TikTok fined $7 million in South Korea for illegal ad data collection

Share:
Audio Loading voice…
TikTok fined $7 million in South Korea for illegal ad data collection

Synopsis

South Korea's privacy regulator has fined TikTok $7 million for secretly harvesting behavioural data from 9.45 million users via third-party trackers to serve personalised ads — without telling them. The ruling lands weeks after a record $410 million fine on Coupang, signalling that Seoul is fast becoming one of Asia's most aggressive data protection enforcers, with direct implications for how global ad-tech platforms operate in the region.

Key Takeaways

South Korea's PIPC fined TikTok Pte.
10.3 billion won ($7 million) on 23 July for unlawful collection of behavioural data for personalised advertising.
TikTok harvested data from 9.45 million South Korean users via tools on third-party websites and apps, without adequate user notification.
Two Apple subsidiaries were fined a combined 252 million won for collecting Siri voice recordings and transcripts without consent until August 2019 .
Last month, the PIPC issued a record 624.7 billion won ($410 million) fine against Coupang Corp. over a data breach affecting more than 37 million users .
The Coupang breach was attributed to 'inadequate safety management' , not sophisticated hacking, according to PIPC chief Song Kyung-hee .

South Korea's Personal Information Protection Commission (PIPC) on Thursday, 23 July imposed a fine of 10.3 billion won ($7 million) on TikTok Pte. Ltd. — the Singapore-registered entity operating TikTok's services in South Korea — for unlawfully harvesting and deploying users' behavioural data to power personalised advertisements, in violation of the country's personal information law.

What TikTok Was Found to Have Done

According to the PIPC, TikTok collected behavioural data from 9.45 million South Korean users through tracking tools embedded in third-party websites and applications. This data was then used to target those users with personalised ads. Critically, the commission found that TikTok failed to adequately notify users that their data was being collected and used in this manner — a fundamental requirement under South Korean privacy law.

Apple Subsidiaries Also Penalised

In a separate action announced on the same day, the PIPC ordered corrective measures against two Apple Inc. subsidiaries and levied a combined fine of 252 million won for privacy violations linked to the company's Siri voice assistant. According to the watchdog, Apple collected voice recordings and text transcripts of Siri interactions without user consent until August 2019. While Apple began seeking consent for voice recordings from October 2019, it reportedly did not extend the same consent process to transcripts of those recordings.

Context: South Korea's Escalating Privacy Crackdown

The TikTok and Apple penalties come just weeks after the PIPC handed down its largest-ever fine — a record 624.7 billion won ($410 million) — against South Korean e-commerce giant Coupang Corp. That penalty comprised a 423.6 billion won sanction for a data breach affecting more than 37 million users, plus an additional 201.1 billion won for the unauthorised collection of users' online activity records and related violations.

Song Kyung-hee, the commission's chief, said at a briefing that the Coupang breach was not the result of sophisticated hacking but stemmed from the company's own 'inadequate safety management system.' Coupang expressed regret over the fine and said it plans to 'clarify the facts through legal procedures.'

Why These Cases Matter Beyond South Korea

This is part of a broader global pattern of regulators tightening scrutiny over how tech platforms — particularly those reliant on behavioural advertising — handle user data collected through third-party channels. TikTok, which has faced data-privacy probes across the European Union, the United States, and Australia, now faces a formal regulatory finding in one of Asia's most digitally active markets. Notably, the South Korean action targets the platform's advertising infrastructure specifically — not just data storage — which may set a precedent for how ad-tech practices are evaluated under national privacy frameworks.

What Happens Next

The PIPC has not publicly detailed whether TikTok or Apple have indicated plans to challenge the fines. Both companies are expected to implement corrective measures as directed. South Korea's string of high-profile privacy enforcement actions signals that the PIPC is positioning itself as one of the region's more assertive data protection regulators, with consequences that could influence how global platforms structure their consent mechanisms across Asia.

Point of View

Finding fault with how behavioural data flows from third-party trackers into ad personalisation systems. That is a meaningfully different regulatory theory from fines over data storage or breach notification failures. If other Asian regulators adopt the same framing, the cost of behavioural advertising infrastructure could rise sharply for platforms that have long treated cross-site tracking as a legal grey zone. The Coupang fine, meanwhile, suggests Seoul is willing to use scale: a $410 million penalty on a domestic champion sends a signal that national origin offers no protection. The PIPC is quietly becoming one of the region's most consequential data regulators.
NationPress
23 Jul 2026

Frequently Asked Questions

Why was TikTok fined by South Korea's privacy watchdog?
South Korea's Personal Information Protection Commission fined TikTok 10.3 billion won ($7 million) for collecting behavioural data from 9.45 million users through third-party website and app tracking tools, and using that data for personalised advertising without properly notifying users — a violation of South Korean personal information law.
Which TikTok entity was penalised?
The fine was levied on TikTok Pte. Ltd., the Singapore-registered company that operates TikTok's services in South Korea, rather than the platform's Chinese parent, ByteDance.
What did Apple do wrong, according to South Korean regulators?
Two Apple subsidiaries were fined a combined 252 million won for collecting Siri voice recordings and text transcripts of those recordings without user consent until August 2019. Apple began requesting consent for voice recordings in October 2019 but reportedly did not apply the same requirement to transcripts.
What was the record Coupang fine about?
South Korea's PIPC fined e-commerce firm Coupang Corp. a record 624.7 billion won ($410 million) last month — 423.6 billion won for a data breach affecting over 37 million users, and an additional 201.1 billion won for unauthorised collection of online activity records. The commission's chief said the breach resulted from inadequate internal safety management, not external hacking.
What does South Korea's privacy crackdown mean for global tech platforms?
South Korea's string of high-profile fines signals that the PIPC is emerging as one of Asia's most assertive data protection regulators. For global platforms, the TikTok ruling in particular — targeting ad-tech data flows specifically — could set a precedent for how behavioural advertising practices are assessed under national privacy frameworks across the region.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 5 months ago
  3. 7 months ago
  4. 1 year ago
  5. 1 year ago
  6. 1 year ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google