中文版:/zh/decisions/aliexpress-2024/
Key points. On 24 July 2024 the Personal Information Protection Commission ("PIPC") imposed a penalty surcharge of KRW 1,978,000,000 and an administrative fine of KRW 7,800,000 on Alibaba.com Singapore E-Commerce Private Limited ("AliExpress"), and issued corrective orders and improvement recommendations (decision No. 2024-013-192). The surcharge rests on PIPA art. 28-8(1): users ticked a "consent to overseas transfer (required)" box at sign-up, but the Commission found no record that they were told at the point of purchase which country and which seller would receive their data. The Commission held that consent given without the country, the recipient and the recipient’s contact details was not consent. The fine rests on art. 28-8(4), because the seller terms carried none of the required protective measures. In the surcharge calculation the Commission added 50% for a violation lasting more than two years, added 20% for failing to submit total turnover data, and took off 30% for correcting the violation before the prior-notice comment period ended.
This note takes the four violations one at a time. For each it sets out the facts, the Commission’s finding and, where the respondent contested the point, the Commission’s answer. It then turns to the calculation of the surcharge and the fine.
The published decision text redacts the respondent’s name. The Commission named the respondent in its press release of 25 July 2024, which refers to it as "AliExpress", and this note follows that usage. The decision also redacts other names and figures, including the domestic representative, the number of sellers who received data in a given period, and every intermediate amount in the surcharge calculation. They are not supplied here. English renderings of the Korean text are ours.
What was decided
The Commission adopted the decision on 24 July 2024 at its 13th plenary meeting, according to the press release.
The decision describes the respondent as a personal information controller that has provided an e-commerce service to Korean users since July 2016. The Commission opened the investigation because of concerns about personal data in fast-growing cross-border direct-purchase services. The data collected from Korean users included names, addresses, email addresses, personal customs clearance codes and payment information. The decision describes the service as a typical open marketplace: when a user buys a product, the respondent passes the user’s data to the seller, and the seller ships the product. According to a footnote, a seller can access that data for 90 days, or keep and use it for longer through a seller tool.
The decision records the following findings.
| Provision | What the Commission found | Consequence in the decision |
|---|---|---|
| Art. 28-8(1): cross-border transfer | Personal data was provided to overseas sellers without separate consent obtained after the statutory items had been notified | Penalty surcharge KRW 1,978,000,000 |
| Art. 28-8(4): protective measures for cross-border transfer | No protective measures required by the Act were taken for overseas sellers or reflected in the terms agreed with them | Administrative fine KRW 7,800,000; corrective order (a) |
| Art. 31-2(3): domestic representative in the privacy policy | A newly designated domestic representative was not disclosed in the privacy policy until 4 April 2024, and the name of its representative director was not disclosed | No fine or order is attached to this finding by itself; improvement recommendation (b) concerns the domestic representative |
| Art. 38(4): method for exercising rights | Deleting an account was harder than signing up | Corrective order (b) |
The press release lists the domestic representative item as a breach of art. 31-2(1). The decision text applies art. 31-2(3), and this note follows the decision.
The decision applies the Act as amended by Act No. 19234 and the Enforcement Decree as amended by Presidential Decree No. 34309, both in force from 15 March 2024. The Commission sent the prior notice of the proposed measures on 5 June 2024, and the respondent submitted its comments on 26 June 2024.
The Commission’s decision board lists this decision under investigation number 2024조일0013. The later decision against Whaleco Technology Limited, the operator of Temu (No. 2024-013-193, 14 May 2025), carries the same investigation number. The press release of 25 July 2024 stated that Temu would be deliberated after further fact-finding and supplementary requests for materials. That decision is covered in The PIPC’s Temu decision.
The four violations and the Commission’s findings
1. Cross-border transfer without a lawful basis (art. 28-8(1))
The facts. When a Korean user buys a product, the respondent provides the user’s personal data to the overseas seller. The decision records that in the three months from 1 October to 31 December 2023 the respondent provided Korean users' data to a number of Chinese sellers and seller-tool operators. The decision redacts both numbers. The transferred data included payment information, such as bank account details, card numbers and cash receipt information, as well as delivery addresses. Based on the countries registered in the respondent’s global seller centre, the data could go to five countries: China, Spain, Italy, Türkiye and Brazil. At the time of the decision the respondent was providing data to China only.
