주메뉴바로가기본문바로가기
비즈한국 비즈한국

Information Security Legislation Surges Following Coupang and SKT Incidents: "Fast Reporting, Strong Punishment"

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] As the effectiveness of regulations faces scrutiny following a series of massive data breaches this year, legislative efforts to strengthen information security are accelerating. In the six months following the SK Telecom017670 USIM (Subscriber Identity Module) hacking incident—which was followed by repeated customer data leaks at companies such as Yes24053280, KT030200, and Lotte Card—25 amendments to the Information and Communications Network Act have been proposed, aimed at overhauling Information Security Management Systems (ISMS) and investigation procedures. Bills are also being pushed to mandate notifications to potential victims and require protective measures for all users. With voices calling for stronger systems rising due to recurring similar incidents and delayed reporting, attention is focused on whether these flooding legislative proposals can effectively plug the security "gaps."

The National Assembly is moving toward legislation to prevent information leakage incidents and minimize damage. Park Dae-joon, CEO of Coupang, is seen with a stern expression while attending a hearing on the Coupang security breach at the National Assembly's Science, ICT, Broadcasting and Communications Committee on the 2nd. Photo=Reporter Park Eun-sook
The National Assembly is moving toward legislation to prevent information leakage incidents and minimize damage. Park Dae-joon, CEO of Coupang, is seen with a stern expression while attending a hearing on the Coupang security breach at the National Assembly's Science, ICT, Broadcasting and Communications Committee on the 2nd. Photo=Reporter Park Eun-sook

Preventing Corporate Delays and Defining Obligations are Key

Since the SK Telecom USIM hacking incident in April, the National Assembly has been eager to develop countermeasures. According to the National Assembly’s bill information system on the 2nd, 25 "Partial Amendments to the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. (Information and Communications Network Act Amendment)" have been proposed over the past six months. The amendments focus primarily on detailing reporting and notification obligations to prevent companies from delaying or avoiding responses, and on systematizing information security budget investments and management system operations.

While current law mandates user protection duties, it lacks specific regulations regarding protective measures to be taken when security breaches, such as hacking, occur. Many argue that allowing exceptions to postpone notifications has created "loopholes" in response efforts. Individual amendments have proposed: △imposing duties for rapid damage relief and increasing fines for non-compliance (Rep. Choi Min-hee's proposal), △mandating information security level assessments and public disclosure of results for businesses above a certain size (Rep. Lee Hae-min's proposal), △granting authority for personnel management and budget allocation to the Chief Information Security Officer (CISO) (Rep. Jo In-chul's proposal), and △mandating information security management system certification for public institutions (Rep. Kim Gi-hyeon's proposal).

These bills stem from the delayed reporting and concealment behaviors of companies revealed in recent large-scale personal data breaches, as well as gaps in government response systems and security blind spots in public institutions. Many of the bills incorporate legislative discussions aimed at legally specifying the authority and sanction tools of competent agencies and imposing obligations on companies to prevent the spread of damage and provide relief.

SK Group Chairman Chey Tae-won makes a public apology regarding the SK Telecom hacking incident at the SK Telecom T-Tower SUPEX Hall in Jung-gu, Seoul, on the morning of May 7. Photo=Reporter Park Jung-hoon
SK Group Chairman Chey Tae-won makes a public apology regarding the SK Telecom hacking incident at the SK Telecom T-Tower SUPEX Hall in Jung-gu, Seoul, on the morning of May 7. Photo=Reporter Park Jung-hoon

According to data received from the Korea Internet & Security Agency (KISA) by Rep. Lee Hae-min of the Rebuilding Korea Party, a member of the National Assembly's Science, ICT, Broadcasting and Communications Committee, there have been 66 cases of delayed or non-reporting confirmed in the year since last August. Although an amendment to the Information and Communications Network Act last August mandated reporting within 24 hours of an incident, some companies did not report until over a year after becoming aware of the breach. Critics argue that the current level of sanctions—a maximum fine of only 30 million won—is encouraging companies to evade reporting.

