Key developments
Coupang Receives Record South Korean Privacy Fine
Platform Economy Insights reported that South Korea’s Personal Information Protection Commission imposed a record 624.7 billion won, or about $410 million, fine on Coupang. The regulator attributed 423.5 billion won to data-protection violations tied to a breach affecting 37.6 million people and 201.1 billion won to other unauthorized data-collection practices. PIPC said a former Chinese software developer retained an authentication key after leaving and used it for about a year to access names, phone numbers, and residential building entry codes; Coupang said no financial or government ID data was compromised and plans to appeal.
Why it matters
The penalty materially raises enforcement risk for large platforms handling customer data in South Korea and signals tougher treatment of access-control failures.
Sources & driving stories
PLATFORM ECONOMY INSIGHTS
Platform Economy Insights coverageATF Drops Warrantless Ad-Tech Location Pilot
WSLS reported that the Bureau of Alcohol, Tobacco, Firearms and Explosives canceled its Webloc contract after Rep. Michael Cloud and Sen. Ron Wyden raised legality and privacy concerns. The tool, sold by Penlink and sourced from consumer apps and advertising networks, allowed mobile-device location searches using commercial ad-tech data; lawmakers said ATF ran more than 300 warrantless searches, including more than 200 tied to active cases. CyberScoop also reported that ATF Director Robert Cekada told Congress the agency had purchased geolocation data and had not established policies for criminal-investigation use.
Why it matters
The cancellation is a concrete pullback from government purchases of commercial location data while FBI and DHS use of similar data remains unresolved.
Sources & driving stories
WSLS
Wsls coverageCYBERSCOOP
CyberScoop coverageKDDI Breach Exposes Millions of Email Logins
BleepingComputer’s Bill Toulas reported that Japanese telecom operator KDDI disclosed a breach of an email system used by five other internet service providers. KDDI discovered the compromise on June 17 and said attackers exploited a vulnerability in unnamed third-party software, potentially exposing email addresses and passwords for up to 14.22 million current, former, and inactive accounts. KDDI notified Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications and advised password resets and two-factor authentication.
Why it matters
The incident combines third-party software exposure with credential risk across multiple ISPs, though KDDI has not disclosed how many passwords were plaintext versus hashed or encrypted.
Sources & driving stories
BLEEPINGCOMPUTER · Bill Toulas
BleepingComputer coverageWorth noting
WORTH NOTING
Meta smart-glasses facial recognition code found
The Eastern Herald reported that EFF researchers found dormant NameTag facial-recognition code in the Meta AI app, including real-time faceprint matching when enabled in debug mode, before Meta reportedly removed the code update on June 5.
WORTH NOTING
KIDS Act age-check pressure grows
Techdirt reported that Congress is preparing to vote within the next week on a package whose “knows or should have known” standards could push platforms toward age verification, document checks, facial age estimation, and new controls on private messaging.
WORTH NOTING
EDPB breach template enters consultation
Pearl Cohen’s Nicole Levy reported that the European Data Protection Board adopted a common GDPR Article 33 breach-notification template, with public consultation open until August 5, 2026.
Still unclear
OPEN QUESTION
Will ATF’s pullback spread to other agencies?
The reported cancellation leaves open whether FBI, DHS, military, immigration, and local law-enforcement uses of commercial geolocation data will face comparable policy limits or judicial-order requirements.
OPEN QUESTION
Can age-safety bills avoid privacy-invasive verification?
The KIDS Act coverage suggests child-protection obligations may create incentives for platforms to collect sensitive identity, biometric, or behavioral data from adults and minors alike.
