![[Seoul=NEWSIS] Reporter Ko Beom-jun = At the National Assembly audit of the Ministry of Science and ICT and the Korea Communications Commission held at the Seoul Yeouido National Assembly on the 6th, platform company officials related to personal information leaks, including Tving CEO Choi Ju-hee, answered questions from lawmakers. From left: Tving CEO Choi Ju-hee, Woowahan Brothers CISO Kim Jung-hoon, Toss Payments CEO Im Han-wook, Gangnam Unni CEO Hong Seung-il, and Duo CEO Park Soo-kyung. October 6, 2026. bjko@newsis.com /Photo=Ko Beom-jun](https://thumb.mt.co.kr/cdn-cgi/image/f=avif/21/2026/10/2026100715223451307_1.jpg)
A controversy has arisen after the CEO of Duo, a marriage information company where sensitive personal information such as income, assets, and divorce status of approximately 420,000 members was leaked, responded to questions regarding a victim compensation plan at the National Assembly audit of the Ministry of Science and ICT and the Korea Communications Commission on the 6th by stating that "what members want is to find a good spouse." As criticism has been raised over Duo's complacent attitude and the "light" penalty, the issue of reverse discrimination compared to e-commerce giant Coupang, which received a record-breaking fine of 620 billion won following a high-intensity investigation into recent information leaks, has also come up. Opinions are emerging that to heighten corporate awareness of information security, investigations should be conducted rigorously using the same verification standards as for Coupang, and fine determination criteria should comprehensively consider factors such as the sensitivity of the leaked information, potential secondary damage exploitation, and actual victim cases, rather than revenue.
According to the Personal Information Protection Commission (PIPC) on the 7th, in January last year, a work PC used by an employee handling personal information at Duo was hacked, resulting in the leakage of personal data for 427,464 regular members. The leaked information included more than 10 types, such as IDs and passwords, names, dates of birth, encrypted resident registration numbers, addresses, height and weight, blood type, religion, hobbies, marriage history, sibling relationships, schools attended, majors, and workplace names. In particular, for some members, sensitive information that could lead to secondary damage, such as the name of a former spouse, reasons for divorce, annual income, assets, and health status, was leaked. It was also confirmed that Duo had not destroyed 298,566 pieces of personal information it had held for more than five years.
In response, the PIPC imposed a fine of 1.197 billion won and an administrative penalty fee of 13.2 million won on Duo. In July last year, Duo filed an administrative lawsuit against the sanction. Separately, Duo is also involved in a damages lawsuit filed by 46 victims of the personal information leak, who are claiming 1 million won each in consolation money.
The PIPC imposed a total fine of 624.681 billion won on Coupang in June last year. This sanction was based on investigation results indicating that customer information for approximately 37.5 million people had been leaked. In terms of the scale of the information leak, Coupang's case is more than 80 times larger than Duo's, but there is a difference in the "quality" of the leaked information. According to the PIPC investigation, the information leaked from Coupang included names, email addresses, home addresses, and phone numbers. The most sensitive information was approximately 2,600 apartment common entrance passwords.

Following the information leak incident at the end of last year, Coupang formulated its own compensation plan and provided points worth 50,000 won per customer. As a result, additional marketing costs exceeding 1 trillion won were incurred across the fourth quarter of last year and the first quarter of this year. Brett Mattis, Coupang's Chief Information Security Officer (CISO), stated at the National Assembly audit on the 6th, "I would like to express my deep apologies once again for causing concern to the public due to the information leak incident," adding, "We have improved our key management policies, including the introduction of a hardware-based key generation system, and strengthened our monitoring capabilities."
It is also known that in the financial sector, where recent information leak incidents have occurred, highly sensitive loan-related information was leaked. Considering this, there are indications that the PIPC should conduct thorough investigations and promote preventive measures against recurrence for future information leak cases while simultaneously improving sanction criteria. Seo Jong-hee, a professor at Yonsei University Law School Moon Dae-hak-won (Prof.), said, "Companies must definitely take responsibility for personal information leaks. However, it is necessary to examine whether the results sufficiently reflect the nature of the leaked information, whether actual damage occurred, and the company's post-incident response efforts." She added, "The method of calculating fines based on revenue, regardless of a business operator's profit and loss, leaves room for misunderstanding that this constitutes an excessive penalty only for specific companies."
Cho Dong-geun, a distinguished professor in the Department of Economics at Myongji University, said, "The revenue of companies with information leaks has no direct relationship with the damage suffered by consumers," adding, "The criteria for determining the amount of fines should be the severity of the infringement and actual damage." He further added, "If administrative sanctions prioritize the logic that 'large companies pay large fines,' there is a risk that fines will degenerate into a kind of 'size tax.'"