The South Korean authority sanctions the National Center for Children's Rights for massive personal data leak of missing and adopted children
A massive data leak involving more than 1.17 million records of missing children and adopted persons was caused by poor management of removable storage media by a public body. The lack of data encryption and failure to comply with notification obligations worsened the situation.
Facts and context
The South Korean authority, the Personal Information Protection Commission (PIPC), issued on August 27, 2026, a sanction decision against the National Center for Children's Rights (CNDE), including the imposition of a fine of 832,700,000 South Korean won (approximately €562,600), for multiple breaches leading to the data leak of over one million individuals.
The case began following an internal investigation within the CNDE, conducted due to suspicions about the management of its digitization projects, which revealed the disappearance of storage media containing personal data.
Grounds for the decision
The authority found several violations of the Personal Information Protection Act:
- Data security obligation (equivalent to Article 32 of the GDPR): The CNDE failed to ensure data security by not implementing any adequate physical security measures for removable storage media (external hard drives, CDs) which were simply kept in cabinets or desk drawers. Moreover, national identification numbers stored on these media were not encrypted, making the data easily accessible in case of loss or theft.
- Obligation to supervise processing by a processor (equivalent to Article 28 of the GDPR): The authority found that the CNDE failed in its duty to supervise and control the processor responsible for digitizing the files. This negligence, notably in managing deliverables containing digitized data, directly contributed to the security breaches.
- Data breach notification obligation (equivalent to Article 33 of the GDPR): Although aware of the loss of a CD containing digitized data from 2013 to 2018 and an external hard drive containing data from 2020, the CNDE did not notify these breaches to the supervisory authority and the data subjects within the legal 72-hour deadline.
- Obligation to ensure security through access control: It was established that the CNDE shared access accounts to its system of its own employees with the processor's staff, constituting a violation of fundamental security measures regarding access management.
Authority's decision
Consequently, the authority imposed a fine of 832,700,000 South Korean won (approximately €562,600) on the National Center for Children's Rights.
Furthermore, the authority ordered the CNDE to take corrective measures, recommended disciplinary procedures against those responsible, and ordered the publication of the decision. A recommendation was also addressed to the Ministry of Health and Social Protection to improve its supervision of the CNDE.
Lessons learned
This decision reminds that:
- The management of removable storage media (USB keys, external hard drives, CDs) must be subject to a strict security policy, including an entry/exit register, designation of responsible persons, and secure physical storage conditions.
- Encryption of personal data, especially sensitive data or unique identifiers stored on removable or portable media, is an essential technical security measure.
- Supervision of a processor is not limited to signing a contract; it requires effective and regular control of its security practices, including management of access it has to the data controller's information systems.
- Sharing named access accounts between internal staff and external providers is a practice to be prohibited, as it destroys traceability of actions and constitutes a critical security flaw.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire