Today's Focus: Privacy & Personal Data Protection — Tuesday, 21 July 2026
Today's Top Story
Korea's PIPC fines three breach laggards KRW 706M
At its 13th plenary on 8 July, Korea's Personal Information Protection Commission sanctioned LocknLock (KRW 503M), Ubase (KRW 168M) and Sunphoto (KRW 30M) — KRW 701M in penalty surcharges plus a KRW 5.4M administrative fine, all with publication orders — after basic safeguard failures let hackers take roughly 1.5 million people's data. The fact patterns are elementary: an unpatched 2022 mail-server vulnerability, admin pages reachable from the open internet with no IP restriction or second factor, unencrypted identifiers, and a breach discovered only via the hacker's extortion email. The timing is the real message: identical failures sanctioned after PIPA's 10%-of-turnover punitive-fine regime commences on 11 September (52 days) face a categorically different ceiling.
Also Today
Delete Act broker duty binds 1 August — California's DROP platform is live for consumers; registered data brokers must process deletion requests at least every 45 days from 1 August. Confirm your DROP access and processing workflow now. CPPA DROP
Korea's fine-calculation decree still unpublished — the Enforcement Decree rewriting PIPA's punitive-fine methodology has not appeared 52 days out. Track PIPC's press index; budget for the 10% ceiling until told otherwise.
New York's surveillance-pricing ban awaits signature — the One Fair Price Act (S8623B) sits with Governor Hochul and takes effect 180 days after signing. Map any personalized-pricing logic touching New York consumers. NY Senate
⏰ Deadline Alert
California Delete Act — DROP deletion-processing duty binds registered data brokers in 11 days (1 August 2026).
One Thing to Do Today
IP-restrict every admin interface of your personal-data systems and require a second authentication factor for external access — the exact two controls whose absence drove all three Korean sanctions.
Tomorrow's Focus
AI Governance — the EU AI Act's Article 50 transparency obligations apply in 12 days (2 August), and the Transparency Code of Practice signatory window closes tomorrow.
Related briefings: EU AI Act transparency rules go live 2 August · CNIL email tracking-pixel consent deadline hits today
CyberEyeQ — Actionable Regulatory Intelligence · Questions: [email protected]
