Sanctions against companies that leak personal data will be significantly strengthened. Companies that repeatedly leak personal data due to intent or gross negligence, or cause harm to 10 million or more people, will be required to pay fines of up to 10% of their total sales revenue. While the intention is to sound an alarm on corporate security awareness, concerns about negative side effects arise because the sanction levels are designed to shake the very survival of companies.
The 10% cap is difficult to avoid criticism as excessive compared to global standards. The European Union's GDPR (General Data Protection Regulation), known for its strict personal data protection, sets the fine cap at a maximum of 4% of worldwide sales revenue. Even China's Personal Information Protection Law (PIPL), enacted during efforts to rein in big tech, imposes fines of only up to 5% of sales revenue.
There is also hope that raising the amount of fines will encourage companies to proactively expand security investments. However, increasing the intensity of punishment does not necessarily improve effectiveness. Excessive regulation can act as a fatal risk for companies beyond merely raising awareness.
For retail or platform companies, profit margins are typically low while sales volumes are large. If a company with an operating profit margin of only 2-3% is required to pay fines amounting to 10% of its total sales revenue, the very existence of the company could be jeopardized. Although factors such as intent or gross negligence, the scale of damage, and post-incident remediation efforts are considered when determining fine amounts, the problem lies in the possibility that ad hoc standards based on public opinion and the beliefs of responsible officials may be applied inconsistently.
As hacking techniques become increasingly sophisticated, it is a reality that even large corporations struggle to block all attempts at personal data leaks. Companies lacking the resources to build security infrastructure commensurate with regulations may increasingly abandon data-driven businesses altogether. There is also a possibility that companies will conceal leak incidents internally rather than voluntarily reporting security breaches and resolving them promptly. Inevitably, administrative resources will be wasted due to large-scale administrative lawsuits, and social costs will arise.
It is clear that investment in personal data protection must expand. However, excessive regulations centered on punishment that fail to draw out voluntary corporate investments can undermine the original purpose of personal data protection itself. Along with reasonable sanction standards that address actual damages, institutional incentives are needed to prevent incidents and enable prompt reporting and remediation.
