Seoul: South Korea's privacy regulator on Wednesday ordered Coupang Inc. to revise its liability exemption clause for data breaches and simplify its membership cancellation process.
According to Yonhap News Agency, the Personal Information Protection Commission (PIPC) issued the instruction after reviewing the company's terms of service, membership policy, and follow-up measures in the wake of its massive data leak. Last month, Coupang revealed that personal information of 33.7 million customers had been compromised, indicating that data such as names, phone numbers, email addresses, and delivery details for nearly all members was affected.
The commission noted that Coupang added a new clause to its terms of use in November, stating that it is not liable for damages caused by illegal third-party access to its servers. The commission pointed out that this provision contradicts the Personal Information Protection Act by making the company's liability for intentional or negligent damages unclear.
Furthermore, the agency highlighted that Coupang had made its account deletion procedure deliberately complex, preventing users from canceling paid memberships until the expiration date. The PIPC also instructed Coupang to operate a designated task force to address possible secondary damage to users following the breach.