Enforcement action · Personal Information Protection Commission (PIPC)

The PIPC Sanctions Three Businesses for Failures to Implement Safeguards Required under the PIPA

The PIPC Sanctions Three Businesses for Failures to Implement Safeguards Required under the PIPA is an AI-related enforcement action involving Personal Information Protection Commission (PIPC). Penalty: monetary_fine of $KRW 706,400,000. The South Korean Personal Information Protection Commission sanctioned three companies with over KRW 700 million in fines and publication orders for failing to implement adequate data protection safeguards under the PIPA, leading to data breaches.

Action details

Agency
Personal Information Protection Commission (PIPC)
Jurisdiction
KR
Enforcement type
fine
Document type
enforcement action
Penalty
$KRW 706,400,000 monetary_fine
Effective
2026-07-09
Topic
ai privacy

Summary

The Personal Information Protection Commission (PIPC) of South Korea issued administrative fines totaling KRW 706.4 million and publication orders against LocknLock, Ubase, and SUN-PHOTO. The sanctions resulted from failures to implement adequate safeguards under the Personal Information Protection Act (PIPA), which led to significant data breaches affecting millions of individuals. Key failures included not updating security patches, using weak authentication, not encrypting sensitive data, and poor access log management and access control. This action signals heightened enforcement against common data security negligence.

Primary source

https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=null&nttId=3112 →

Frequently asked questions

What is The PIPC Sanctions Three Businesses for Failures to Implement Safeguards Required under the PIPA?
The Personal Information Protection Commission (PIPC) of South Korea issued administrative fines totaling KRW 706.4 million and publication orders against LocknLock, Ubase, and SUN-PHOTO. The sanctions resulted from failures to implement adequate safeguards under the Personal Information Protection Act (PIPA), which led to significant data breaches affecting millions of individuals. Key failures included not updating security patches, using weak authentication, not encrypting sensitive data, and poor access log management and access control. This action signals heightened enforcement against common data security negligence. Primary source →
Which agency brought the action?
Personal Information Protection Commission (PIPC) brought this enforcement action in KR. Primary source →
What was the penalty?
The disclosed penalty is a monetary_fine amount of $KRW 706,400,000. Primary source →
When did the action take effect?
The action was effective 2026-07-09. Primary source →
Where can I find the primary source?
The primary source for The PIPC Sanctions Three Businesses for Failures to Implement Safeguards Required under the PIPA is at https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=null&nttId=3112. AIGI does not paraphrase secondary commentary — every claim on this page links back to that primary source. Primary source →

Regulatory intelligence

Follow reviewed Personal Information Protection Commission (PIPC) AI enforcement developments.

AIGI monitors cited regulatory change and delivers decision-ready analysis. It does not monitor customer AI systems or enforce policy.