WorldNews

Coupang challenges record South Korean privacy fines in two court cases

The company is seeking to overturn penalties totaling 624.681 billion won and has separately asked a Seoul court to pause their effect. The court has not been reported to have granted a stay.

Seoul city skyline viewed from Namsan, with buildings including Jongno Tower and Changdeokgung in view.
Context photograph: a view across central Seoul from Namsan, taken May 1, 2016. Flickr - Laurie Nevay https://www.flickr.com/photos/laurienevay/ (resized and converted to WebP). CC BY-SA 2.0.
LinkedInPostEmail
Save for later

Coupang filed two lawsuits at the Seoul Administrative Court on October 7 challenging South Korean privacy penalties totaling 624.681 billion won, according to Seoul Economic Daily and CHOSUNBIZ. The company also applied to pause the penalties while the cases proceed. The challenges put the regulator’s findings about a large data breach and the collection of users’ online activity before the court; the filings themselves do not suspend the sanctions.

The two cases target separate decisions by the Personal Information Protection Commission, or PIPC. One penalty, 423.575 billion won, concerns data-security obligations connected to the breach. The other, 201.106 billion won, concerns the collection of records of users’ activity on other websites and apps. The commission resolved to impose both penalties at a June 10 meeting, according to its published account.

What Coupang has asked the Seoul court to do

Seoul Economic Daily and CHOSUNBIZ each reported the two October 7 lawsuits, citing legal sources for the filings. Both also reported applications to stay the effect of the penalties. The retrieved reporting does not include the court pleadings or a docket entry, and it does not establish that a judge has ruled on either stay application.

A lawsuit seeking to overturn an administrative decision does not automatically halt that decision, CHOSUNBIZ reported in its account of the applicable procedure. The court can consider a separate stay application under statutory conditions, including urgency and a risk of irreparable harm. Whether those conditions are met in Coupang’s cases remains for the court to decide.

What the privacy regulator found about the breach

The PIPC said its investigation found that the breach affected about 33.22 million Coupang users. It also identified exposed shipping information relating to about 4.33 million third parties, including names, phone numbers, addresses and order details. Those are the regulator’s findings, now being challenged through the company’s court actions, rather than findings made by a court in the new cases.

In its English notice, the commission attributed the breach to inadequate safeguards and security management. It identified problems involving authentication signing keys and responses to unusual traffic. The PIPC said a former employee who had accessed signing keys during employment used forged backup authentication tokens to reach internal systems from April through November 2025. The commission said Coupang reported the breach on November 20, 2025.

The regulator also said Coupang became aware on January 30, 2026, of a leak affecting about 160,000 users through its Delivery Address List Page, but did not notify authorities within the 72 hours required by the Personal Information Protection Act. It said Coupang manually deleted web access logs from July through November 2024 after being ordered to preserve evidence. According to the PIPC, the missing logs impeded its inquiry into when the breach began and how far it extended.

Why there are two penalties

The second major penalty addresses conduct distinct from the data breach. The PIPC said Coupang collected online behavioral data from about 11.17 million users, including approximately 15.645 million webpage access logs, without the required consent or notice. The records included visited URLs, access times, IP addresses and device identifiers, according to the commission. This finding explains why the overall 624.681 billion won sanction comprises two large amounts, rather than a single breach fine.

The commission’s June decision included other measures beyond those two penalties. Its release describes a 16.8 million won fine and correction orders covering breach notifications, key management, access controls and privacy governance. It says Coupang Fulfillment Services, the company’s logistics subsidiary, separately received a 248 million won penalty. The current reports identify the two larger Coupang penalties as the targets of the October court challenges.

Coupang’s response and the unresolved court questions

Seoul Economic Daily reported that, when the penalties were announced, Coupang said it regretted that its efforts to prevent secondary harm and its explanation of the facts had not been sufficiently reflected in the decision. The company said it expected the facts to be established through legal proceedings. CHOSUNBIZ reported that the PIPC had said it would respond actively if Coupang sued.

The immediate procedural question is whether the Seoul Administrative Court will grant either requested stay. The wider question is whether it will uphold or overturn the regulator’s decisions after considering the challenges. The available reporting establishes the applications and the regulator’s stated reasons for its penalties, but gives no ruling or timetable for either case. Until the court decides, the PIPC’s findings and Coupang’s objections should be read as opposing positions in an unresolved dispute.

Sources and context

AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.

About NewsJaws Desk

AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.