Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy & Compliance

South Korea Fines Google, Meta Over Privacy Violations

South Korea’s privacy watchdog has fined Google and Meta a combined 100 billion won ($72 million) for tracking consumers’ online behavior without their consent and using their data for targeted advertisements.

South Korea’s privacy watchdog has fined Google and Meta a combined 100 billion won ($72 million) for tracking consumers’ online behavior without their consent and using their data for targeted advertisements.

South Korea’s Personal Information and Protection Commission said it fined Google 69.2 billion won ($50 million) and Meta 30.8 billion won ($22 million) after a meeting where officials agreed that the companies’ business practices might cause “serious” privacy infringements.

The fines were the biggest ever penalties imposed by South Korea for privacy law violations, the commission said in a press release.

Both companies refuted the commission’s findings and Meta indicated it could challenge its fine in court. The fines can be appealed through administrative lawsuits, which must be filed within 90 days after the companies are formally notified of the commission’s decision.

According to the commission, Google and Meta, which operates Facebook and Instagram, didn’t clearly inform users or obtain their consent as they collected information about their online activities when they used other websites or services outside their own platforms. Such data was used to analyze their interests and create individually customized advertisements, the commission said.

The commission ordered the companies to provide an “easy and clear” process of consent giving people more control over whether to share information about what they do online.

“Google did not clearly inform consumers that it would collect and use their behavioral information about their use of other companies’ (services) when they signed up,” the commission said.

“Meta did not present the content of consent in way that could be easily seen by consumers when they signed up, and just included the content in their full data policy statement. It did not specifically inform consumers of the legally required notifications and did not obtain their consent.”

Advertisement. Scroll to continue reading.

The commission said the companies’ practices seriously threatened privacy rights as more than 82% of South Koreans using Google and more than 98% using Meta have let the companies track their online activities.

Google, a search and email giant that also operates the YouTube video platform, disagreed with the commission’s findings. It said in a statement that it has always demonstrated a commitment to “making ongoing updates that give users control and transparency.” The company said it will review the commission’s findings once it receives the fully written decision.

Meta said it will consider “all options,” including seeking a court ruling.

“We are confident that we work with our clients in a legally compliant way that meets the processes required by local regulations,” Meta said in an emailed statement.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...

Mobile & Wireless

As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for...

Cloud Security

AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...

Application Security

Security researchers at Google’s Project Zero have picked apart one of the most notorious in-the-wild iPhone exploits and found a never-before-seen hacking roadmap that...