Customer Data Breaches: Small Businesses Are Not Exempt
OPUS 보안팀 · Privacy & Information Security Response ·
Key takeaway: Korea's Personal Information Protection Act (PIPA) applies to every data controller regardless of size — large corporations, SMEs, and sole proprietors alike. Once you become aware of a breach, you must notify affected individuals (your customers) within 72 hours. If the breach involves 1,000 or more people, sensitive or unique identifying information, or unauthorized external access such as hacking, you must also report it to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours.
It's easy to assume "we're a small shop, privacy law doesn't apply to us." But the moment you handle customer phone numbers, booking lists, or order details, the obligations attach regardless of your size.
It applies regardless of size
The Personal Information Protection Act doesn't ask how big you are. Large corporations, SMEs, sole proprietors, and micro-businesses alike are all "data controllers" carrying identical obligations.
72 hours after a breach — notification comes first
Once you learn that personal data has been exposed, you have 72 hours to inform the affected individuals (your customers) of what was exposed, when and how it happened, what they can do to limit harm, and where to reach you.
When you must also report it — PIPC and KISA
- Personal data of 1,000 or more individuals was exposed
- Sensitive information or unique identifiers (such as resident registration numbers) were exposed
- The exposure resulted from unauthorized external access, such as hacking
How to reduce risk day to day
- Collect only what you genuinely need, and destroy data once its retention period expires.
- Minimize access privileges, and apply passwords and encryption.
- When outsourcing to couriers, messaging platforms, and other third parties, review your privacy policy and vendor management.
- Document your breach response procedure in advance — who notifies and reports what, when, and to whom.
What to take away
- Keep: If you collect customer data, build a breach response procedure alongside it — Size is not a defense, and the notification deadline is 72 hours.
- Promote: Use the security controls you've built as leverage in B2B proposals — The bigger the client, the more likely they'll ask about your data handling before signing.
- Do now: Write down, on one page, who does what the moment a breach is discovered
Frequently asked questions
Does the Personal Information Protection Act apply to sole proprietors?
Yes. PIPA applies to every data controller that processes personal information, regardless of business size.
How soon must I notify after a data breach?
You must notify affected individuals within 72 hours of becoming aware of the breach.
When do I have to file a report?
If the breach affects 1,000 or more people, involves sensitive information or unique identifiers, or resulted from unauthorized external access, you must report it to the Personal Information Protection Commission or KISA within 72 hours.
More business columns that can help
- Why AI Never Cites Your "Well-Written" Posts
- The 5 Factors That Drive AI Citation — What Controlled Experiments Found
- Asking "Just Any AI" vs. Handing It to a Blog Agent
- How Advertising Evolves — What the World Cup Reveals About Ad Technology, and the Startups Behind It
- When a Single Review Becomes an Ad — How to Actually Put Reviews to Work
- Buying Back a Doctor's Time — How Abridge Took Over the Hospital Market
- The Company That Reached Nasdaq Selling "We'll Erase Your Past" — A Full Breakdown of LegalZoom's Business Model
- Korea's Amended Network Act Took Effect July 7 — How Remedies Changed for Victims of Defamation and False Posts
- The People Who Built Airbnb and Stripe Just Named 7 Things They Want to Fund
- 5 Checks Before You File a Trademark Yourself — "Submitted" Is Not "Registered"
- A Tour of Defamation Case Law — How Far Can an Online Review Go Before It Is a Crime?
- What Happens When Someone Else Registers Your Brand Name First — A Survival Guide to First-to-File
- Giving Employees Equity: What Founders Must Lock Down — Stock Option Vesting vs. Shareholders' Agreements
- Five Minutes Before You Sign: A 7-Point Toxic Clause Checklist
- The Money Quietly Leaking Out of Your Taxes as Sales Grow — 3 Things Online Sellers Miss
