NCRC Hit With Heavy Penalty for Leaking 1.17 Million Records of Missing Children and Adoptees' Personal Information
- Input
- 2026-08-27 12:31:03
- Updated
- 2026-08-27 12:31:03
This is the largest penalty surcharge ever imposed on a public institution. For public agencies with no sales revenue, or where revenue is difficult to calculate, the PIPC imposes a fixed amount. The size of the penalty shows how serious the violations were.
On the 26th, the PIPC held a plenary meeting and decided to impose the fine and penalty surcharge on the NCRC, which caused three personal data breaches involving missing children and adoptees. It also resolved to recommend that the Ministry of Health and Welfare (MOHW), the supervising ministry, strengthen guidance and oversight of the center's overall personal data management system, the commission said on the 27th.

From 2013 to 2022, the NCRC digitized adoption records and intake cards for missing children into Excel files and scanned documents, then stored the data on auxiliary media such as external hard drives, USB memory sticks and CDs. The center kept these devices in office cabinets and drawers, but failed to properly implement security measures such as assigning a responsible manager or maintaining logs for removal and return. It also failed to even notice that the storage media had gone missing.
Because of this poor management, one external hard drive containing 2020 intake card data for missing children was leaked, exposing about 30,000 items of personal information, including names, dates and places of occurrence, as well as roughly 15,000 resident registration numbers.
In addition, one CD was also leaked, exposing about 1.14 million items of personal information, including the names, addresses and contact details of adoptees.
Separately, a personal data breach also occurred in the Adoption Information Disclosure Request System operated by the NCRC. When application menus for adoptees and prospective adoptive parents were opened in March and April, poor site management led to an incident in which adoptees and prospective adoptive parents with the same serial number were able to view each other's documents. As a result, the names, dates of birth, genders and other personal information of 47 people, including 37 adoptees and 10 prospective adoptive parents, were leaked.
The PIPC stressed that "public institutions face even higher public interest and expectations regarding personal data protection, and because the personal information they handle carries greater meaning and value, they must do their utmost to protect it."
It also said it would respond strictly, including recommending disciplinary action, against institutions that delay or fail to notify affected individuals of data breaches.
[email protected] Lee Gu-sun Reporter