South Korea Forces Telecom Giants to Remove Unfair Liability Clauses After Major Data Breaches
South Korea’s Korea Fair Trade Commission (KFTC) has ordered the country’s three dominant mobile carriers SK Telecom, KT, and LG Uplus to remove four categories of unfair clauses from their standard customer contracts. The ruling, issued on Thursday, targets provisions that previously shielded carriers from legal responsibility in cases of data breaches or negligence, marking a significant shift in consumer protections for the nation’s 55 million mobile subscribers.
Key Findings and Contract Changes
The KFTC’s review identified four types of clauses that violated Korea’s Terms and Conditions Act, which prohibits standard-form contracts from unreasonably limiting a business’s liability:
-
Blanket Data-Breach Immunity – All three carriers had clauses absolving themselves of liability for breaches, particularly those involving wireless LAN systems or private telephone exchanges. The KFTC ruled that carriers cannot contractually transfer security risks to subscribers and must now be held liable in proportion to their negligence.
-
Credential Security Shifted to Users – One carrier’s contract held subscribers fully responsible for unauthorized account use while capping the carrier’s liability to cases of gross negligence. The KFTC rejected this, affirming that carriers bear the burden of proving they were not at fault under Korea’s data protection laws.
-
All-or-Nothing Fault Elimination – Carriers previously included clauses stating that if a service disruption was partly caused by subscriber conduct, the carrier bore zero liability. The KFTC ruled that damages must be apportioned based on each party’s degree of fault, preventing carriers from evading responsibility entirely.
-
Silence as Consent to Contract Changes – One carrier’s contract deemed subscriber inaction as acceptance of amendments. The KFTC voided this practice unless carriers provide clear, prominent notice that silence within a reasonable period constitutes agreement.
Regulatory Pressure in the Wake of Major Breaches
The ruling arrives amid heightened scrutiny of South Korea’s telecom sector, following a series of high-profile security failures:
-
SK Telecom’s USIM Breach – In April 2025, malware in SK Telecom’s network exfiltrated USIM authentication data for 26.96 million subscribers (nearly half the population). Investigators found the company stored 26.1 million USIM keys unencrypted, used plaintext admin credentials, and ignored security patches dating back to 2016. The Personal Information Protection Commission (PIPC) fined SK Telecom ₩134.8 billion ($94 million) the largest telecom privacy penalty in Korean history while the Consumer Dispute Settlement Commission later ruled the carrier could owe up to ₩2.3 trillion ($1.61 billion) in per-user compensation.
-
KT’s Evidence Deletion – KT faced allegations of deleting server evidence during an investigation into a separate breach.
-
LG Uplus’s Server Wiping – LG Uplus was accused of wiping servers before regulators could examine them.
The KFTC’s action adds a consumer contract dimension to these enforcement efforts, removing the legal loopholes carriers could previously exploit to avoid liability.
Market Impact and Broader Enforcement Trends
South Korea’s telecom market is highly concentrated, with SK Telecom, KT, and LG Uplus serving nearly all 55 million subscribers. The KFTC noted that the lack of competitive alternatives left consumers with no choice but to accept the carriers’ unfair terms. The ruling ensures that future breaches will no longer be shielded by contractual waivers, providing subscribers with clearer legal recourse for damages.
The decision aligns with a broader crackdown on unfair standard-form contracts. In 2024, the KFTC handled 168 such cases 50% more than in 2023 targeting sectors from webtoons to e-commerce. However, the telecom ruling carries the highest stakes, given the industry’s scale and the sensitivity of the data involved.
Global Contrast: US Lacks Equivalent Protections
The KFTC’s action highlights a regulatory gap in the U.S., where mobile carriers routinely include limitation-of-liability clauses in contracts. While the FCC’s 2023 breach notification rules require disclosure, no federal regulator has compelled carriers to remove such waivers. State laws vary, but no systematic review akin to Korea’s has been conducted at the national level.
Future Implications
South Korea’s amended Personal Information Protection Act, set to take effect on September 11, 2026, will raise the maximum administrative fine for serious violations from 3% to 10% of a company’s annual revenue. While the new penalties won’t apply retroactively to past breaches, they will govern future incidents, increasing pressure on carriers to bolster security measures.
