In short
South Korea's Personal Information Protection Commission sanctioned the National Center for the Rights of the Child, a public body, over a series of breaches involving particularly sensitive personal data. The total is 885.2 million won: 863 million in penalties and 22.2 million in administrative fines.
The project that created the problem
Between 2013 and 2022 the agency digitised its paper records on children. The work covered more than 1.17 million records: roughly 1.14 million on adoptees and about 30,000 on missing children. Among the data processed were resident registration numbers — the Korean equivalent of a national ID number, but with far greater identifying weight — stored unencrypted.
The data ended up on inadequately protected devices, and the agency lacked basic controls to track where those devices were. Their absence surfaced only during checks carried out in 2024 and in 2026: two years between one realisation and the next.
Why this case is worth more than an ordinary fine
- These are data that follow a person for life: someone searching for their origins, someone given up for adoption, a family that lost a child
- There is no remedy: an identification number cannot be changed like a password, and an adoption file cannot be made confidential again once it is out
- The controller is a public body — the very entity those people were obliged to hand their data to. There was no alternative, no other supplier
- The digitisation was done for a good purpose — making the archives consultable — and that prevented nothing
The digitisation project is the moment of risk, not the archive
A paper archive locked in a warehouse is slow and inconvenient, but it is also hard to carry away wholesale. The moment you digitise it, the entire content moves onto media that get copied, moved and lost. Treat the digitisation project as processing in its own right: impact assessment, encrypted media, a named inventory of devices, and a periodic reconciliation that does not wait two years.
Questions for a client who is digitising
- Who physically does the scanning: internal staff or a supplier? If a supplier, does the Article 28 agreement also cover transport and custody of the media?
- Where do the files sit during processing, before reaching the destination system? That is the temporary archive nobody puts in the record
- Are the removable media encrypted? Is the encryption verified, or is it a box ticked in a tender document?
- Is there a device inventory with a named owner for each, and how often is it reconciled?
- What happens to the paper originals at the end: certified destruction, or a warehouse everyone forgets about?
The size of the fine — about USD 641,000 — is not the important part. The important part is that a public body took two years to notice that devices holding over a million sensitive files were not where they should be. The control missing here is not technological: it is a list kept current by someone who answers for it.
Official source:Personal Information Protection Commission (Corea del Sud) - comunicati e decisioniLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free