The consent mechanism worked as follows. At sign-up, the user had to tick "consent to overseas transfer (required)". Clicking the item opened the full text of the privacy policy. If the user scrolled down to the section on provision to third parties, the list of sellers showed only a limited number of Chinese sellers (the number is redacted), and the recipients' location was given as "worldwide". The decision found no record that the respondent, at the point of purchase, told users the items listed in art. 28-8(2) and obtained their consent. A footnote in the decision summarises those items as the personal data transferred; the country, timing and method of transfer; the recipient’s name; the recipient’s purpose of use and retention period; and the method, procedure and effect of refusing the transfer. In its reasoning the Commission singled out the missing country, recipient and recipient contact details as the core of the notice.
During the investigation, on 12 April 2024, the respondent removed the sign-up checkbox. It added a consent step to the purchase process that shows the country of transfer, the seller’s name and contact details.
The Commission’s finding. The Commission noted that most recipients were Chinese sellers. It found that, for this respondent, separate consent from the data subject was the only lawful basis available under art. 28-8(1). The respondent had not built any separate consent process beyond the sign-up checkbox. The privacy policy described the country of transfer as "worldwide", did not describe how to refuse the transfer or what refusal would mean, and left out more than 95% of the sellers. A footnote gives the figures: data went to at least 180,000 sellers, and about 8,000 were named. The Commission also referred to its own Online Personal Information Processing Guidelines of December 2020. Those guidelines say that where the recipient cannot be identified at sign-up, the recipient should be named and consent obtained at the actual purchase or payment stage. The Commission concluded that failing to notify the statutory items and obtain separate consent during the purchase, when the country and the recipient become identifiable, breached art. 28-8(1).
The respondent’s argument. The respondent argued that it had left out only some of the statutory items, namely the country and the contact details, and that this was not a ground for a surcharge. It said users could see the missing information on the purchase screen, and that users of a marketplace could foresee that their data would go to sellers.
The Commission’s answer. The Commission rejected the argument in three steps.
First, the Commission read the notice items as part of consent. The Act prohibits cross-border transfer in principle and allows it only on specified conditions such as consent. The Commission said that such consent must be substantive and must follow full notice of the statutory items. In its view the notice items do not stand alone. They attach to the consent requirement and are a main element in deciding whether consent was valid. If the notice was so incomplete that consent cannot be regarded as obtained, the breach is a breach of the consent duty, and a surcharge can be imposed. A footnote cites the Commission’s guide to the amended Act to the same effect.
Second, the Commission found that the omissions went to the core of the notice. The respondent itself had admitted that the country and the contact details were missing, and most recipient names were also missing. The decision puts it this way:
「국외이전의 핵심(요체)인 국가와 연락처, 이전받는 자를 포함하지 않은 것은 해당 고지 자체를 형해화한 것이다」 — leaving out the country, the contact details and the recipient, which are the core of a cross-border transfer, "reduced the notice itself to an empty shell".
Third, the Commission rejected the argument that users could find the information elsewhere or could foresee the transfer. Notifying the statutory items and obtaining consent is the controller’s duty. Korean open marketplaces obtain a separate consent at the purchase stage. An ordinary Korean user who ticked the sign-up box would expect it to cover the transfers the privacy policy linked to sign-up, such as marketing analysis, translation, hosting and spam checks, and would expect a separate consent for order information. The Commission added two more points. The respondent had a place of business in Korea, a Korean-only page and heavy advertising in Korean media, so users could take it for a Korean company. E-commerce also takes many forms, including operators that buy goods and ship them themselves. For these reasons the Commission did not accept that users could have foreseen the cross-border transfer.
2. No protective measures for the cross-border transfer (art. 28-8(4))
The law. Art. 28-8(4) requires a controller that transfers personal data abroad on one of the art. 28-8(1) grounds to comply with the Act and to take protective measures prescribed by Presidential Decree. Art. 29-10(1) of the Enforcement Decree lists those measures: safety measures under Decree art. 30(1), measures for handling complaints and resolving disputes over infringement, and other measures needed to protect data subjects. Decree art. 29-10(2) requires the controller to consult the recipient on those matters in advance and to reflect them in the contract or similar instrument.
The facts. The decision found no step by which the respondent had enabled sellers to comply with the Act. It found no safety measures, no complaint-handling or dispute-resolution measures, and none of the other measures that businesses usually take, and none of this appeared in the terms agreed with overseas sellers. The respondent also did not check, when a seller viewed a buyer’s data, that the person logging in was an authorised seller, beyond the seller’s ID and password. The Commission linked this to the risk that seller accounts are taken over and buyers' data is leaked.
The respondent relied on its seller terms, a Free Membership Agreement that sellers accept through a link when they register, and on a separate document described as rules on disclosing others' information and on malicious harassment. According to a footnote, that separate document is not shown to sellers at registration. The Commission found nothing relevant in the terms. The separate document only prohibited unauthorised disclosure or transmission of buyers' personal data. The respondent also stated that on 24 May 2024 it had told sellers, through the seller site, to comply strictly with the relevant laws and to take the necessary safety measures.
The Commission’s finding. The Commission observed that data transferred abroad can move beyond the reach of the Act, so measures against misuse by the recipient are especially needed. It noted that overseas sellers had been involved in two kinds of abuse: listing goods at low prices to collect personal data without shipping anything, and so-called brushing scams, in which a seller uses personal data to place orders and ships worthless items to inflate its sales record. The respondent had not taken the measures that Korean operators usually take when they provide data to Korean sellers, such as a ban on use for other purposes and destruction once the purpose is achieved. In the Commission’s words it had not taken even the minimum measures required by law. The Commission found a breach of art. 28-8(4).
The respondent’s argument and the answer. The respondent argued that its contracts with overseas sellers did include user data protection, and that letting sellers log in with an ID and password alone was not a breach of the safety-measure duty. The Commission answered that Korean operators usually have terms on purpose limitation and destruction, sometimes train sellers, and use a secure authentication method beyond ID and password when sellers access the system. The respondent’s seller terms contained none of this, and it began informing sellers about protective measures only during the investigation. The Commission did not accept the argument.
3. Domestic representative not fully disclosed (art. 31-2(3))
Art. 31-2(3)(1) requires a controller that designates a domestic representative to include the representative’s name in the privacy policy, and for a corporation its corporate name and the name of its representative director. The KLRI English translation of the Act calls the domestic representative a "domestic agent".
On 29 August 2023 the respondent replaced its domestic representative with a new corporate representative. It did not disclose the change in its privacy policy. On 5 April 2024, during the investigation, it revised the policy and named the new representative, but still did not give the name of the representative’s representative director. The decision redacts the names of both representatives. The Commission found that not disclosing the representative until 4 April 2024, and not disclosing the representative director’s name, breached art. 31-2(3).
4. Account deletion harder than sign-up (art. 38(4))
Art. 38(4) requires a controller to set out and publish a specific method and procedure for data subjects' requests, and says that the method must not be more difficult than the method used to collect the data.
A user could sign up with only an email address or a mobile number, or through a simple login with Google, KakaoTalk, Naver, Facebook, Apple and others. To delete the account, the user had to go through Home, Account, Settings, Edit profile, "Deactive Account", "Delete Your Account", type "agree", and then enter an email verification code. The "Deactive Account" link sat at the top of the Edit profile screen, and the page it opened was in English by default.
The respondent argued that deletion was not more complex than sign-up and was much simpler than at other operators, and asked the Commission to reconsider the corrective order. The Commission rejected this. It reasoned that users usually understand "Edit profile" as a page for changing the information they entered, so they would not find the deletion route intuitively. Even after reaching it, they had to read English text and type "agree". The Commission found the deletion procedure clearly more complex than sign-up, and a breach of art. 38(4).
How the surcharge was built up
The surcharge was imposed for the art. 28-8(1) violation only. Its legal basis is art. 64-2(1)(7) of the Act, art. 60-2 of and Table 1-5 to the Enforcement Decree, and the Standards for Imposing Surcharges for Violations of Personal Information Protection Laws (PIPC Notice No. 2023-3, in force from 15 September 2023; "the Notice").
