Customer Data Breaches: Small Businesses Are Not Exempt

OPUS 보안팀 · Privacy & Information Security Response ·

Key takeaway: Korea's Personal Information Protection Act (PIPA) applies to every data controller regardless of size — large corporations, SMEs, and sole proprietors alike. Once you become aware of a breach, you must notify affected individuals (your customers) within 72 hours. If the breach involves 1,000 or more people, sensitive or unique identifying information, or unauthorized external access such as hacking, you must also report it to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours.

It's easy to assume "we're a small shop, privacy law doesn't apply to us." But the moment you handle customer phone numbers, booking lists, or order details, the obligations attach regardless of your size.

It applies regardless of size

The Personal Information Protection Act doesn't ask how big you are. Large corporations, SMEs, sole proprietors, and micro-businesses alike are all "data controllers" carrying identical obligations.

72 hours after a breach — notification comes first

Once you learn that personal data has been exposed, you have 72 hours to inform the affected individuals (your customers) of what was exposed, when and how it happened, what they can do to limit harm, and where to reach you.

When you must also report it — PIPC and KISA

  • Personal data of 1,000 or more individuals was exposed
  • Sensitive information or unique identifiers (such as resident registration numbers) were exposed
  • The exposure resulted from unauthorized external access, such as hacking

How to reduce risk day to day

  • Collect only what you genuinely need, and destroy data once its retention period expires.
  • Minimize access privileges, and apply passwords and encryption.
  • When outsourcing to couriers, messaging platforms, and other third parties, review your privacy policy and vendor management.
  • Document your breach response procedure in advance — who notifies and reports what, when, and to whom.

What to take away

  • Keep: If you collect customer data, build a breach response procedure alongside it — Size is not a defense, and the notification deadline is 72 hours.
  • Promote: Use the security controls you've built as leverage in B2B proposals — The bigger the client, the more likely they'll ask about your data handling before signing.
  • Do now: Write down, on one page, who does what the moment a breach is discovered

Frequently asked questions

Does the Personal Information Protection Act apply to sole proprietors?

Yes. PIPA applies to every data controller that processes personal information, regardless of business size.

How soon must I notify after a data breach?

You must notify affected individuals within 72 hours of becoming aware of the breach.

When do I have to file a report?

If the breach affects 1,000 or more people, involves sensitive information or unique identifiers, or resulted from unauthorized external access, you must report it to the Personal Information Protection Commission or KISA within 72 hours.

More business columns that can help

OPUS