Skip to menu Skip to content

Korean e-government homepage mark This site is the official e-Government website of the Republic of Korea.

zoom
100%

Notice / Press Release

Notice Detail
Title PIPC Sanctions Twelve General Insurance Companies for Non-Compliance with PIPA
Department Date 2024.12.13
Attachment press release PIPC Sanctions Twelve General Insurance Companies for Non-Compliance with PIPA.pdf
Page URL https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2744
Contents

Press Release

PIPC Sanctions Twelve General Insurance Companies for Non-Compliance with PIPA 

- PIPC imposes around KRW 9.208 billion on four general insurance companies for using personal information without gaining lawful consent from data subjects for marketing purposes 

- Correction orders issued to enhance the roles of CPOs due to their failures to carry out internal data privacy controls in an appropriate manner 

- Correction orders issued not to retain personal information of those who only used an insurance premium calculator on all twelve insurance businesses

 

December 12, 2024

(This is an unofficial translation of a press release, originally prepared in Korean.) 

 

The Personal Information Protection Commission (PIPC) held its 21st plenary meeting and resolved to impose sanctions on twelve general insurance companies for their failures to comply with the Personal Information Protection Act (PIPA) on December 11, 2024. The aforementioned insurance companies subject to the sanctions are Hyundai Marine & Fire Insurance Co., Ltd.; AXA General Insurance Co., Ltd.; Hana Insurance; MG Non-Life Insurance; Lotte Insurance Co., Ltd.; Samsung Fire & Marine Insurance Co., Ltd.; DB Insurance Co., Ltd.; KB Insurance; Meritz Fire & Marine Insurance Co, Ltd.; Hanwha General Insurance Co., Ltd.; Heungkuk Fire & Marine Insurance Co., Ltd.; and Carrot General Insurance Co., Ltd.

 

1. What’s behind the Investigations and Results of the Plenary Meeting

 

The PIPC started launching investigations into car insurance companies in August 2023 as the media outlets covered that car insurance companies unduly required personal data from customers while there were growing concerns over privacy infringements of data subjects.

 

As a result, the PIPC reached a resolution to impose penalty surcharges of around KRW 9.208 billion on four insurance companies, including Hyundai Marine & Fire Insurance, AXA General Insurance, Hana Insurance, and MG Non-Life Insurance, for the collection and use of personal data without gaining lawful consent to pursue their marketing strategies. The data protection supervisory authority also issued correction orders on them to enhance the roles of Chief Privacy Officers (CPOs) for internal data privacy controls.

 

The PIPC found that all twelve insurance businesses failed to destruct the personal information of those who stopped calculating their insurance premiums or buying an insurance policy for a year. In this regard, the PIPC issued correction orders on them to make improvements in their practice for the retention periods. Among them, Lotte Insurance Co., Ltd was fined KRW 5.4 million for its failure to destruct personal information of users for more than a year.

 

2. Violation Details

 

Collection and Use of Personal Information without Lawful Consent to Achieve Marketing Goals

 

The aforementioned four insurance companies used a pop-up window to lure users who opted out of giving consent to viewing insurance products to change their option (hereinafter, “nudge pop-up”), but this type of consent was not considered freely given because of ambiguity in expressions and affected the data subjects’ rights to self-determination.

 

In particular, they used nudge pop-ups as a marketing gimmick to gain consent to the collection and use of personal information but did not contain any expressions about ‘personal data processing’ or legal notifications. This gimmick left behind the users from the knowledge that it was intended to process their personal information for marketing purposes.

 

Nudge pop-ups misled the data subjects to give consent to personal data processing for marketing purposes by switching the effect of the buttons. Clicking on the button “Yes” did not allow the data subjects to check their consent status, and other businesses modeled after this practice to achieve their marketing goals.

 

During the period the four insurance businesses used this gimmick, their consent rate for marketing soared by up to 30 percentage points (from 31.42% to 61.71%).

 

They used the personal information for marketing campaigns not only in car insurance but also in driver, health, and dental insurance products. It turned out they made numerous marketing calls, including text messages, and phone calls. The number of marketing calls only for car insurance amounted to 30 million. As a result, a fair amount of spam reports associated with this marketing gimmick were identified during the period. 

 

Given that insurance companies run marketing campaigns to give out vouchers or coupons ranging from KRW 5,000 to KRW 10,000 in return for giving consent to viewing insurance products while using an insurance premium calculator in general, the insurance companies seemed to earn a significant amount of cost reduction benefits. 

 

For consent to be lawful under the PIPA: 

● Data subjects are well aware of the fact that their personal information is processed by personal data processors; and 

● They make informed decisions on personal data processing and the scope of consent.

 

However, the four sanctioned insurance companies used vague expressions for the collection and use of personal data from users and made legally required notifications out of reach, resulting in users being unaware of whether their personal data was processed.

 

Insufficient Internal Data Privacy Control Roles of CPOs

 

The PIPC’s investigations found out that CPOs supposed to be tasked with controlling over data privacy issues failed to fulfill their duties, such as reviewing the consent procedures for this marketing gimmick established by their marketing departments.

 

The PIPA stipulates that implementing an internal control system is one of the duties of a CPO and consent is a key to processing personal data. However, designing the system without reviews and oversight of CPOs means that they lacked the independence to carry out the duties. Considering the circumstances unfolded, the PIPC issued correction orders on the four insurance companies to make sure CPOs have empowerment and independently carry out their tasks for internal data privacy control procedures. 

 

Failures to Destruct Personal Information after Achieving Initial Purposes

 

The general insurance companies under investigations provide an insurance premium calculator to sell their products. To use this service, users are required to provide their names, resident registration numbers (RRNs), and phone numbers to them. However, even if the users ended up not dealing with them, their personal information was retained for a year. Under the PIPA, personal data processors shall destruct the personal information without undue delay once the initial purpose of the collection and use is achieved.

 

However, the insurance businesses came up with plans to remedy their non-compliance with the retention periods in consultation with the General Insurance Association of Korea and submit the plans to the PIPC. As the insurance companies will remedy their practice from the beginning of 2025, the data protection supervisory authority issued correction orders on them accordingly. Among them, however, Lotte Insurance was fined KRW 5.4 million for not destructing personal information of 320,000 users more than a year, a valid consent time frame.

 

3. Lessons Learned from the Investigations and Administrative Sanctions

 

The PIPC’s investigations and sanctions against car insurance companies speak volumes of the importance of safeguarding the data subjects’ rights associated with what needs to be done for consent to be valid. Also, the data protection supervisory authority clearly stresses that CPOs should play their roles in implementing safeguards against data breaches as well as designing an internal data privacy control system for the lawful processing of personal data.

 

Moreover, the sanctions hold significance that the PIPC reemphasizes that the personal data processing in the financial service sector should be in compliance with the PIPA when the information does not fall under the purview of the Credit Information Use and Protection Act. 

 

* A PDF file, formatted for better readability, is attached.

Previous
PIPC to Newly Launch Nationally Accredited Qualification Scheme for CCTV Operators in Public and Private Sectors
Next
PIPC Unveils AI Privacy Risk Management Model to Usher in an Era of Trustworthy AI