The decision states the intermediate amounts in Chinese yuan, and all of them are redacted in the published text. The decision converted the final amount into Korean won at the average exchange rate for the turnover calculation period.
| Step | What the decision applies | Amount in the published text |
|---|---|---|
| Ceiling | 3% of the average annual turnover for the three business years before the year of the violation (art. 64-2(1); Decree art. 60-2) | Not stated |
| Seriousness grade | "Serious violation" (중대한 위반행위), after weighing the four factors in the next table (Notice art. 8(1) and Table) | — |
| Relevant turnover | Average annual total turnover for the previous three business years, less revenue from one service (its name is redacted) and revenue related to business development and marketing investment, whose connection with the violation was not confirmed (Notice art. 7(3)) | Redacted |
| Base amount | Relevant turnover × 1.5% (150/10,000), the base rate for a serious violation | Redacted |
| First adjustment | +50% of the base amount: the violation lasted more than two years, a "long-term violation" (Notice art. 9) | Redacted |
| Second adjustment, increase | +20% of the amount after the first adjustment: failure to submit total turnover data requested under art. 63(1), treated as obstruction of the investigation (Notice art. 10) | Redacted |
| Second adjustment, reduction | −30% of the amount after the first adjustment: the violation was corrected before the prior-notice comment period ended (Notice art. 10) | Redacted |
| Final surcharge | Amounts of KRW 100 million or more are rounded down to the nearest KRW 1 million (Notice art. 11(5)) | KRW 1,978,000,000 |
The Commission weighed four factors to set the seriousness grade.
| Factor | Grade | The Commission’s reasons |
|---|---|---|
| Intent or negligence | Medium | The respondent entered the Korean market aggressively for profit and for a long time did not review or observe basic rules, which the Commission called gross negligence. The Commission took into account that the sign-up screen did ask users to tick a consent to overseas transfer. |
| Method of the violation | Medium | The respondent provided data to at least 180,000 overseas sellers without following the consent procedure or taking protective measures, which the Commission called markedly improper. It took into account that some transfer is necessary to provide the service. |
| Type of personal data | Low | The data did not include unique identifying information such as resident registration numbers, sensitive information or authentication information. |
| Scale and effect on data subjects | Medium | The violation lasted about seven years and nine months. The Commission again took into account that some transfer is necessary to provide the service. |
The obstruction increase deserves a closer reading. The decision says that the failure to submit total turnover data was a case of obstructing the investigation, for which a 30% increase "should" apply. The Commission applied 20% instead because the respondent had appeared before the Commission, actively explained the reasons for the failure, and showed remorse.
Both second-adjustment percentages were applied to the same amount, the amount after the first adjustment. Taken together, the second adjustment reduced the amount after the first adjustment by a net 10%.
A separate page explains the same steps in general terms: How Korean privacy fines are calculated.
The administrative fine
The administrative fine was imposed for the art. 28-8(4) violation, under art. 75(2)(14) of the Act, art. 63 of and Table 2 to the Enforcement Decree, and the PIPC’s guidelines on administrative fines for violations of the Act (in force from 15 September 2023).
The respondent had no fine for the same violation in the previous three years. The Commission therefore used KRW 6,000,000, the amount for a first violation, as the base amount. It increased the base amount by 30% under art. 8 of the guidelines because the violation had lasted more than two years. It found no ground for a reduction. The fine came to KRW 7,800,000.
Corrective orders, improvement recommendations and publication
The Commission issued three corrective orders under art. 64(1) of the Act.
- (a) Comply with the Act’s rules on cross-border transfer, put in place the measures the Act requires to prevent misuse of personal data by overseas sellers and others and to respond to infringements, and reflect them in contracts.
- (b) Set out a specific method and procedure that lets data subjects exercise their rights easily, including account deletion, and publish it.
- (c) Report the results of (a) and (b) within 90 days of being notified of the measures.
The Commission also made four improvement recommendations under art. 61(2).
- (a) Disclose the flow of personal data processing to data subjects as transparently and plainly as possible, and update the disclosure promptly when it changes.
- (b) Go beyond simply designating a domestic representative and make real operational efforts, in particular by setting up and implementing concrete ways to handle complaints and provide redress.
- (c) Minimise the personal data collected, and either join the public-private self-regulatory code run by Korean e-commerce companies or provide an equivalent level of protection.
- (d) Carry out (a) to (c) in consultation with the Commission, and submit the results and plans within 90 days of notification.