It is pointed out that the large-scale data breaches repeated monthly this year have exposed flaws in both the government's preventive measures and post-incident response systems. From Coupang, which recently suffered a breach of 33.7 million customers' personal data, to SK Telecom, Yes24, Lotte Card, and KT—all are companies that have received "ISMS-P" (Information Security and Personal Information Protection Management System) certification, the highest level of security certification in Korea.

Notably, Lotte Card received this certification from the Financial Security Institute just two days before its server hacking incident occurred. It had been recognized as having the capacity to effectively respond to cyber intrusion threats. Security incidents occurring in the private sector outside the financial industry are handled by KISA under the Ministry of Science and ICT in accordance with the Information and Communications Network Act and the Information Security Industry Act. Critics point out that this security certification, introduced by the government to ensure the safety of information networks, is in practice merely a formal system that meets only minimum standards.

Strengthening Internal Security Systems... Pushing for Mandatory 'Protection Measures'

During the same period, there has been a flurry of legislation to amend the Personal Information Protection Act (18 bills) and the Telecommunications Business Act (5 bills). The broad framework remains similar: providing sufficient information to data subjects quickly in the event of a personal data breach and strengthening the government's authority.

Specifically, the Personal Information Protection Act amendments cover detailed regulations to guarantee the rights of data subjects, such as: △strengthening notification procedures regarding rights at the stage of processing and collecting personal information, and expanding the scope of mandatory personal information impact assessments to the private sector (Rep. Park Min-kyu's proposal); △mandating individual notifications to all potential victims whose information may have been leaked (Rep. Lee Hoon-ki's proposal); and △the so-called "Mandatory Individual Notification Act," which requires individual notification via phone, text, email, or mail, and mandatory public disclosure of recurrence prevention measures (Rep. Lee Hae-min's proposal).

On the 19th of last month, the National Assembly's Science, ICT, Broadcasting and Communications Committee passed a committee-level amendment to the Information and Communications Network Act, which strengthens the decision-making structure and accountability system for information security within companies. The bill mandates that information and communications service providers strive to secure specialized information security personnel and sufficient budgets, grant personnel management and budget allocation authority to the Chief Information Security Officer (CISO), and report the status of information security to the board of directors.

The government and the National Assembly are showing their will to strengthen regulations in response to recent hacking incidents. Photo=Pixabay
The government and the National Assembly are showing their will to strengthen regulations in response to recent hacking incidents. Photo=Pixabay

Authorities are demonstrating their resolve to build a regulatory system with stronger enforcement. As hacking incidents have expanded into the financial sector, the Financial Services Commission has signaled that it will push for an amendment to the Electronic Financial Transactions Act, which would significantly increase the level of sanctions, including the introduction of penalty surcharges and enforcement fines. According to the current Personal Information Protection Act, penalty surcharges can be imposed up to 3% of total revenue. In contrast, the current Financial Transactions Act amendment lacks adequate post-incident sanction measures.

The National Assembly Research Service has also pointed out the need to improve passive corporate responses and inadequate government handling of incidents. A related report noted, "It is necessary to consider establishing a system that can quickly announce hacking facts using disaster warning systems in consultation with the Minister of the Interior and Safety when it is judged that a breach could cause extensive or significant danger, by specifically defining the target, content, and method of warnings that should be taken in the event of an intrusion under the Information and Communications Network Act." Categorizing security breaches under the Information and Communications Network Act as "broadcasting and telecommunications disasters" under the Framework Act on Broadcasting and Communications Development is also being discussed.

Recent attention is also focused on the need for practical compensation for individual victims. The SK Telecom case is the first application for collective dispute mediation following the implementation of collective dispute mediation and class-action lawsuits, but on the 20th, the company rejected the mediation proposal by the Personal Information Protection Committee’s Dispute Mediation Committee, which would have required the company to compensate victims of personal data leakage 300,000 won per person.

Park So-young, a legislative researcher at the National Assembly Research Service, pointed out, "It is clearly necessary to prepare effective relief measures for small-scale, multi-victim cases caused by personal information infringement, and it requires in-depth review." She added, "However, introducing class-action lawsuits in Korea, which has a different legal system than the US and others, requires cautious examination and meticulous institutional design."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지