The Korean authority fines Bithumb 210 million won for violating international personal data transfer rules

Sanction of a crypto-asset sector player for international transfers of personal data carried out without the specific and informed consent of users, notably by designating an incorrect recipient.

Facts and context

The South Korean data protection authority (PIPC) today published a sanction decision against Bithumb (including the imposition of a fine of 210,000,000 KRW, approximately €139,000) for breaches related to international transfers of personal data.

The case originated from a 2025 parliamentary audit that raised questions about the legality of sharing the platform's order book with foreign exchanges.

Grounds for the decision

  • Obligation to ensure the lawfulness of international data transfers: The authority first found that, between September and November 2025, the company shared its Tether market order book with a foreign exchange. Although consent was obtained for a transfer to the "Stella Exchange," the data (member number and order information) were actually transmitted to a system operated by another entity (bingx.com). The authority therefore ruled that the consent obtained was not valid, as it did not designate the actual recipient of the data, rendering the transfer unlawful. Then, during the transfer of users' virtual assets to 13 foreign exchanges, the company communicated personal data of senders and recipients (name, wallet address, date of birth) for anti-money laundering purposes. The authority noted that these transfers were made without obtaining the separate consent of the data subjects, in violation of the requirements set out by the Personal Information Protection Act. While recognizing the necessity of these transfers for compliance reasons, the authority emphasized that individuals' right to self-determination over their data requires strict adherence to the legal procedures governing international transfers.

Authority's decision

Consequently, the authority imposed a fine of 210,000,000 KRW (approximately €139,000) on Bithumb.

Furthermore, the authority ordered the company to comply with legal requirements for international data transfers, notably by obtaining valid consent from data subjects and clearly informing users of these transfers in its privacy policy.

Lessons learned

This decision reminds that:

  • consent to an international data transfer is only valid if it precisely and correctly identifies the actual recipient of the data;
  • the legitimate purpose of a transfer, such as anti-money laundering, does not exempt the data controller from complying with the specific procedural requirements for international transfers, such as obtaining separate consent;
  • the use of technologies such as blockchain requires a prior risk analysis for data protection, particularly regarding transparency, decentralization, and immutability of recorded information;
  • privacy policies must transparently and accurately describe cross-border data flows, including data categories, purposes, and recipient countries.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire