Thursday, August 27, 2026

NCRC Hit With Heavy Penalty for Leaking 1.17 Million Records of Missing Children and Adoptees' Personal Information

Input
2026-08-27 12:31:03
Updated
2026-08-27 12:31:03
[Newsis News Agency] The National Center for the Rights of the Child (NCRC), which leaked more than 1.17 million sensitive personal records of missing children and adoptees, has been hit with a fine of 863 million won and a penalty surcharge of 22.2 million won by the Personal Information Protection Commission (PIPC).
This is the largest penalty surcharge ever imposed on a public institution. For public agencies with no sales revenue, or where revenue is difficult to calculate, the PIPC imposes a fixed amount. The size of the penalty shows how serious the violations were.
On the 26th, the PIPC held a plenary meeting and decided to impose the fine and penalty surcharge on the NCRC, which caused three personal data breaches involving missing children and adoptees. It also resolved to recommend that the Ministry of Health and Welfare (MOHW), the supervising ministry, strengthen guidance and oversight of the center's overall personal data management system, the commission said on the 27th.

The PIPC said on the 27th that it had decided at its plenary meeting on the 26th to impose a fine of 863 million won and a penalty surcharge of 22.2 million won on the NCRC, which caused three personal data breaches involving missing children and adoptees. It also resolved to recommend that the Ministry of Health and Welfare (MOHW), the supervising ministry, strengthen guidance and oversight of the center's overall personal data management system. /Photo=Newsis News Agency

From 2013 to 2022, the NCRC digitized adoption records and intake cards for missing children into Excel files and scanned documents, then stored the data on auxiliary media such as external hard drives, USB memory sticks and CDs. The center kept these devices in office cabinets and drawers, but failed to properly implement security measures such as assigning a responsible manager or maintaining logs for removal and return. It also failed to even notice that the storage media had gone missing.
Because of this poor management, one external hard drive containing 2020 intake card data for missing children was leaked, exposing about 30,000 items of personal information, including names, dates and places of occurrence, as well as roughly 15,000 resident registration numbers.
In addition, one CD was also leaked, exposing about 1.14 million items of personal information, including the names, addresses and contact details of adoptees.
Separately, a personal data breach also occurred in the Adoption Information Disclosure Request System operated by the NCRC. When application menus for adoptees and prospective adoptive parents were opened in March and April, poor site management led to an incident in which adoptees and prospective adoptive parents with the same serial number were able to view each other's documents. As a result, the names, dates of birth, genders and other personal information of 47 people, including 37 adoptees and 10 prospective adoptive parents, were leaked.
The PIPC stressed that "public institutions face even higher public interest and expectations regarding personal data protection, and because the personal information they handle carries greater meaning and value, they must do their utmost to protect it."
It also said it would respond strictly, including recommending disciplinary action, against institutions that delay or fail to notify affected individuals of data breaches.


[email protected] Lee Gu-sun Reporter