
Starting next month, businesses that repeatedly cause personal information infringement incidents due to intent or gross negligence will be subject to penalties of up to 3% of their related revenue.
The Ministry of Science and ICT announced on the 30th that the "Act on Promotion of Information and Communications Network Utilization and Information Protection, etc." (Information and Communications Network Act) and its enforcement decree, which comprehensively strengthen information protection systems from preventing cyber intrusion incidents to post-incident response and sanctions, will take effect on the 1st of next month.
The amended law was established to institutionally support the "Comprehensive Information Protection Measures Across Ministries" announced following a series of major intrusion incidents last year. From the perspective of strengthening corporate security governance, provisions have been newly added to secure the substantive authority of the Chief Information Security Officer (CISO), mandate the establishment of an information protection committee, introduce a strengthened Information Security Management System (ISMS) certification system, expand the government's ex officio investigation authority, raise fines for delayed reporting, impose enforcement fines for non-compliance with corrective orders, and establish a penalty system for repeated intrusion incidents.
Specifically, businesses that repeatedly cause infringement incidents due to intent or gross negligence will be subject to penalties of up to 3% of their related revenue, depending on the severity. Businesses that fail to comply with government corrective orders or document submission requests will be charged an enforcement fine equivalent to 0.02% of their average daily revenue for each day of non-compliance.
To facilitate rapid investigation of intrusion incidents, a formal Intrusion Incident Investigation Review Committee under the Ministry of Science and ICT will be operated to deliberate on the necessity of rapid government investigations when circumstances indicating an intrusion incident are established. The committee will consist of 15 members from the private and public sectors, including Wi Won-hoe-neun (Chairman), with a two-year term for private sector members.
To strengthen corporate information protection governance, the status of the Chief Information Security Officer will be elevated from existing employees to executive officers. Accordingly, mid-sized companies, etc., must designate their Chief Information Security Officer as an executive officer. Additionally, companies obligated to report their Chief Information Security Officer must mandatorily establish and operate an information protection committee within the company.
In addition, to enhance the effectiveness of the Information Security Management System certification system, a new enhanced certification will be introduced for businesses that suffer significant damage in the event of an intrusion incident. Targets for enhanced certification include, among those obligated to obtain ISMS certification: △major information and communications service providers and integrated information and communications facility operators, such as telecommunications companies, with revenue of 1 trillion won or more in the previous year; △information and communications service providers with revenue of 3 trillion won or more in the previous year; and △businesses that have been subject to investigation by a joint public-private investigation team or penalty imposition within the last three years.
Vice Prime Minister and Minister of Science and ICT Bae Kyung-hoon stated, "The implementation of this Information and Communications Network Act and its enforcement decree has laid an institutional foundation for further strengthening corporate security awareness and accountability." He added, "We expect companies to recognize security not merely as a cost but as an essential element of management and to continue with active investment. The government will also actively support the establishment of these systems to create a digital environment where citizens can use services with peace of mind."