SOUTH KOREA Trends and Developments Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
incident response and emerging technology issues, including AI. Jihoon earned his LLM from the UCLA School of Law and his LLB from Seoul National University. He is admitted to the Korean Bar and previously served as a judge advocate in the Republic of Korea Army.
Lee & Ko Hanjin Building 63 Namdaemun-ro Jung-gu Seoul 04532 South Korea Tel: +82 2 772 4000 Fax: +82 2 7724 0012 Email: mail@leeko.com Web: www.leeko.com
South Korea (“Korea”) is globally recognised as an information and communication technology (ICT) powerhouse, built upon its high-speed internet pen - etration and mobile-centric digital ecosystem. How - ever, a recent wave of large-scale hacking incidents and subsequent data breaches (ie, incidents involving the loss, theft or unauthorised disclosure of personal information) targeting major domestic telecom com - panies (such as SK Telecom and KT) and large plat - form operators (such as Coupang) has elevated data protection and cybersecurity to critical social issues. This shift has prompted a fundamental reassessment and overhaul of the existing regulatory framework. In light of this evolving landscape, this article examines Korea’s current data protection and cybersecurity regulations, outlines the anticipated trend towards stricter enforcement, and provides practical recom - mendations for domestic and foreign operators navi - gating these developments. Recent Trends in Cyber-Attacks and Changes in Social Perception Over the past three to four years, the volume of report - ed cyber incidents and data breaches in Korea has steadily increased. Attack vectors have diversified to include hacking, ransomware, account theft, insider
leaks and supply chain attacks, with threat actors increasingly employing methods characterised by long-term dormancy and continuous infiltration. Notably, 2025 witnessed a series of high-profile data breaches targeting major players in the telecom and platform sectors. In certain instances, the potential compromise of tens of millions of customer records was announced, causing significant social repercus - sions. These events are no longer viewed merely as isolated accidents stemming from inadequate corpo - rate security. Instead, they have drawn attention to: • the sheer scale and sensitivity of data processed by major operators; • the adequacy of the current regulatory framework in ensuring the safety and reliability of ICT infra - structure; and • the urgent need for robust corporate data protec - tion governance. Consequently, regulatory authorities and the National Assembly have moved beyond piecemeal amend - ments, initiating a comprehensive overhaul of cyber - security regulations that encompasses heavier sanc - tions, executive accountability, stringent incident
320 CHAMBERS.COM
Powered by FlippingBook