The Korean authority sanctions TikTok and Apple for illegal collection of personal data

The South Korean authority sanctions TikTok and Apple for collecting and transferring user data without a valid legal basis, highlighting in particular the invalidity of bundled consent for behavioral tracking and the lack of transparency in international data flows.

Facts and context

The South Korean Personal Information Protection Commission (PIPC) today issued a sanction decision against Tiktok Pte. Ltd. and two Apple subsidiaries (including a total fine of 10.558 billion won, approximately €7 million) for breaches related to the collection, use, and international transfer of personal data without a valid legal basis.

The investigation concerning TikTok was initiated following press reports indicating possible violations of the Personal Data Protection Act. The investigation targeting Apple began after media coverage of a lawsuit in the United States regarding unauthorized collection and use of voice data from the "Siri" service.

Grounds for the decision

Regarding Tiktok Pte. Ltd.

  • Obligation to have a legal basis for data collection and use (equivalent to Article 6 of the GDPR): The authority found that TikTok collected information on user behavior on third-party sites and apps via its tracking tools (Pixel, software development kit), affecting 9.45 million active users in Korea. This data, including advertising identifiers, was then linked to TikTok accounts for profiling and targeted advertising. The consent obtained was deemed invalid because it was presented bundled with the terms necessary for service use, effectively forcing users to accept this tracking to access the platform, thus depriving consent of its free nature.
  • Obligation to regulate data transfers outside the territory (Articles 44 and following of the GDPR): The transfer of this behavioral data abroad was deemed unlawful due to the lack of an appropriate legal basis.
  • Obligation to inform at the time of collection (equivalent to Article 13 of the GDPR): Within the "TikTok Lite" service, data was transferred to an affiliated company without users being informed of the categories of data concerned, the purpose of processing by the recipient, or retention periods, violating transparency requirements.

Regarding Apple Distribution International Limited (ADI) and Apple Services Pte. Ltd. (ASPL)

  • Obligation to have a legal basis for data collection and use (equivalent to Article 6 of the GDPR): It was established that until August 2019, Apple collected "Siri" voice recordings and their textual transcriptions to improve its service without obtaining separate consent. After this date, although consent was requested for voice recordings, the use of textual transcriptions continued without a valid legal basis.
  • Obligation to inform and regulate data transfers outside the territory (equivalent to Articles 13 and 44 of the GDPR): The authority noted that the information provided in the privacy policy about data transfers to affiliated companies, notably Apple Inc. in the United States, was insufficient. It did not precisely detail the categories of data transferred, the purposes pursued by the recipient, or retention periods.

Authority's decision

Consequently, the authority imposed a fine of 10.306 billion won (approximately €6.87 million) on Tiktok Pte. Ltd. and a fine of 252 million won (approximately €167,000) on the Apple subsidiary, Apple Distribution International Limited.

Furthermore, the authority ordered the companies to take corrective measures, publish the sanction decision, and instructed the subsidiary Apple Services Pte. Ltd. to review its international data transfer processes to strengthen the level of protection.

Lessons learned

This decision confirms / specifies / recalls that:

  • The data subject's consent is valid only if given freely, which excludes bundled or mandatory consent mechanisms to access a service not directly related to that processing.
  • The notion of "international data transfer" is to be understood broadly and covers any transfer outside the authority's jurisdiction, including intra-group transfers, which must comply with applicable legal requirements.
  • Transparency is a fundamental obligation requiring precise description in the privacy policy of the modalities of data transfers, including data categories, recipients, purposes, and retention periods.
  • Foreign companies processing local residents' data are fully subject to national data protection laws and must ensure respect for the right to informational self-determination.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire