my timesThe Korea Times
  1. Opinion

Beyond fines: How Korea should respond to Coupang’s data breach, accountability gap

Listen
By Cho Hee-kyoung
  • Published Dec 24, 2025 3:03 pm KST

The recent personal information leak at Coupang should not be dismissed as an isolated cybersecurity incident. It reflects a deeper failure by a company that presents itself as an e-commerce leader, yet appears to have neglected even the most basic of responsibilities that come with collecting and monetizing vast amounts of customer data. When breaches occur at this scale, they are rarely the result of a single technical flaw; they are symptoms of questionable corporate priorities. The pattern points to a company that has underinvested in critical digital infrastructure while devoting significant resources to lobbying activities, choosing to manage regulatory and political risk rather than prioritize customer safety and security. This imbalance may be rational from a cost perspective, but it is deeply troubling from the standpoint of consumer trust and public accountability.

Korea’s regulatory response to data breaches has relied mainly on administrative fines and corrective orders. While necessary, these measures fall short against dominant digital platforms. For a company of Coupang’s scale and revenue, such penalties become mere routine business costs, not true deterrents. Indeed, Coupang has previously been fined by the Personal Information Protection Commission for failing to implement two-factor authentication for seller logins — a violation met with a penalty of just 3.5 million won ($2,364). In contrast, comparable privacy violations by U.S. technology firms have triggered regulatory responses serious enough to command the attention of senior management and boards.

This mismatch between penalty and harm is especially troubling given the nature of Coupang’s business. Despite branding itself as a technology company, Coupang functions simultaneously as a logistics operator, data aggregator, payments intermediary and advertising platform. Such vertical and horizontal integration dramatically amplifies the consequences of any cybersecurity failure. When personal information is mishandled at this scale, the resulting harm is not confined to individual users but radiates across the broader digital economy. The policy question is not merely how to punish Coupang after the fact, but how to redesign market and regulatory structures so breaches become both less likely and less burdensome to society.

More troubling than the breach itself has been Coupang’s posture in the aftermath. The company reportedly remained unaware of the incident for months, delayed notifying the relevant authorities and has responded to legislative scrutiny with what can only be described as indifference, if not disdain. The decision to replace the chief executive responsible at the time of the breach with a foreign national who does not speak Korean has only reinforced the perception of distance rather than accountability. Most strikingly, Chairman Kim Bum-soo has declined to appear before the National Assembly despite repeated calls for testimony. It's hard to imagine the head of a U.S. tech giant ignoring Congress without facing consequences. Yet Coupang, which earns the overwhelming majority of its revenue from Korea, appears to operate as though Korean law and democratic oversight are optional inconveniences rather than binding obligations.

It is precisely this pattern of behavior that has prompted policymakers elsewhere to reconsider whether traditional remedies are adequate for dominant digital platforms. Both the United States and the European Union have debated and, in some cases, pursued structural remedies to deal with companies whose scale and integration distort incentives. In theory, separating Coupang’s marketplace, logistics and data operations would reduce the temptation to accumulate and exploit personal data without commensurate safeguards.

A formal breakup would undoubtedly face legal and political hurdles in Korea. It would require a more expansive reading of competition law and would raise concerns about weakening nationally dominant corporations in a highly competitive global market. However, this option should not be treated as taboo. Even the credible threat of structural separation can alter corporate behavior, forcing dominant platforms to take compliance, governance and consumer protection seriously in ways that fines alone have failed to achieve.

If an outright breakup is politically unrealistic, regulators should pursue policies that achieve similar effects. Coupang should be prohibited from freely combining consumer data across its commerce, logistics, payments and advertising businesses. Data silos, though often disparaged in corporate management, reduce privacy risks and limit the competitive advantages that flow from excessive data concentration. Dominant platforms should also face stricter rules on data retention and use, as well as enforceable data portability requirements that allow consumers and merchants to switch platforms more easily. In addition, future acquisitions or expansions by Coupang should be presumed anticompetitive unless proven otherwise.

At the same time, policymakers should reconsider the asymmetrical regulatory burden placed on traditional retailers. Large supermarkets remain subject to strict rules governing opening hours, delivery methods and operations — regulations originally designed to protect small merchants. Yet the retail landscape has already been fundamentally reshaped by e-commerce platforms that face few comparable constraints. Preserving outdated restrictions on offline competitors while allowing dominant online platforms to scale freely only entrenches market concentration rather than promoting fair competition.

Coupang’s slogan asks, “How did I live without Coupang?” Some consumers have already begun to answer that question by voting with their feet. The more urgent issue today is whether we should accept living with a platform that treats personal data protection as an afterthought. Convenience is not a license for carelessness. A society that values privacy and accountability can live perfectly well without any company that fails to respect them.

Cho Hee-kyoung is a professor of law at Hongik University. The views expressed in the article are the author’s own and do not reflect the editorial direction of The Korea Times.