Small record cards show, in sequence, the location of data, external connections, and incident-response paths, while heavy pressure on one side opens a narrow passage toward better record-keeping.
AI and LLMsthrough Read It Backwards

Stronger Privacy Fines Open a Market for Small Record-Keeping Services

Stronger privacy penalties create room for small, repeatable tools that help even small businesses document where customer data goes, which vendors handle it, and how they respond to incidents.

Published 2026. 9. 12.

Responsibility changed before punishment did

From September 11, 2026, a system imposing heavier administrative fines for repeated or serious personal-data breaches took effect. It applies where a violation involving intent or gross negligence is repeated within three years, where wrongdoing at that level harms 10 million or more people, or where an incident occurs because a corrective order was not followed. Under the amended Personal Information Protection Act (개인정보 보호법), the statutory maximum is 10% of total revenue, and the Personal Information Protection Commission (개인정보보호위원회), Korea’s privacy regulator, can impose a fine within that limit.

This does not mean every breach automatically brings a fine equal to 10% of revenue. The general cap remains 3%, and even for serious violations, the actual amount is determined by considering unrelated revenue, the scale and circumstances of harm, and corrective efforts. For a company with KRW 10 billion in revenue, the maximum limit is KRW 1 billion; it does not mean the company must immediately pay KRW 1 billion.

On the same day, the responsibility of company representatives also became clearer. Business owners and representatives became ultimately responsible for providing the staff and budget needed to handle personal data safely. A personal information protection officer manages privacy specialists, secures a budget, and reports the state of privacy protection and major matters to the owner or representative and the board.

The requirement to have the board approve the appointment or replacement of a personal information protection officer and report it to the government mainly applies to large organizations. For private companies, the threshold is annual revenue above KRW 180 billion while handling sensitive information and similar data for at least 50,000 people, or handling personal data for at least 1 million people. That equals more than KRW 15 billion in average monthly revenue, far from the scale of a neighborhood shop.

Obligations already remain for smaller businesses. When they entrust customer-data processing to outside vendors for work such as reservations, delivery, or text messages, they must define the scope of work and protection measures in documents and supervise the vendor. Certain breaches must be reported within 72 hours of becoming aware of them. Breaches affecting 1,000 or more people, involving sensitive data or unique identification information, or caused by unlawful external access must be reported within 72 hours of discovery.

A small records box comes before an enterprise security suite

Consider the owner of an online side-dish shop with 12 employees. The shop downloads orders from its own online store and copies them into a delivery company’s form. Employees paste order numbers into a group chat to check missing orders, while a separate provider sends repeat-purchase text messages. Customer names, phone numbers, and addresses move through at least three places, yet the owner cannot explain the full path at once.

Vendor contracts are not in one place either. The online-store contract sits in a former employee’s email account. The owner only saw the text-message provider’s terms on screen while signing up. They do not know whether the website-management vendor uses another storage provider. If something goes wrong, the owner and staff first have to work out whom to call.

Stronger enforcement may make everyone think of an enterprise security system. But if it is wrong to assume that a small company must buy such a system to be safe, the center of this market becomes a tool that records routine work without omissions, not difficult monitoring features. A company without a technical employee needs a screen that can answer where customer data is today before it needs perfect controls.

In a new tool, the owner answers questions in sequence about the online store, delivery, text messages, email, and similar items. The tool then creates a one-page list of where customer data is received, transferred, and retained, which employee is responsible, and which outside vendors are involved. When the business starts using a new service, the tool asks only what changed from the existing list.

When a vendor contract is uploaded, the tool identifies whether it includes the scope of work, a ban on use beyond the purpose, protection measures, and terms on subcontracting. Missing items remain marked in red, and the responsible person gets short questions to send to the vendor. Its role is not to replace legal judgment, but to prevent people from forgetting what to ask.

When an incident is suspected, a separate screen opens. The user enters, in order, when it was first discovered, how many people may be affected, what types of information are involved, and whether there was an external intrusion. The tool then shows the 72-hour benchmark and the required actions. Everything from an employee’s first report to vendor responses and notices sent to customers is linked in the same incident record.

At the end of each month, the representative reviews changed vendors, unfinished checks, and incidents, then presses a confirmation button. Some work still belongs to people. Determining whether there was actually a breach, deciding whether reporting is required, explaining the situation to customers, and assigning responsibility with vendors must be handled by the responsible person or an expert.

Abroad, teams started small with records

The US digital publisher Gear Patrol (기어 패트롤) had between 11 and 50 employees and more than 5.5 million monthly readers, but no dedicated privacy team. Its growth strategy lead used Osano (오사노) to first organize website tracking consent and requests from customers to access or delete their own information.

Previously, each request took 15 to 20 minutes and interrupted the person handling it. After adoption, the company said it had a repeatable process that could be handed to other employees. The time figures come from a customer case study published by the service provider and are not independently verified results.

The German advertising agency Smarketer (스마케터) manages consent screens on websites for more than 1,000 clients. It began by using Consentmanager (콘센트매니저) to bring each client’s settings and records into one screen.

Smarketer said it reduced the time required to configure and manage one client account by four hours. The point to note is that a business can operate recurring work for many clients instead of selling a tool directly to every shop. This figure also comes from a provider-published case study.

Smart Pension (스마트 펜션), a UK workplace-pension operator, brought the locations of personal data, vendor assessments, and incident records that had been scattered across Excel files and documents into OneTrust (원트러스트). It began by making one list of where information flows, then expanded to procedures where employees conduct checks and report incidents themselves.

No time or cost savings were disclosed. Instead, the case shows an operating approach that keeps vendor checks and incident records in one place, preparing materials for submission to regulators in advance. The performance description is based on OneTrust’s customer case study.

Four things you can build now

1. Customer-data location ledger

What: A service that uses questions to identify the ordering, reservation, delivery, and text-message tools a shop uses, then creates a one-page personal-data list. Who: A food retailer with 12 employees that uses both its own online store and a delivery company.

Why now: The representative must be able to explain the location of customer data and who is responsible before vendor checks and incident response can begin. First screen: show 3 places receiving customer data · 4 places not yet checked and an Add new tool button.

2. Vendor-contract review box

What: A service that reads contracts, flags whether they cover the scope of personal-data processing, protection measures, and subcontracting, and drafts questions to send to vendors. Who: A small website agency that manages site production and text-message delivery for 20 online stores.

Why now: A business owner’s duty to supervise does not disappear because work was entrusted to a vendor, and the actual vendor list must also match the privacy policy. First screen: show an Upload contract button and unfinished items such as No protection measures · Subcontracting not confirmed.

3. 72-hour incident-response log

What: A service that records an employee’s first report, vendor contact, reporting review, and customer notice in chronological order. Who: A Pilates branch with six employees that stores members’ phone numbers and entry records.

Why now: A hacking incident or a sensitive-data breach may require reporting within 72 hours even at a small business, so it is too late to start finding contact details after an incident. First screen: include a field for Time incident was first discovered, remaining time, and three buttons: Block access · Contact vendor · Review reporting.

4. Monthly representative review box

What: A service where the representative reviews new customer data, changed vendors, and unfinished checks once a month, leaving a record. Who: A cosmetics manufacturer with 30 employees that supplies a large distributor and sometimes receives personal-data management questionnaires.

Why now: As the representative’s responsibility becomes clearer, it matters not only that they received a report, but which issues they reviewed and what instructions they gave. First screen: show 2 changes this month · 1 unreviewed item and a Representative review and record action button.

What to check in 30 minutes today

Call three businesses that take online orders or reservations. Without letting them prepare, ask them to name every place where customer data enters and every outside vendor involved. If at least two of the three cannot complete the list within 10 minutes, and say they would need to update it monthly after seeing the missing items, a customer-data location ledger is worth building first.

Why this matters where you are

Check whether small businesses in your market can quickly identify where customer data is received, transferred, and stored, as well as which vendors process it. Reporting rules and penalties may differ, but fragmented records, vendor oversight, and incident-response steps are operational problems that can be tested directly. Start by testing whether a simple recurring record is more useful than a large security system.

Sources

7 sources

Every fact in this article came from the pages below. Check them yourself.

Stronger Privacy Fines Open a Market for Small Record-Keeping Services | Prometheon