
Hacker News • 7일 전

한국, 데이터 유출 과징금 상한 매출 10%로 인상

IMP
8/10
핵심 요약

개정 개인정보보호법 시행으로 고의 또는 중대한 과실로 1,000만 명 이상의 개인정보를 유출한 기업은 총매출의 최대 10%까지 과징금을 부과받게 됩니다. 잠재적 유출 가능성이 높은 경우에도 72시간 내 통지 의무가 신설되었으며, 사전 데이터 보호 투자와 신속한 대응에 따라 최대 40%까지 감경받을 수 있습니다.

번역된 본문

한국, 데이터 유출 과징금을 매출의 10%로 인상

중대한 과실로 대규모 데이터 유출을 일으킨 기업은 개정된 개인정보 보호 규정에 따라 연간 매출의 최대 10%까지 과징금을 부과받을 수 있게 되었다.

한국의 개인정보 보호 규제기관은 데이터 유출에 대한 처벌 수위를 대폭 강화하여, 기업들이 데이터 보호를 일상적인 사업 비용이 아닌 예방적 투자로 treats하도록 유도하고 있다. 금요일부터 고의 또는 중대한 과실로 1,000만 명 이상의 개인정보를 유출한 것으로 판명된 기업에는 총매출의 최대 10%까지 과징금이 부과될 수 있다. 이는 같은 날 시행되는 개정 개인정보보호법에 따른 포괄적 제도 개혁의 일환이다. 유출이 확정되지 않았더라도 노출 위험이 높은 경우 기업은 72시간 내에 이용자에게 통지해야 한다.

개인정보보호위원회 양정삼 사무처장은 목요일 기자들에게 "최근 개인정보 유출이 유통·통신 등 일상생활과 밀접한 분야에서 반복적으로 발생하고 그 규모도 커지고 있다"며 "중대한 위반에 대해 엄중한 책임을 묻는 한편, 유출 자체를 예방할 수 있도록 제도를 개선했다"고 밝혔다.

시행령에 따르면 과징금 상한은 3년 내에 고의 또는 중대한 과실 위반을 반복한 기업, 또는 시정 명령을 이행하지 않아 그 결과 유출이 발생한 기업에 적용된다. 과징금은 위반의 성격과 심각성, 관련 정황, 피해 규모를 바탕으로 산정된다. 개정 전에는 매출의 최대 3%까지 과징금이 부과됐다.

기존 규정과 새 규정의 차이는 실제 사례에 적용해보면 명확해진다. 국내 이커머스 대기업 쿠팡은 3,755만 명의 개인정보를 유출해 6월에 6,246억 원의 과징금을 부과받았다. 이 사례에 새 기준을 적용하면 과징금이 조 단위 원화까지 치솟을 수 있다. 다만 실제 부과 금액은 고의성·과실 정도, 피해 규모, 감경 사유 등에 따라 결정된다.

사전에 데이터 보호에 투자한 기업은 새 규정 하에서 감경 혜택을 받는다. 규제기관은 기업의 데이터 보호 예산·인력·장비 투자의 규모와 지속성, 개인정보보호책임자를 포함한 전반적인 보호 체계를 고려해 과징금을 최대 40%까지 줄일 수 있다. 유출을 조기에 탐지하고 신속히 신고·통지하며 피해 확산을 막은 기업 역시 최대 40%의 감경을 받을 수 있다.

이번 개정에는 '잠재적 개인정보 유출 통지 제도'도 도입됐다. 기업이 개인정보가 노출되었을 가능성이 높다고 판단하는 경우—예컨대 데이터 처리 시스템에 불법 접근이 있었거나, 일부 개인정보가 불법 거래된 사실을 발견해 다른 개인정보도 유출되었을 가능성이 있는 경우—해당 사실을 안 시점부터 72시간 내에 영향을 받는 개인에게 통지해야 한다. 랜섬웨어 등 유사 공격으로 위조·변조·훼손된 데이터에도 동일한 신고·통지 의무가 적용된다.

주요 기업·기관의 개인정보보호책임자의 권한과 책임도 확대된다. 연간 매출 1,800억 원을 초과하면서 100만 명 이상의 개인정보 또는 5만 명 이상의 민감정보·고유식별정보를 처리하는 기업은 개인정보보호책임자를 임명·변경·해임하기 전에 이사회 승인을 받아 개인정보보호위원회에 보고해야 한다. 2만 명 이상의 학생이 있는 대학, 상급종합병원 등도 동일한 요건이 적용된다.

원문 보기
원문 보기 (영어)
Korea raises data breach fines to 10% of revenue Companies behind major negligent data leaks can now face fines of up to 10 percent of annual revenue under revised privacy rules. News Team News Team Published September 10, 2026 - 4:16 p.m. Modified September 10, 2026 - 7:00 p.m. Korea's privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business. Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence can be fined up to 10 percent of their total revenue as part of a broader overhaul under the revised Personal Information Protection Act that is set to take effect the same day. Even if a leak hasn't been confirmed, companies must notify users within 72 hours if the risk of exposure is high. “Personal data breaches have recently occurred repeatedly and grown in scale in fields closely tied to daily life, such as retail and telecommunications,” Personal Information Protection Commission (PIPC) Secretary General Yang Cheong-sam told reporters Thursday. “We've improved the system to hold serious violations strictly accountable while also helping prevent breaches from happening in the first place.” Related Article Korea to introduce strengthened penalties for large-scale data leaks Gender Ministry considers criminal charges against Google over leaked victim data As U.S. and Europe hit gas on Chinese smart car restrictions, Korea sits at red light Under the enforcement decree, the cap applies to companies that repeatedly commit intentional or grossly negligent violations within three years, or that fail to comply with a corrective order and go on to suffer a breach as a result. Fines are calculated based on the nature and severity of the violation, the circumstances involved and the scale of the damage. Before the revision, companies were subject to a penalty of up to 3 percent of sales. The gap between the old and new rules becomes clear when applied to a real case. Local e-commerce giant Coupang was fined 624.6 billion won ($466.3 million) in June after leaking the personal data of 37.55 million people. Applying the new standard to that case could push the fine into the trillions of won. However, actual penalties will still depend on intent, negligence, the scale of damage and any mitigating factors. Companies that invested in data protection beforehand will get credit under the new rules. Regulators will consider the scale and continuity of a company's investment in data protection budgets, staffing and equipment, along with its broader protection system, including its chief privacy officer, to reduce a fine by up to 40 percent. A company that detects a breach early, reports and notifies users promptly, and prevents the damage from spreading can also receive up to a 40 percent reduction. The revision also introduces a “potential data breach notification system.” If a company determines there is a high likelihood that personal data was exposed — for instance, after illegal access to its data processing systems, or after discovering that some personal data was illegally traded in a way that suggests others' data may have leaked too — it must notify affected individuals within 72 hours of learning that. Data forged, altered or damaged by ransomware and similar attacks is now also subject to the same reporting and notification requirements. The authority and responsibility of chief privacy officers at major companies and institutions will also expand. Companies with annual revenue exceeding 180 billion won that process the personal data of 1 million or more people, or the sensitive or unique identifying information of 50,000 or more people, must get board approval before appointing, changing or dismissing a chief privacy officer and report the decision to the PIPC. Universities with 20,000 or more students, tertiary general hospitals and operators of major public systems fall under the same requirement. “We expect the way companies view investment in data protection to shift from seeing it as a cost to treating it as a proactive investment that builds customer trust and expands corporate profit,” PIPC's Chairperson Song Kyung-hee said. BY HAN EUN-HWA [lee.jian@joongang.co.kr] This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom. personal information protection commission personal information industry data leak business