South Korea’s top financial regulator has reduced a proposed 140 billion won penalty against Tongyang Life Insurance to 7 billion won, following a legal reinterpretation of how the insurer shared customer data with its own sales arm. The decision sits within a documented pattern of enforcement rollbacks – and raises questions about data governance that reach across the industry.
The Financial Services Commission (FSC) approved the reduced fine at its regular meeting on September 9, 2026. The FSC did not publish an English-language press release on the decision.
The case originated from a 2022 management review in which the Financial Supervisory Service (FSS) found that Tongyang Life had passed customers’ personal credit information to its affiliated general agency (GA) without obtaining customer consent.
The FSS classified the conduct as a third-party provision of information under the Credit Information Use and Protection Act and recommended a penalty of approximately 140 billion won.
The FSC’s Legal Interpretation Review Committee reached a different conclusion. Tongyang Life’s data transfer to its affiliated GA “amounted to a simple outsourcing of business operations rather than the provision of information to a third party,” according to the Seoul Economic Daily. The commission also found the scale of the leak was not large compared with other financial sectors, and that some of the conduct did not meet the threshold for fines. The penalty was reduced “in consideration of the principle of proportionality, among other factors.”
Neither Tongyang Life nor Woori Financial Group, which acquired the insurer in 2025, issued a public statement in response.
Under South Korea’s Credit Information Act, transferring personal credit data to a third party requires prior customer consent. Outsourcing arrangements carry a different set of obligations – disclosure through privacy policies and, in some cases, reporting to the FSC – but not the same consent trigger.
By determining that the data transfer to Tongyang Life’s subsidiary GA constituted outsourcing, the FSC established that corporate structure can define what compliance obligations apply – regardless of the nature of the data or its intended commercial use.
Whether this finding creates binding precedent for future cases has not been publicly confirmed. It applies to the specific facts of this matter.
The Tongyang Life case is not a standalone outcome. According to the Seoul Economic Daily, of 38 monetary penalty cases finalized at FSC regular meetings between January and July 1, 2026, 34 – or 89.5% – resulted in reduced amounts. Only four were revised upward.
The National Assembly Research Service has flagged the trend, warning that “concerns are raised that sanctions lack consistency and are swayed by public opinion.”
Court losses have also shaped the FSC’s approach. Refunds to financial firms exceeded 3.5 billion won as of end-May 2026 – more than four times the previous year’s total of 789 million won – after a series of regulatory penalties were overturned in the courts. Some FSC commissioners have argued that litigation risk should factor into penalty deliberations, a position critics say has allowed legal exposure to influence enforcement outcomes ahead of the evidence.
Financial authorities said they would review ways to improve the fine-calculation system under the credit information law. No timeline was provided.
The fine lands on an insurer that completed a change of ownership just months before the ruling. Woori Financial Group received FSC approval to acquire Tongyang Life Insurance in May 2025 and completed the transaction on July 1, 2025, paying approximately 1.3 trillion won for a 75.34% stake, according to KED Global.
Non-bank businesses’ contribution to Woori group net income rose from 6.9% to 22.3% in the first half of 2026, reflecting the early impact of the insurance acquisitions on group earnings. A data breach penalty predating the acquisition now sits on the books of an insurer serving as a key growth vehicle within one of South Korea’s largest financial conglomerates.
Agency forces – including GAs – held a 48.25% share of South Korea’s combined life and non-life insurance distribution market in 2025, according to Mordor Intelligence.
As subsidiary GAs have become a primary route to market for life insurers, the routine flow of policyholder data between parent companies and their affiliated agencies has become an operational given. The FSC ruling provides some regulatory clarity on how that flow may be classified – but says nothing about how data may be used once it arrives at the agency.
If a client’s data enters an insurer's corporate group under an outsourcing classification, whether it can be used for cross-selling or retention activity within the same group remains commercially live, even if the transfer itself is now legally distinct from third-party disclosure.
Brokers managing client relationships in markets with similar insurer-GA structures – present across several Asian markets – should examine how data their clients share with insurers is governed once it moves within a corporate group, and whether their client agreements address that boundary.