The Commission did not order the respondent to publish the fact that it had been sanctioned. It found that the case met one ground for a publication order in its guidelines, a violation lasting more than three years. It decided against the order after considering, among other things, that the respondent had corrected the cross-border transfer violation itself and could be expected to comply with the Act.
The decision states the routes for challenge. The corrective orders and the surcharge can be challenged by an administrative appeal or an administrative lawsuit within 90 days. An objection to the administrative fine must be filed with the Commission in writing within 60 days.
Three points for a group legal team
1. The decision places consent to a marketplace transfer at the point where the recipient becomes known. The respondent’s consent was taken at sign-up, before any seller could be identified. The Commission treated the country, the recipient and the recipient’s contact details as the core of the notice, and treated a consent without them as no consent. It then imposed the surcharge on that basis. The point applies where a group relies on separate consent as the basis for the transfer, as the respondent had to here. Such a group may therefore need to check at which step in the user journey each cross-border recipient becomes identifiable, and whether the statutory items are shown and consent is obtained at that step.
2. The protective measures under art. 28-8(4) were assessed in the seller terms. The Commission looked for the measures in the terms agreed with overseas sellers. It did not accept a general prohibition on disclosing buyers' data as sufficient. It compared the respondent’s terms with what Korean operators usually include, such as purpose limitation and destruction clauses, and with seller authentication beyond ID and password. A notice sent to sellers during the investigation did not change the finding.
3. The obstruction increase and the correction reduction rested on different grounds. The respondent did not submit total turnover data, and the Commission added 20% for obstruction. The respondent also corrected the violation before the comment period ended, and the Commission took off 30%. The Commission lowered the obstruction increase from the 30% it said should apply because the respondent had appeared and explained itself. How these factors would be weighed in another investigation depends on its own facts and requires individual review.
Related
- Decision text in Korean (PIPC decision board)
- The PIPC’s Temu decision (2025)
- Appointing a domestic representative under Korea’s PIPA
- How Korean privacy fines are calculated
- PIPC enforcement decisions, in English
Frequently asked questions
In the AliExpress decision, did a "consent to overseas transfer (required)" checkbox at sign-up count as consent under PIPA art. 28-8(1)?
No. Clicking the consent item opened the full privacy policy. The Commission found that the policy described the recipients' location as "worldwide" and named only a small part of the sellers who received data. The Commission held that the statutory notice items under art. 28-8(2) are part of what makes consent valid. Where the country, the recipient and the recipient’s contact details are left out, the Commission treated the consent as not obtained. It also referred to its December 2020 online guidance: where the recipient cannot be identified at sign-up, the recipient should be named and consent obtained at the purchase or payment stage.
Why was the AliExpress surcharge increased for obstruction, and by how much?
The respondent did not submit total turnover data that the Commission had requested under PIPA art. 63(1). The Commission treated this as obstruction of the investigation. It stated that a 30% increase should apply, but it applied 20% because the respondent had appeared before the Commission, actively explained the reasons and showed remorse. In the same second-adjustment step it reduced the amount by 30% because the respondent had corrected the violation before the prior-notice comment period ended. Both percentages were applied to the amount after the first adjustment.
What sanction attached to AliExpress’s failure to put protective measures into its terms with overseas sellers?
An administrative fine of KRW 7,800,000 under PIPA art. 75(2)(14), and corrective order (a). The fine started from a base amount of KRW 6,000,000 for a first violation and was increased by 30% because the violation had lasted more than two years. The Commission found no ground for reduction. Corrective order (a) requires the respondent to put in place the measures the Act requires to prevent misuse of personal data by overseas sellers, and to reflect them in its contracts.
This note describes a single published decision for readers outside Korea and is not legal advice. The outcome of any investigation turns on its own facts and requires individual review. The respondent’s name is taken from the PIPC’s press release of 25 July 2024. Names of other entities, seller counts for the October to December 2023 period, turnover figures and intermediate amounts are redacted in the published decision and are not supplied here. All English renderings of Korean statutes, rules and decision text are unofficial; the Korean text governs.
Written by Hyunsub Lee, a Korean-qualified lawyer at SEUM Law in Seoul (firm profile — the page opens in Korean; use the ENG switch at the top right for the English version). Other English summaries are collected at English summaries.