Korea raises data breach fines to 10% of revenue
South Korea's privacy regulator will impose fines up to 10% of revenue for data breaches leaking personal data of 10 million or more people.
South Korea's privacy regulator is sharply raising penalties for data breaches, with fines reaching 10% of a company's revenue. The higher fines take effect Friday for companies found to have leaked personal data of 10 million or more people through intent or gross negligence. The regulator aims to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.
Delaware Consumer Privacy and Data-Breach Law Updates
Delaware's governor signed HB 380 and HB 381 amending the state privacy act and breach notification law.
On September 2, 2026, Delaware's Governor signed House Bill 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), enacted in 2023 and effective January 1, 2025. HB 381 separately amends Delaware's computer security breach notification law. Joseph J. Lazzarotti of JacksonLewis summarizes the changes.
FTC rescinds policy requiring health apps to notify customers after a breach
The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.
The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.