McDonald’s Korea fined for breach of customers’ personal data

In this article (5)
McDonald’s Korea was given a fine of 696 million won ($532,110) on Wednesday after the personal data of 4.87 million customers was leaked to hackers due to the firm’s lax data management.
The Personal Information Protection Commission handed out the fine to the Korean branch of the American fast food chain, along with a financial penalty of about 10 million won for the data breach.
According to the commission’s findings, McDonald’s Korea did not perform sufficient access control, leaving a backup file containing the personal data of its restaurant and McDelivery customers accessible via protocols for file sharing.
As a result, the personal data of more than 4.87 million customers was hacked and leaked. McDonald’s Korea was also found to have not destroyed the personal data of 766,846 customers for whom the data retention period had expired, and belatedly notified authorities and customers of the data leakage.
Questions & Answers
Q.How many customers were affected by the data breach?
How many customers were affected by the data breach?
More than 4.87 million customers had their personal data hacked and leaked. This included customers of McDonald's restaurants and McDelivery services.
Q.What was the main reason for the data leak?
What was the main reason for the data leak?
The leak occurred due to McDonald's Korea's lax data management. They did not perform sufficient access control, leaving a backup file accessible via file sharing protocols.
Q.What was the total amount of the fine imposed on McDonald's Korea?
What was the total amount of the fine imposed on McDonald's Korea?
McDonald's Korea received a fine of 696 million won ($532,110) for the data management breach, plus an additional 10 million won penalty specifically for the data breach.
Q.Were there any other issues found regarding customer data?
Were there any other issues found regarding customer data?
Yes, McDonald's Korea failed to destroy the personal data of 766,846 customers after their data retention period had expired. They also notified authorities and customers belatedly.
Reader pulse
Will this fine force major data security changes?
16,161 votes so far