South Korea's public sector faces soaring data breaches ahead of new privacy law

Public institutions in South Korea report a sharp increase in personal data leaks, highlighting internal weaknesses as the country prepares to enforce stricter privacy regulations later this year.

South Korea’s privacy regulator has recorded a sharp rise in data breaches at state bodies, with 164 public institutions reporting personal information leaks in the first half of 2026, according to figures compiled by opposition lawmaker Rep. Song Eon-seok from the Personal Information Protection Commission. That is already above the full-year total of 128 cases in 2025 and far beyond the 22 incidents logged in 2021, underscoring how quickly the public sector’s record has deteriorated as the country prepares for tougher privacy rules later this year.

The trend has worsened year by year. PIPC records show 23 public institutions were hit in 2022, rising to 41 in 2023 and 104 in 2024 before last year’s total climbed further. If the first-half 2026 pace continues, the annual figure would be well above last year’s record. The cases processed by the commission since 2022 involved about 7.84 million exposed records, including names, contact details, home addresses, resident registration numbers, bank account information and health data.

What stands out in the data is the cause of most incidents. Of the 139 cases formally handled by the PIPC between 2022 and the first half of 2026, 94 were linked to negligence, while 44 stemmed from hacking and one from deliberate internal wrongdoing. That means the main weakness is often not sophisticated external attack, but poor handling, weak access discipline and failures in internal governance. In practice, that points to training, supervision and accountability rather than only technical defences.

The contrast with private-sector enforcement has become more visible this year. In February, South Korea’s watchdog fined the local units of Louis Vuitton, Dior and Tiffany a combined 36 billion won over customer data leaks, with the largest penalty going to Louis Vuitton Korea after a breach affecting about 3.6 million customers, according to Yonhap. In June, the commission imposed a record 624.6 billion won fine on Coupang after a breach affecting more than 37 million customers, and in July it fined KT Corp. 53.9 billion won over a separate leak. The scale of those actions highlights a clear willingness to punish companies aggressively.

The timing is significant because South Korea’s amended Personal Information Protection Act is due to take effect on 11 September, after passing the National Assembly in March. The changes raise the maximum administrative fine to 10% of total annual turnover in severe cases and introduce direct personal supervisory liability for institutional heads where systemic compliance failures are found. Legal analyses of the reform say the new framework is designed to push privacy from a paper exercise into an executive responsibility.

That matters for government agencies as much as for companies. Under the new rules, the heads of public institutions could face personal accountability if privacy governance fails at scale. The reform also reflects a wider effort to strengthen deterrence after repeated major incidents, including the recent breach at the Korea National Diplomatic Academy’s training platform, which was said to have exposed about 10,000 records over several months. Even where the initial cause is external intrusion, weak monitoring and slow detection remain part of the failure.

For citizens, the issue is especially acute because public bodies hold information people cannot readily withhold. Tax offices, welfare agencies, hospitals and local authorities collect data as a condition of basic services. That means a breach at a state institution can affect records that are not merely sensitive, but often unavoidable to share. Whether the new law forces the same level of accountability on government bodies that regulators have begun imposing on major companies will become clear only after the September deadline.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.