Seoul: The data protection regulator said Wednesday that e-commerce giant Coupang Inc. did not properly notify its customers of its recent major data breach, demanding a corrected notification of a personal information "leak" from an "exposure" of such data.
According to Yonhap News Agency, the Personal Information Protection Commission (PIPC) made the decision in an emergency meeting after the company said last week personal information of 33.7 million customers had been compromised, including names, addresses, and phone numbers.
While Coupang notified affected users of the breach, the PIPC said the company merely described it as personal information being exposed when it was aware that such data had been leaked. The regulator said Coupang also partially omitted types of data affected while announcing the breach on its website for just one to two days.
The PIPC ordered the company to notify affected customers again of the leak, advise them of data protection measures, such as changing passwords, and reinspect steps to prevent harm to customers, among other measures. It demanded Coupang submit the results of its measures within one week.
"(We) will swiftly and thoroughly investigate the circumstances, scope and items of Coupang's personal information leak, as well as violations of safety duties, and will make strict punishment if violations are found," it said in a release. Meanwhile, the regulator said it strengthened the monitoring of illegal distribution of personal information on the internet and the dark web Sunday, which will last for three months.