[비즈한국] Recent recurring cybersecurity incidents have heightened corporate interest in personal data protection. In response, the Korea Internet & Security Agency (KISA) has been disclosing information on corporate security personnel and investment status through its Information Security Disclosure Portal.
However, the high threshold for mandatory information security disclosure has prompted calls for institutional reform. Consequently, the government has begun discussions on improving the information security disclosure system.

Information Security Portal Disclosure Criteria Set Too High
Following SKT's USIM data leak in April 2025 and a ransomware attack on Yes24053280 in June, the first half of the year saw a series of personal data breaches at companies including luxury brands Dior, Tiffany & Co., and Cartier; luxury goods platform MustIt; job search platform AlbaMon; and pizza brand Papa John's Korea.

This has sparked criticism over how companies manage customer personal data. Interest has also surged regarding the status of security measures, investment amounts, staffing, and executive information for protecting customer privacy at each company.
While such data can typically be searched on the KISA Information Security Disclosure Portal, it has been pointed out that the high baseline for mandatory disclosure leaves very few companies subject to public transparency.
Under the Information and Communications Technology Protection Act (hereinafter the Information Security Industry Act), KISA requires companies to disclose information related to security. Targeted information includes investments in security, personnel, security certifications, evaluations, and inspection activities, which companies must submit by June 30 of each year.
Under these regulations, SKT reported 65.2 billion KRW in security investments and 219.2 dedicated staff for 2025. Yes24 reported 1.6 billion KRW in investments and 10.1 dedicated staff for the same year.
However, companies that experienced data breaches—such as Dior Korea, Tiffany Korea, Cartier's local entity Richemont Korea, Papa John's Korea, AlbaMon, and MustIt—cannot be found on the portal. This is because they are not legally obligated to disclose security information.
Foreign Corporate Entities and SMEs Are Not Obligated
This is evident when examining the relevant laws and regulations. Under current law, the information security disclosure system leaves disclosure to the discretion of companies unless they fall under the categories designated as mandatory by the enforcement decree.
Article 13 of the Information Security Industry Act states that companies may disclose their security status. Furthermore, to protect users, the act mandates disclosure for companies defined in the enforcement decree, taking into account their business sector, revenue, and number of users.
Article 8, Paragraph 1 of the Enforcement Decree specifies these mandatory companies, including major telecommunications carriers, large data companies operating portals like Naver and Kakao035720, tertiary hospitals, and cloud computing service providers.
Additionally, KOSPI and KOSDAQ-listed companies with annual revenues of over 300 billion KRW are subject to mandatory disclosure, as are companies with more than 1 million service users.
In other words, if a company is not a major telco handling vast data, a giant listed firm with over 300 billion KRW in revenue, or a platform with over 1 million users, it has no obligation to disclose security information.
Indeed, the companies involved in the aforementioned personal data breaches were absent from the list of 671 companies that KISA identified as having disclosure obligations in 2025.
For instance, while Papa John's Korea generated 71.7 billion KRW in revenue in 2024, it is not a listed company and its revenue is below the 300 billion KRW threshold, exempting it from disclosure. Christian Dior Couture Korea, which operates Dior in Korea, generated 945.3 billion KRW in 2024, but because it is not a locally listed corporation, it is also not included in the disclosure list.
Significant Number of Data Leaks Occur at SMEs
Under the current system, it is difficult to verify security information for unlisted foreign companies, SMEs, and online platforms with fewer than 1 million users. This is precisely why there is a growing need for institutional reform, especially given that many personal data breaches are concentrated in private firms, particularly SMEs.

Statistical data supports this. According to the 2024 personal data breach report analysis released by the Personal Information Protection Commission in March 2025, more than half of the reported cases in 2024 involved SMEs.
The analysis found that of 307 reports, 66% came from private firms, and 60% of those cases occurred in SMEs. By sector, information technology, software, and e-commerce accounted for 34% of cases. Hacking, which requires investment and rigorous security management, was the cause of 67% of the leaks.
The government is now pushing for institutional reform. During his presidential campaign, President Lee Jae-myung included in his platform a promise to “strengthen the information security disclosure system to transparently reveal the scale of security investments and dedicated personnel” to counter cyber threats.
Furthermore, it is reported that following the inauguration of the new government, the Ministry of Science and ICT briefed the State Affairs Planning Committee on plans to improve the security system. Proposed reforms include expanding the mandate from currently listed companies with 300 billion KRW or more in revenue to all listed companies.
However, whether to mandate disclosure for unlisted SMEs, foreign companies, or smaller online platforms with fewer than 1 million users—where the majority of actual breaches are concentrated—remains to be seen, as the State Affairs Planning Committee is still in the drafting and fine-tuning stages of national tasks.