Seoul: The data protection regulator announced Thursday that it will hold a plenary meeting next week to determine penalties against SK Telecom Co. following a significant data breach that impacted tens of millions of customers.
According to Yonhap News Agency, the Personal Information Protection Commission (PIPC) plans to convene a closed-door session next Wednesday to assess proposed penalties against SK Telecom, the largest telecom operator in South Korea by user numbers. The commission's decision may be delayed if further discussions are deemed necessary by its members.
In April, SK Telecom reported that universal subscriber identity module (USIM) data might have been leaked during a cyberattack on its servers. This prompted the company to offer free USIM replacements to approximately 25 million users. The regulator recently concluded its investigation into the breach and informed SK Telecom of its intended measures late last month.
Under the personal information protection law, companies may be fined up to 3 percent of their total sales, excluding revenues from areas unrelated to the violation. With SK Telecom's mobile communications division generating 12.77 trillion won (US$9.13 billion) in sales last year, the company could face a record fine exceeding 300 billion won.
In 2022, the PIPC imposed a combined 100 billion won penalty on Google and Meta for collecting personal information without users' consent, marking the highest fine ever levied by the regulator.