The Korea Personal Information Protection Commission (PIPC) fined the encryption exchange Bithumb a fine of 21 million won because the platform shared personal information without the full consent of the user when processing transfers with the overseas exchange. Regulators are also required to refine cross-border data transfer processes and to issue new privacy guidelines for block chain enterprises.

13 overseas exchanges involved

PIPC found that Bithumb had provided information on names, wallet addresses and date of birth to offshore platforms while assisting users with transfers with 13 overseas encryption exchanges, but had not been fully authorized under the Korean Personal Information Protection Act.

Regulators have indicated that the cross-border transmission of personal information is directly related to the control of users over their own data and therefore needs to meet stricter statutory requirements for consent procedures and protection measures.

  • Amount of fine: 210 million won
  • Approximate amount: $136,000
  • Target audience: 13 overseas encryption exchanges

Regulatory requirements to modify the transfer process

In addition to the fine, the PIPC requires Bithumb to enhance procedures for the cross-border transmission of personal information in order to comply with the privacy protections in place in Korea. This treatment shows that the Korean regulatory authorities are placing the issue of encryption platform data compliance in a more detailed enforcement context.

For exchanges, cross-border transfers, cooperative clearing and interface with external platforms often involve the flow of user identification information. This statement by the regulator means that the process needs to be more clearly agreed to by the users in the future and to keep a record of compliance.

Zone Chain Enterprises have received new privacy guidelines.

In conjunction with the publication of the decision on penalties, PIPC has also issued guidelines on privacy protection for block-chain enterprises. It was mentioned that the block chains are transparent, decentrized and non-removable, so that enterprises should not directly include identifying information.

Sensitive information named by the regulator includes identification data such as names and social security numbers. For block-chain projects and service providers, this means that there is a need to further isolate personal information from open books when designing the chain for storage.