Coupang's latest privacy penalty is not just large. The newly disclosed deliberation record shows why South Korea's privacy regulator treated the case as a serious breach and why it rejected several arguments that would have reduced the sanction. The Personal Information Protection Commission finalized 423.575 billion won in penalties tied to the large personal-data leak, part of a broader 624.681 billion won enforcement action announced in June.
The scale puts the case in a category of its own. The privacy-leak portion alone is more than three times the previous record sanction cited by Korean media. The underlying breach affected about 37.5 million people, giving the commission a nationwide consumer-protection problem rather than a narrow corporate compliance dispute. For a platform used across Korean households, the enforcement reaches far beyond a specialist privacy-law audience.
The penalty calculation
According to the commission's meeting transcript, Coupang argued that the sales base used to calculate the fine should be narrowed. It sought a net-sales approach and asked the regulator to exclude delivery and storage amounts from relevant revenue. The commission rejected those requests and maintained a broad basis for calculating the penalty. That decision directly shaped the size of the sanction.
The transcript also shows that the final number was not produced by a single automatic formula. Regulators applied an aggravating factor for obstruction of the investigation, then granted a larger reduction reflecting corrective measures and compensation. That combination matters because it reveals how the commission weighed both the seriousness of the conduct and the company's response after the breach.
A benchmark for platform privacy enforcement
The official enforcement release says the broader case also included a separate 201.106 billion won sanction for unauthorized collection of online activity records and other privacy-law violations. Corrective orders and disclosure requirements accompanied the financial penalties. Together, the measures show that the regulator is treating privacy enforcement as more than a one-time fine.
For consumers, the case establishes a practical benchmark for how seriously large-scale leaks can be treated when millions of accounts are involved. It also gives companies a clearer warning about the limits of arguments that narrow the revenue base used for sanctions. The commission's reasoning suggests that post-incident remediation can matter, but it does not erase failures in safeguards or other legal duties.
For other large platforms, the calculation record is likely to matter almost as much as the headline amount. It shows which defenses failed, which mitigating steps received credit and how obstruction can increase exposure. Compliance teams can now compare their own incident-response plans against a case in which the regulator has made its reasoning unusually visible.
Attention now turns to Coupang's response to the finalized reasoning and to whether the case changes compliance behavior across large Korean platforms. The size of the penalty guarantees attention, but the more durable effect will depend on whether companies strengthen data safeguards before another breach rather than relying on corrective action afterward.

