Skip to main content
World Today News
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology
Menu
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology

Why Personal Information Protection Commission Rejected Coupangs Fine Reduction Demands

September 26, 2026 Priya Shah – Business Editor Business

Coupang faces a record 6246억원의 fine after the Personal Information Protection Commission rejected the company’s demands to apply the net calculation method and classify the security breach as a minor violation. The regulatory body imposed the penalty on June 11, following a massive data leak involving approximately 3750만명 user accounts and unauthorized collection of online activity logs.

When compliance failures lead to penalties exceeding historical precedents—such as this fine, which stands at 4.6 times the previous record held by SK Telecom at 1347억9100만원—enterprises must immediately reassess their internal control environments.

Regulatory Rejection of the Net Method and Revenue Calculation Disputes

During the deliberation process documented in the commission’s full meeting transcripts released on September 27, Coupang raised formal objections to the revenue calculation criteria used to determine the penalty. The company argued that direct purchases should be evaluated using the net calculation method. Under this approach, product procurement costs alongside shipping and storage expenditures would be deducted from gross figures.

Coupang reasoned that direct purchase transactions record total sales value, whereas open market platforms record only brokerage commissions. This accounting structure creates a stark disparity in fine assessments despite similar overall transaction volumes and market shares. Coupang representatives noted that comparing 2024 revenues under these diverging frameworks creates a tenfold gap in apparent scale. Commissioner Yoon Young-mi rejected this argument, stating that accommodating the request would destroy consistency with established penalty standards and violate statutory provisions under the Personal Information Protection Act. The commission instead utilized publicly disclosed corporate revenues while excluding non-infringing divisions like Coupang Eats, Coupang Play, and business-to-business operations.

Security Vulnerabilities and the Reclassification of Violation Severity

The regulatory scrutiny intensified over the underlying nature of the security failure. Coupang contended that the incident warranted classification as a ‘weak violation’ because it originated from a former employee’s criminal acts without commercial intent. The firm emphasized its multi-layered security architecture, including ISMS-P certification, alongside customer compensation and remediation efforts.

Why Personal Information Protection Commission Rejected Coupangs Fine Reduction Demands

Investigators dismantled this defense by establishing that the breach stemmed from fundamental safety management failures rather than sophisticated hacking. Unauthorized access exposed delivery management pages roughly 1억4800만회 times across 16 distinct IP addresses. The firm operated authentication signature keys in plain text and maintained lax access controls that left accounts vulnerable. Systems failed to detect the activity for over six months until customer complaints triggered an internal review.

Penalty Adjustments and Corporate Legal Strategy

The Personal Information Protection Act mandates a multi-stage adjustment process for administrative penalties. Initial calculations adjusted base amounts upward by 25 percent because the violation period exceeded one year but remained under two years. An additional 30 percent was added due to two or more similar regulatory violations occurring within the preceding three years. Conversely, investigators applied a 30 percent reduction reflecting the lack of direct commercial profit derived from the infractions.

Why Personal Information Protection Commission Rejected Coupangs Fine Reduction Demands

Secondary adjustments factored in investigative obstruction, adding 10 percent for log deletions, which fell from the secretariat’s initial proposed 20 percent penalty. Committee deliberations raised mitigating factors from 40 percent to 50 percent to account for completed corrective actions, customer compensation, and broader privacy enhancements. Representatives for Coupang expressed regret that their proactive measures and factual explanations were omitted from the final determinations. The company confirmed plans to pursue administrative litigation to clarify the underlying facts through formal legal channels.

Market analysts monitoring the fallout observe that corporate capitalization frequently overshadows actual data sensitivity in determining administrative severity.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Related reading

  • AI Data Centers: Energy Challenges, Liquid Cooling, and Orbital Infrastructure
  • Rennata A. Nickram Admitted to the Guyana Bar

Related

개인정보보호법, 규모, 금액, 마찬가지, 시장점유율, 오픈마켓, 정보보호, 행정소송, 회계기준

Search:

World Today News

World Today News is your trusted source for global journalism — breaking headlines, in-depth analysis, and reporting from around the world.

Quick Links

  • Privacy Policy
  • About Us
  • Accessibility statement
  • California Privacy Notice (CCPA/CPRA)
  • Contact
  • Cookie Policy
  • Disclaimer
  • DMCA Policy
  • Do not sell my info
  • EDITORIAL TEAM
  • Terms & Conditions

Browse by Location

  • GB
  • NZ
  • US

Connect With Us

© 2026 World Today News. All rights reserved. Your trusted global news source directory.
For contact, advertising, copyright, issues email: office@world-today-news.com

Privacy Policy Terms of Service