The Korean authority calls for strengthening the prevention of personal data leaks related to the use of application programming interfaces
The South Korean Personal Information Protection Commission (PIPC) has issued recommendations to companies to prevent personal data leaks via application programming interfaces (APIs), whose use is rapidly expanding.
This warning follows several security incidents where flaws in API authorization management allowed massive information leaks. The observed shortcomings include APIs that only verify login status without checking specific data access rights, or that include unnecessary information in their responses. These vulnerabilities have led to breaches, such as the leak of data of 37,000,000 people (name, address, email, phone number, date of birth) through abnormal access, the unintentional transmission of the phone number of 135,000 users to a third-party system, or access to customer data via an old unsecured API that remained active.
The commission recommends a structured approach around three main axes. First, compliance with the data minimization principle from the design phase, excluding any non-essential data from API responses and limiting bulk requests. Second, rigorous authorization management based on the principle of least privilege, assigning differentiated rights according to user type and blocking by default any unauthenticated or unauthorized requests. Third, continuous monitoring of APIs in service, including maintaining an up-to-date inventory, deleting obsolete APIs, revoking unused access keys, and detecting suspicious activities through connection log analysis. Companies using third-party APIs are also required to verify received data and delete any irrelevant personal information.
This warning follows several security incidents where flaws in API authorization management allowed massive information leaks. The observed shortcomings include APIs that only verify login status without checking specific data access rights, or that include unnecessary information in their responses. These vulnerabilities have led to breaches, such as the leak of data of 37,000,000 people (name, address, email, phone number, date of birth) through abnormal access, the unintentional transmission of the phone number of 135,000 users to a third-party system, or access to customer data via an old unsecured API that remained active.
The commission recommends a structured approach around three main axes. First, compliance with the data minimization principle from the design phase, excluding any non-essential data from API responses and limiting bulk requests. Second, rigorous authorization management based on the principle of least privilege, assigning differentiated rights according to user type and blocking by default any unauthenticated or unauthorized requests. Third, continuous monitoring of APIs in service, including maintaining an up-to-date inventory, deleting obsolete APIs, revoking unused access keys, and detecting suspicious activities through connection log analysis. Companies using third-party APIs are also required to verify received data and delete any irrelevant personal information.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire