People Power Party lawmaker Cho Jung-hoon (조정훈) delivers opening remarks at a meeting with victims of the Tving personal data leak at the National Assembly Members' Office Building in Seoul on Sept. 17. [Photo: DigitalToday]

A call has emerged to change the current relief system that requires victims to apply directly for compensation after a large-scale personal data leak at the online video service (OTT) Tving. Participants also argued for institutional safeguards to prevent companies from collecting and storing personal data beyond what is necessary.

At a meeting with victims of the Tving personal data leak hosted by the office of People Power Party lawmaker Cho Jung-hoon (조정훈) at the National Assembly Members' Office Building in Yeouido, Seoul, on Sept. 17, speakers repeatedly pointed to the need to strengthen victim relief procedures and to bolster the responsibilities of companies and the government after data leak incidents.

A joint public-private investigation team under the Ministry of Science and ICT found that information from a total of 39.54 million accounts was leaked in a Tving breach that occurred in May. That total comprised 22.06 million active accounts, 17.37 million inactive accounts such as dormant or withdrawn accounts, and 110,000 test accounts. The figure includes many duplicates, including cases in which a single person held up to 13 accounts. Leaked items included a range of personal data such as subscribers' names, phone numbers, email addresses, dates of birth and payment histories. Some encrypted information was leaked together with encryption keys.

Victims who attended the meeting said the response process after the incident also placed an excessive burden on users.

They said that although information that users cannot change themselves was leaked, the company’s initial response measures focused on steps users could take, such as changing passwords. Linked information (CI), used to identify individuals and difficult for users to change at will, was cited as a representative example.

One attendee said, "I entrusted my personal data to the company, but applying for compensation and dealing with the aftermath also became the user’s responsibility," and argued that the principle should shift to a system in which compensation is provided even if victims do not submit separate applications.

Tving is accepting compensation applications through its website and app from Sept. 7 to Sept. 30. Members who have withdrawn must go through the sign-up process again to receive compensation. Compensation includes hacking and phishing insurance, Tving points, and content-related benefits.

The application period itself was also flagged as a problem. If victims learn late about the incident or compensation procedures, they could miss the chance to apply even if they are eligible. Compensation that presumes use of the service, such as points or content passes, was also criticised as not constituting meaningful compensation for victims who already left the service or no longer use it.

Some also said corporate practices of collecting personal data must be changed. Another attendee said, "Personal data has become an important asset for companies, to the extent that it is called 'the oil of the 21st century'," and added, "This incident should not be seen as a simple case of a few items such as a name or phone number being leaked."

"We also need to ask why an OTT platform needs to hold so much personal data," the attendee said, adding that a system is needed to prevent companies from continually amassing personal data on the grounds of business expansion and to require companies to explain why they need to collect information.

Consumer groups also said that the current damages compensation system alone makes it difficult for victims of personal data leaks to obtain meaningful relief.

Jo Yeon-haeng (조연행), head of the Korea Financial Consumers Federation, cited experience including work with the Personal Information Dispute Mediation Committee and pointed to the fact that compensation for actual personal data leak 피해 is not large. He said the structure that places the entire burden of proof on victims when a company managing personal data has an incident also needs to be fixed, and he called for strengthening relief measures such as punitive damages so victims can receive meaningful compensation.

Cho also said at the meeting that he plans to push for revisions to the Civil Act to recognise personal data as an individual’s "property". The idea is to approach personal data as an asset with economic value, similar to holding parties responsible for infringing property rights when they steal assets such as bank deposits or cars.

Cho also said he will actively address the Tving personal data leak issue during the upcoming parliamentary audit. He plans to call a Tving official as a witness and to closely question the Personal Information Protection Commission on response measures and institutional improvements for dealing with personal data leak incidents.

Keyword

#Tving #Ministry of Science and ICT #People Power Party #National Assembly #Personal Information Dispute Mediation Committee
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.