The dispute over a personal-data breach at Coupang, South Korea's dominant online retailer, has entered a new and fractious phase. The Consumer Dispute Mediation Committee, which sits within the Korea Consumer Agency, proposed that Coupang pay 100,000 won (roughly $75) to each affected individual. Coupang refused, sending tens of thousands of victims back to the beginning of what promises to be a long and costly road to redress. The episode raises uncomfortable questions about whether large platform companies in South Korea are ever meaningfully held to account for data failures.
From breach to breakdown: a chronology
The affair began when a large volume of Coupang users' data was exposed externally. Victims alleged that sensitive personal information — including names, telephone numbers, home addresses and purchase histories — had been leaked, and filed for collective redress. After reviewing submissions from both sides, the mediation committee arrived at its 100,000-won-per-person award. Coupang declined to accept it, and the process collapsed.
The collective dispute-mediation mechanism is grounded in South Korea's Framework Act on Consumers. It is designed to deliver wholesale relief when many people suffer harm from a common cause. When a proposed settlement is rejected, victims must pursue individual civil litigation — a path that is slower, more expensive and far less certain. In effect, a wall of time and money is erected in front of each claimant all over again.
Why Coupang said no — and what lies beneath
Coupang has not publicly explained its decision, but industry observers point to several probable motives.
The first is the sheer arithmetic of aggregate liability. One hundred thousand won sounds modest, but multiplied across tens of thousands of claimants the total bill runs to billions, potentially tens of billions, of won. For any corporation, agreeing to a collective payout of that magnitude sets a dangerous precedent.
The second is a legal dispute over culpability. In data-breach cases, the pivotal question is whether the company took "sufficient technical and administrative protective measures" — the standard enshrined in Article 29 of South Korea's Personal Information Protection Act. Companies routinely argue that external hacking constitutes force majeure, an unforeseeable event beyond their control. Coupang appears likely to be advancing a similar line of defence.
Third, accepting the mediation award could create problems in any subsequent civil litigation. Data-protection lawyers note that agreeing to a settlement can be interpreted as an implicit admission of negligence, thereby strengthening plaintiffs' hands in court. The legal calculus may therefore favour rejection even if the headline cost of acceptance is lower.
Is 100,000 won adequate compensation?
Victim groups and civil-society organisations argue that the proposed sum is derisory regardless of whether Coupang accepts it. Once personal data has been exposed, the potential for secondary harm — spam, voice-phishing scams and financial fraud — is substantial and essentially impossible to quantify in advance.
South Korean court precedents on data-breach compensation vary enormously. In 2012 the Supreme Court upheld a 200,000-won award per victim in the hacking of SK Communications, which operated the Cyworld and Nate platforms. In the 2014 credit-card companies' data-breach cases, rulings from different courts ranged from nothing to more than 1,000,000 won per person. The absence of a clear standard for translating the psychological harm of a privacy violation into monetary damages remains the single biggest obstacle to effective redress.
The scale of the underlying problem is striking. According to the Personal Information Protection Commission, more than 1,600 data-breach incidents were reported in 2023 alone, and the volume of exposed data continues to rise. Yet only a small fraction of cases ever result in compensation, leaving what experts describe as vast blind spots in the protection of victims.
International comparisons: a harder line elsewhere
Other major jurisdictions take a significantly sterner approach. The European Union's General Data Protection Regulation (GDPR) allows fines of up to 4% of a company's global annual revenue. Amazon was hit with an $887 million GDPR penalty in 2021; Meta was sanctioned for $1.2 billion in 2023.
The United States has a well-developed class-action system that forces companies to face the full collective liability of a plaintiff class in a single proceeding. In 2023 T-Mobile settled a data-breach class action for $350 million.
South Korea, by contrast, caps data-protection fines at 3% of the revenue derived from the offending activity (Article 64-2 of the Personal Information Protection Act). Class-action litigation is available only in securities cases; for everything else, victims must sue individually. Specialists argue that this structural gap encourages moral hazard: the penalty for a breach is simply too low relative to the cost of preventing one.
What options remain for victims
After the mediation breakdown, victims face two realistic choices: civil litigation, or filing complaints with the Personal Information Protection Commission in the hope of additional regulatory sanctions. Individual lawsuits are expensive and slow; even successful claimants often find that the damages awarded fall short of their legal costs.
Some victim groups are said to be co-ordinating with law firms to bring a joint action that would spread the burden across a larger group of plaintiffs. Legal experts view such collective suits as the most practical remaining avenue, while cautioning that proceedings could drag on for years.
Structural failures and calls for reform
This affair is not merely a problem for Coupang; it is a symptom of broader weaknesses in South Korea's personal-data protection ecosystem. Consumer groups and academics are pressing for several reforms.
The most urgent, in the view of many, is the introduction of a general class-action mechanism. The current collective-mediation system is structurally neutered the moment a company refuses to accept a proposed award. Campaigners argue that companies which reject mediation should face automatic legal enforcement, or at the very least a formal penalty for doing so.
Strengthening punitive damages is another priority. Under existing law, statutory damages for personal-data violations are capped at 3,000,000 won per person (Article 39-2 of the Personal Information Protection Act) — a ceiling widely regarded as an inadequate deterrent to large-scale breaches. "As long as companies judge that the cost of compensation is lower than the cost of security investment, structural improvement will remain out of reach," one data-protection specialist warned.
There are also calls to expand the Personal Information Protection Commission's role from retrospective sanctioning to proactive oversight of companies' data-handling systems before problems arise.
Outlook: a test of platform trust
Coupang holds the personal data of tens of millions of South Koreans. The long-term reputational consequences of its refusal to accept the mediation award remain to be seen, but in an era of growing consumer vigilance towards platform companies, a dismissive response carries real risk of backfiring.
Legal scholars and academics suggest that this case could prove a turning point — the moment that finally forces a rethink of how South Korea handles data-breach redress. As consumer awareness grows and the economic value of personal data becomes more widely understood, the social and legal pressure on companies that reject even modest settlements is unlikely to abate. The lesson, many argue, is that the resolution of such disputes cannot rest on courtroom battles alone. It requires both genuine corporate accountability and a regulatory framework with teeth.
