South Korea is sharply increasing the financial consequences for companies responsible for very large personal-data leaks, with a new penalty ceiling of up to 10 percent of sales for the most serious cases. The tougher regime takes effect this week and applies when a breach affecting more than 10 million people results from intentional misconduct or gross negligence.

The previous maximum penalty was 3 percent of sales. The revised rules also allow the higher ceiling to be used against companies that repeatedly violate personal-information law within three years or fail to comply with corrective orders and then suffer another leak. Regulators can reduce the penalty by up to 40 percent when a company can demonstrate substantial investment in privacy protection and other security measures.

Cybersecurity failures now carry a larger balance-sheet risk

The change follows a series of high-profile data incidents that raised questions about whether existing fines were large enough to change corporate behavior. For large platforms, retailers and online services, a percentage of total sales can translate into a much larger exposure than a fixed fine. That makes cybersecurity spending, incident response and compliance with regulatory orders more directly connected to financial risk.

The practical effect will depend on how the Personal Information Protection Commission applies the new standard in major cases. Companies will be watching what counts as gross negligence, how regulators calculate the relevant sales base and how much credit is given for security investment before an incident. For users, the reform does not eliminate the risk of leaks, but it raises the cost of failing to prevent or properly address them.