TikTok fined $7 million in South Korea for illegal ad data collection
Synopsis
Key Takeaways
South Korea's Personal Information Protection Commission (PIPC) on Thursday, 23 July imposed a fine of 10.3 billion won ($7 million) on TikTok Pte. Ltd. — the Singapore-registered entity operating TikTok's services in South Korea — for unlawfully harvesting and deploying users' behavioural data to power personalised advertisements, in violation of the country's personal information law.
What TikTok Was Found to Have Done
According to the PIPC, TikTok collected behavioural data from 9.45 million South Korean users through tracking tools embedded in third-party websites and applications. This data was then used to target those users with personalised ads. Critically, the commission found that TikTok failed to adequately notify users that their data was being collected and used in this manner — a fundamental requirement under South Korean privacy law.
Apple Subsidiaries Also Penalised
In a separate action announced on the same day, the PIPC ordered corrective measures against two Apple Inc. subsidiaries and levied a combined fine of 252 million won for privacy violations linked to the company's Siri voice assistant. According to the watchdog, Apple collected voice recordings and text transcripts of Siri interactions without user consent until August 2019. While Apple began seeking consent for voice recordings from October 2019, it reportedly did not extend the same consent process to transcripts of those recordings.
Context: South Korea's Escalating Privacy Crackdown
The TikTok and Apple penalties come just weeks after the PIPC handed down its largest-ever fine — a record 624.7 billion won ($410 million) — against South Korean e-commerce giant Coupang Corp. That penalty comprised a 423.6 billion won sanction for a data breach affecting more than 37 million users, plus an additional 201.1 billion won for the unauthorised collection of users' online activity records and related violations.
Song Kyung-hee, the commission's chief, said at a briefing that the Coupang breach was not the result of sophisticated hacking but stemmed from the company's own 'inadequate safety management system.' Coupang expressed regret over the fine and said it plans to 'clarify the facts through legal procedures.'
Why These Cases Matter Beyond South Korea
This is part of a broader global pattern of regulators tightening scrutiny over how tech platforms — particularly those reliant on behavioural advertising — handle user data collected through third-party channels. TikTok, which has faced data-privacy probes across the European Union, the United States, and Australia, now faces a formal regulatory finding in one of Asia's most digitally active markets. Notably, the South Korean action targets the platform's advertising infrastructure specifically — not just data storage — which may set a precedent for how ad-tech practices are evaluated under national privacy frameworks.
What Happens Next
The PIPC has not publicly detailed whether TikTok or Apple have indicated plans to challenge the fines. Both companies are expected to implement corrective measures as directed. South Korea's string of high-profile privacy enforcement actions signals that the PIPC is positioning itself as one of the region's more assertive data protection regulators, with consequences that could influence how global platforms structure their consent mechanisms across Asia.