Covers the legal liability for harm to data subjects from the leak, loss or theft of personal data a company holds or processes, under the Personal Information Protection Act and the Network Act.
N2N Insurance Brokerage does not represent any single insurer — it independently represents the client as an FSS-registered broker (Reg. No. 2026-012201). We compare the wordings, rates and service of AIG · Chubb · DB · Hyundai · KB · