FINANCE

Fines for data breaches set to triple, with CEO liability on the line — banks brace for trillion-won penalties

by
Yu Hye-rim
Published : June 25, 2026 - 09:19:18
    • Copy Completed!

View Korean Original

Regulator sends banks notice on amended enforcement decree

Fine ceiling rises from 3% to 10% of revenue — up to threefold increase

CEO liability for data oversight now explicitly codified

New businesses such as stablecoins and AI agents face compliance pressure

Banks race to build AI-based security systems and hire specialists

[Created using ChatGPT]
[Created using ChatGPT]

The chief information security officer at a major South Korean bank has lately found himself juggling two demanding tasks at once: reviewing new digital-asset business proposals and preparing for a significantly tougher data-protection law taking effect in September. As the bank pushes ahead with stablecoin and AI agent initiatives as part of its broader digital transformation, the CISO must simultaneously map out a compliance strategy for the amended Personal Information Protection Act. "The security perimeter we have to manage has exploded with all these new digital businesses, and hacking techniques are growing more sophisticated by the day," he said. "The pressure is considerable — not just from bigger fines, but from the prospect of executive liability as well."

Anxiety is mounting across South Korea's financial sector as the amended Personal Information Protection Act, which allows fines of up to 10 percent of revenue for serious data breaches, is set to take effect in September. The fine ceiling is expanding by as much as threefold, and data protection is being elevated into a board-level responsibility. The burden is compounding as banks push deeper into digital assets, AI and other new businesses that generate and process ever-larger volumes of personal data.

The Personal Information Protection Commission recently sent a formal notice to banks and other institutions outlining the key provisions of the amended enforcement decree, according to financial industry sources. The decree covers the formalization of chief privacy officer appointment procedures requiring board approval and registration, the establishment of criteria for institutions subject to mandatory data-protection certification, and the overhaul of the data-breach notification and reporting system.

The amended act, which takes effect Sept. 11, allows regulators to impose fines of up to 10 percent of relevant revenue on companies that have suffered repeated data breaches caused by willful misconduct or gross negligence within the past three years, or that have caused harm to 10 million or more data subjects through such conduct. The previous fine ceiling stood at 3 percent of relevant revenue, so the new rules represent up to a threefold increase in penalty severity. "Once you're talking about 10 percent of revenue, the arithmetic means fines in the trillions of won are theoretically possible," one bank official said.

The changes are also emerging as a management risk that reaches all the way to the boardroom. The amended rules explicitly extend data-management and oversight responsibilities — previously confined to the chief privacy officer — to the CEO as well. CPOs will also be required to manage specialist personnel and secure budgets for data protection, and to report data-protection matters directly to the CEO and the board.

The rapid spread of new digital businesses lies behind the financial sector's particularly acute sensitivity to the amended rules. Banks have been rolling out a string of data-intensive new ventures, including won-denominated stablecoins, security token offerings, digital-asset custody services and generative AI-based financial products. The problem is that every new business line expands the personal data and security perimeter that must be managed.

"On top of the hacking and data-protection work we were already doing, we've suddenly got entirely new chapters to deal with — digital assets, AI agents, cloud, quantum computing," one financial industry official said. "It's hard to predict where the next incident will come from." The official added that the prospect of CEO and board liability in the event of a data incident is making banks hesitant to accelerate their push into new businesses.

Industry officials also said the nature of security threats has shifted since the emergence of generative AI, raising the difficulty of an effective response. "Where it used to take three months from finding a vulnerability to launching an attack, now it takes 10 minutes," one bank CPO said. Generative AI has sharply boosted attackers' productivity, making it increasingly difficult to defend against threats using existing security frameworks alone. Officials also flagged a growing risk of attacks occurring before security patches can be applied.

"For new businesses where collaboration with overseas operators is essential — such as won stablecoins, global payments, AI and cloud — banks will need to conduct a comprehensive review of their contract structures and personal data-handling procedures," one industry official said. Lee Jun-sang, an attorney at law firm Choisun, said the Credit Information Act has been continuously tightened in step with amendments to the Personal Information Protection Act, and added that if the gap in penalty levels between the two laws widens too far, a push to amend the Credit Information Act could follow.

Against this backdrop, financial institutions are stepping up investment in data protection and working to meet the conditions for fine reductions. The amended rules allow fines to be cut by up to 40 percent for companies that have consistently invested in data-protection budgets, personnel and infrastructure. Financial Supervisory Service Governor Lee Chan-jin said at a press briefing June 22 that the regulator would differentiate sanctions based on the level of information-security controls financial firms have in place, promising reduced penalties for institutions that take thorough preventive measures and act swiftly to contain damage after an incident, and heavier punishment for those that comply only superficially or suffer repeat incidents.

Major banks are responding by building AI-based security systems and competing to hire specialists. Shinhan Bank has formed a joint task force between its information security division and its technology group to develop asset management, zero-trust and autonomous security assessment frameworks. This month the bank also launched a recruitment drive for experienced information-security professionals, including members of a "Purple Team" responsible for validating security detection systems through simulated hacking exercises, as well as cloud security and security infrastructure architects.

KB Kookmin Bank established a new group cybersecurity center this year and built an AI-based vulnerability assessment system. Hana Bank has hired new AI and cloud security specialists and is pursuing a transition to an AI-based intelligent security framework, with plans to prioritize patching existing equipment and replacing aging hardware. Woori Bank is also consistently expanding its information-security headcount and upgrading its AI-based incident-response capabilities.

Information-security budgets are on the rise as well. KB Kookmin Bank's information-security budget grew from about 42.5 billion won ($27.6 million) in 2024 to 43.3 billion won last year, while Woori Bank has continued to invest in the 40 billion won range. "We are strengthening our ability to detect and respond to vulnerabilities in externally exposed assets in order to respond quickly to new security threat trends," a bank official said.


forest@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