Seoul: The Science, ICT, Broadcasting and Communications Committee of the National Assembly is set to conduct a hearing on Coupang's significant data breach next Wednesday, focusing on the massive leak of customer personal information. Key witnesses summoned include Coupang founder and de facto owner, Bom Kim, former CEO Park Dae-jun, and Kang Han-seung, head of North American operations at the e-commerce giant. However, there remains uncertainty over Kim's attendance, as he has previously cited his presence abroad to avoid such appearances.
According to Yonhap News Agency, Park, who resigned as Coupang Corp. CEO last Wednesday, stated during a recent National Assembly inquiry that the company's business in Korea is his responsibility, distancing Kim from the incident. Park's claim of not knowing Kim's whereabouts in the US has been met with skepticism, especially given the severe implications for the 33.7 million Coupang members affected by the data breach. Despite Coupang's substantial operations in Korea, Kim has remained silent and out of sight, while holding over 73 percent voting rights in Coupang Inc., the parent company.
Kim's journey from Seoul to the US, where he later gained citizenship and founded Coupang in 2010, adds complexity to the scenario. His resignation from board positions in 2021, post a logistics center fire, had previously raised eyebrows, with critics suggesting it was a move to sidestep accountability under the then-impending Serious Accidents Punishment Act. This history underlines the need for Kim's accountability, especially as he continues to wield significant influence over Coupang's strategic decisions.
The data breach incident not only underscores technical lapses but also points to governance and accountability challenges within Coupang's structure. Given the scale of personal data compromised, the minimum expectation is for the business owner to directly address the situation and outline preventive measures. The upcoming hearing is pivotal for establishing facts and exploring solutions to avoid future breaches.
In response to the breach, Coupang is facing collective legal actions demanding compensation, with around 200,000 individuals reportedly filing lawsuits. However, the potential compensation of approximately 100,000 won ($68) per victim falls short of meaningful restitution. This highlights the limitations of current damage lawsuits in compelling corporate accountability for data leaks.
While Korea has introduced class-action suits in securities, their application is limited due to procedural complexities and restricted scope. Conversely, in the US, victims could potentially access internal Coupang data through the discovery process, which is not feasible under Korean law. A New York-based Korean law firm, Daeryun, is reportedly preparing a class-action suit seeking punitive damages, reflecting victims' anticipation of securing critical data through US legal channels.
The Coupang data breach has accentuated the need for Korea to enhance its class-action legal framework, making it more robust and effective in safeguarding consumer rights.