South Korea's Personal Information Protection Commission (PIPC), the country's primary data protection authority, fined TikTok 10.3 billion won, roughly $7 million, on 23 July for collecting and monetising the behavioural data of 9.45 million South Korean users without lawful consent. The regulator also issued corrective orders and required TikTok to publicly disclose the findings, a reputational measure increasingly used by Seoul against large platforms.
The mechanics of the violation centred on a suite of free tracking tools that TikTok distributes to businesses: TikTok Pixel, Events SDK and Events API. These are small pieces of software that companies embed in their websites or apps to measure ad performance. According to the Korea JoongAng Daily, about 71,000 South Korean businesses had installed these tools, which quietly recorded user actions including clicks, searches, purchases, downloads and content views. TikTok then linked that activity to individual device identifiers and TikTok accounts to build interest profiles and serve personalised advertisements.
Consent bundled away
The PIPC's central objection was not only that data was collected, but how consent was obtained. The commission found that TikTok folded agreement to third-party behavioural tracking into the standard terms users must accept to open an account at all. As the Korea JoongAng Daily reported, the regulator concluded that TikTok "bundled consent for personalized advertising with consent required to use the [app's] service," leaving users no practical way to opt out without abandoning the platform entirely. South Korea's Personal Information Protection Act requires that consent for each distinct purpose of data use be obtained separately and clearly.
“At TikTok, protecting our users' privacy and ensuring the security of their information are among our highest priorities. We are committed to complying with all applicable laws and regulations in Korea.”
A secondary violation involved data transfers. TikTok Lite, a stripped-down version of the app that rewards users with cash-equivalent incentives for watching videos and recruiting friends, transferred personal data to an overseas affiliate via its points cash-out feature. The commission found the company failed to specify which categories of data were being sent abroad, the purpose of those transfers, or how long the data would be retained, breaching Article 28-8 of the Personal Information Protection Act.
Part of a sharper regulatory pattern
Thursday's fine is not an isolated event. South Korea's PIPC has been systematically expanding its scrutiny of global technology firms. In June 2026, the commission imposed a record 624.7 billion won fine, roughly $409 million, on domestic e-commerce leader Coupang over a data breach and a separate data-collection violation. The regulator has also previously fined Meta approximately 21.6 billion won for harvesting the data of around 980,000 Facebook users and passing it to advertisers.
The enforcement comes as South Korea's National Assembly has already legislated stiffer future penalties. Amendments passed in February 2026 introduce a higher penalty tier of up to 10 percent of a company's total revenue for serious violations, up from an existing ceiling of 3 percent of revenue linked to the specific breach. That change is due to take effect on 11 September 2026, meaning future cases against large platforms could carry dramatically larger consequences.
A global picture
“South Korea's action against TikTok reflects a broader global trend: regulators are tightening control over how tech companies handle user data.”
South Korea's action adds to a growing international record against TikTok. The European Union's Irish Data Protection Commission separately fined TikTok 530 million euros in 2025 over transfers of European user data to China, though that case involved different legal provisions and conduct. The PIPC's Seoul fine is calculated differently, based on the revenue TikTok generated from personalised advertising that relied on the unlawfully collected data. As digital advertising models increasingly depend on cross-platform behavioural tracking, regulators across Asia, Europe and beyond are signalling that shadow data collection, the kind users never see and never truly agree to, carries a growing legal cost.
This article is free to read. It always will be — no paywall, no account, no tracking.




