South Korea’s Personal Information Protection Commission has fined KT Corporation KRW 53.979 billion, or about $39 million, over data protection violations linked to a customer data breach. The action puts one of the country’s biggest telecommunications companies under renewed scrutiny over how customer information was handled.

According to the regulator’s announcement, the penalty relates to failures tied to personal data protection. While the available report does not include the full findings, the case centers on customer information and the company’s responsibility to safeguard that data under South Korea’s privacy rules.

The KT data breach fine stands out as a major enforcement move by the PIPC, underscoring the pressure on telecom providers to maintain stronger security and compliance practices. For a large carrier that manages significant amounts of user information, regulatory action of this size can carry both financial and reputational consequences.

The case also reflects a broader focus in South Korea on personal data protection and corporate accountability after security incidents. As regulators continue to examine how companies collect, store and protect customer records, the KT penalty is likely to remain a closely watched example in the telecom and privacy sectors.