
#Businessman A created an open chat room to allow consultation staff to check the status of inquiries together, and uploaded an Excel file containing customers' personal information. The open chat room was accessible to anyone, and no password was set on the Excel file, resulting in the leakage of dozens of customer records to individuals who were not employees. A received a penalty of 1.8 million won.
#Office worker B disposed of copies of contracts in the trash without incinerating or shredding them while relocating their office. A passerby collected them and contacted the contracting parties directly, involving approximately 100 cases. Discarding documents containing personal information without incineration or shredding was not recognized as proper disposal of personal information, resulting in a penalty of 1.8 million won.
As data breach incidents have emerged as a new risk for companies, Naver (NAVER) launched an information protection strengthening campaign on the 30th, Personal Information Protection Day, including disclosing actual administrative penalty cases to Smart Place business operators.
Naver also introduced basic compliance requirements for personal information protection through Smart Place announcements. It emphasized that customer information received from Naver may only be used within the scope of the provided purpose, such as order processing, delivery, reservation confirmation, payment processing, and customer consultation, and that information whose purpose has been fulfilled should be destroyed immediately as a principle.
Discussions on the latest security issues will also continue. Naver's Personal Information Protection Commission held a regular meeting in early this month to discuss AI security threats. In particular, as generative AI and agent AI spread, new types of threats that are difficult to fully detect with existing security frameworks have been highlighted, leading to a decision to continuously strengthen capabilities for early detection and response.
Smart glasses privacy was also discussed. Given the successive concerns raised domestically and internationally regarding privacy violations and illegal filming caused by smart glasses, measures were decided to be prepared. The committee is reported to have examined various social issues, including cases where smart glasses were misused for cheating on exams.
Physical AI end-to-end security was also discussed. The committee pointed out that for physical AI, protection measures for individual elements alone are insufficient, and it may be difficult to identify the cause of problems arising from the process in which devices make autonomous judgments and operate. Naver decided to systematically manage security elements from the planning and development stages and ensure traceability so that causes and impacts can be identified when an incident occurs.
A Naver official said, "Going forward, while prioritizing the safe protection of user information, we will continue to develop our personal information protection system to flexibly respond to the rapidly changing technological environment."