The KFTC’s ruling is prospective, meaning it applies to future breaches and contract disputes. However, ongoing compensation claims from the 2025 SK Telecom breach will proceed through separate regulatory and civil channels. For subscribers, the changes remove a major legal barrier, making it easier to hold carriers accountable for negligence.
LG Uplus TPRM report: https://www.rankiteo.com/company/lg-uplus
SK Telecom TPRM report: https://www.rankiteo.com/company/sk-telecom
"id": "sk-lg-1786027269",
"linkid": "sk-telecom, lg-uplus",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '26.96 million',
'industry': 'Telecom',
'location': 'South Korea',
'name': 'SK Telecom',
'size': 'Large',
'type': 'Telecommunications'},
{'industry': 'Telecom',
'location': 'South Korea',
'name': 'KT',
'size': 'Large',
'type': 'Telecommunications'},
{'industry': 'Telecom',
'location': 'South Korea',
'name': 'LG Uplus',
'size': 'Large',
'type': 'Telecommunications'}],
'attack_vector': 'Malware',
'customer_advisories': 'Subscribers may seek compensation for '
'negligence-related breaches; legal recourse is now '
'clearer.',
'data_breach': {'data_encryption': 'No (unencrypted USIM keys)',
'data_exfiltration': 'Yes',
'number_of_records_exposed': '26.96 million',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (USIM keys, PII)',
'type_of_data_compromised': 'USIM authentication data, '
'personally identifiable '
'information'},
'date_detected': '2025-04',
'date_publicly_disclosed': '2025-04',
'description': 'South Korea’s Korea Fair Trade Commission (KFTC) ordered SK '
'Telecom, KT, and LG Uplus to remove unfair clauses from '
'customer contracts that shielded them from liability in data '
'breaches or negligence cases. The ruling follows major '
'security failures, including SK Telecom’s USIM breach '
'affecting 26.96 million subscribers, where unencrypted data '
'and ignored security patches were found.',
'impact': {'brand_reputation_impact': 'Significant reputational damage to SK '
'Telecom, KT, and LG Uplus',
'data_compromised': 'USIM authentication data, personally '
'identifiable information',
'financial_loss': '₩134.8 billion ($94 million) fine, potential '
'₩2.3 trillion ($1.61 billion) in per-user '
'compensation',
'identity_theft_risk': 'High (USIM data and PII exposed)',
'legal_liabilities': 'Increased liability for negligence, removal '
'of unfair contract clauses',
'operational_impact': 'Regulatory scrutiny, legal actions, '
'contract revisions',
'systems_affected': 'SK Telecom’s network, wireless LAN systems, '
'private telephone exchanges'},
'investigation_status': 'Ongoing (compensation claims and regulatory actions)',
'lessons_learned': 'Carriers cannot contractually transfer security risks to '
'subscribers; negligence must be proportionally liable. '
'Unencrypted sensitive data and unpatched vulnerabilities '
'pose severe risks.',
'post_incident_analysis': {'corrective_actions': 'Removal of unfair clauses, '
'regulatory compliance '
'adjustments, potential '
'encryption and patching '
'improvements',
'root_causes': 'Unencrypted USIM keys, plaintext '
'admin credentials, ignored '
'security patches, unfair contract '
'clauses'},
'recommendations': 'Implement encryption for sensitive data, enforce regular '
'security patching, remove unfair liability clauses from '
'contracts, enhance regulatory compliance frameworks.',
'references': [{'source': 'Korea Fair Trade Commission (KFTC)'},
{'source': 'Personal Information Protection Commission '
'(PIPC)'}],
'regulatory_compliance': {'fines_imposed': '₩134.8 billion ($94 million)',
'legal_actions': 'Potential ₩2.3 trillion ($1.61 '
'billion) in per-user compensation',
'regulations_violated': 'Terms and Conditions Act, '
'Personal Information '
'Protection Act',
'regulatory_notifications': 'KFTC ruling, PIPC '
'investigation'},
'response': {'remediation_measures': 'Removal of unfair contract clauses, '
'regulatory compliance adjustments'},
'stakeholder_advisories': 'Telecom carriers must revise unfair contract '
'clauses and improve data security practices.',
'title': 'South Korea Forces Telecom Giants to Remove Unfair Liability '
'Clauses After Major Data Breaches',
'type': 'Data Breach',
'vulnerability_exploited': 'Unencrypted USIM keys, plaintext admin '
'credentials, unpatched vulnerabilities'}