The Korean authority recommends corrective measures to strengthen data security in funeral services

The South Korean Personal Information Protection Commission (PIPC) has issued corrective recommendations against three major companies in the funeral services sector following a preventive inspection on the processing of personal data.

The inspection, initiated in January following recent data breaches in this sector, targeted the three main operators representing 70% of the market based on their advance payments. The authority identified several shortcomings, including insufficient security measures such as unpatched vulnerabilities, poor management of access rights for inactive accounts, and incomplete connection logs. It was also found that personal data was retained beyond the legal retention period after service termination, without being destroyed or stored separately. Finally, subcontractor supervision was deemed inadequate, with some not subjected to audits or training.

Other issues, such as insufficient access control to internal database servers, lack of encryption of data in transit, and non-compliance with the requirements to designate a Data Protection Officer (DPO), were identified but corrected by the companies during the inspection. The PIPC emphasized that this preventive approach has strengthened internal control systems and announced that it will verify the implementation of its recommendations.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire