DistantNews
Support us
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Crime & Justice

Child Rights Agency Fined Record $7.2 Million for Data Breach

From Hankyoreh · () Korean

Translated from Korean and summarized by DistantNews. Read the original for the full story.

At a glance

News Named sources Outcome reported
  • The National Child Rights Guarantee Agency (NCRA) was fined a record 880 million won for leaking personal data of over 1.17 million individuals.
  • The leaks involved personal information of adoptees and missing children due to mishandling of digital storage media and system errors.
  • The agency also failed to notify affected individuals and authorities within the legally mandated 72-hour period after discovering the breaches.

South Korea's Personal Information Protection Commission has imposed a record fine of 880 million won (approximately $7.2 million) on the National Child Rights Guarantee Agency (NCRA) for significant data privacy violations. The agency is penalized for leaking the personal information of over 1.17 million individuals, including missing children and adoptees, and for failing to promptly notify the affected parties and relevant authorities as required by law.

Investigations revealed that the NCRA mishandled digital storage media containing sensitive data during a project to digitize adoption records and missing child files between 2013 and 2022. A CD containing adoptee information and an external hard drive with missing child data were lost. These storage devices lacked proper management logs and designated custodians. The leaked data included names, addresses, and contact information for approximately 1.14 million adoptees and 30,000 missing children. Crucially, sensitive information like resident registration numbers was not encrypted.

Compounding the issue, the NCRA failed to report the data breaches within the 72-hour timeframe stipulated by law. Furthermore, the agency was found to have neglected its oversight of contractors, even sharing database access credentials with them. In addition to the substantial fine, the commission issued a corrective order, recommended disciplinary action against responsible staff, and mandated public disclosure of the violation.

In a separate incident, the NCRA's system for processing adoption information requests experienced a design flaw in March-April of this year. This error exposed the personal information of 47 individuals, including adoptees and prospective adoptive parents, to unauthorized third parties. The system incorrectly assigned sequential application numbers, allowing access to unrelated documents. For this breach, the NCRA faces an additional fine of 52.5 million won. The Personal Information Protection Commission emphasized the heightened responsibility of public institutions in safeguarding personal data due to the public's trust and the sensitive nature of the information they handle.

Public institutions, given the high public interest and expectations regarding personal information protection, and the significant meaning and value of the personal information they handle, must do their utmost to protect personal information.

โ€” Personal Information Protection CommissionEmphasizing the responsibility of public institutions in data protection.
About this summary

Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.