The financial authorities are revising the penalty assessment system for violations such as hacking, customer data breaches, and the improper provision and use of credit information. Currently, penalties are capped at 3% of total revenue, but the authorities believe that the existing three-tiered penalty rates of 50%, 75%, and 100% do not adequately reflect the severity of violations.
On September 16, the Financial Services Commission held a meeting of the 'Task Force for Improving Penalty Assessment Standards under the Credit Information Act' to discuss potential reforms.
Under the current Credit Information Act, penalties can reach up to 3% of total revenue for breaches involving the leakage or improper use of personal credit information, as well as the mishandling of pseudonymous data. Although the law was amended in 2020 to expand the scope and cap of penalties, the assessment has continued to rely on the 'Regulations on Inspection and Sanction of Financial Institutions' applicable across the financial sector.
Currently, the basic penalty is calculated using 50%, 75%, or 100% of the legal maximum based on the severity of the violation. Unlike laws such as the Banking Act or the Insurance Business Act, which base penalties on the amount of credit extended or insurance premiums directly related to the violation, the Credit Information Act uses total revenue as the basis. This approach makes it difficult to adequately reflect the degree of individual violations with only three penalty rates, according to the financial authorities.
In contrast, the Personal Information Protection Act and the European Union's General Data Protection Regulation (GDPR) have more detailed criteria. The Personal Information Protection Act applies penalty rates of 1% to 30% for minor violations, while the GDPR applies rates of 0% to 10% for lower-level infringements. The Financial Consumer Protection Act also established separate penalty standards last year, applying rates of 1% to 30% for minor violations.
In response, the financial authorities plan to develop a separate penalty assessment standard that reflects the characteristics of the Credit Information Act. This will involve evaluating the severity of violations based on the nature and type of personal credit information, the number of affected individuals, and the extent of damage, while also considering a more granular penalty rate than currently exists.
For serious violations, the authorities will impose strict penalties, but they are also discussing the possibility of reflecting factors that could mitigate or aggravate penalties, such as whether financial companies took proactive measures to prevent breaches of personal credit information or actively worked to recover consumer losses.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
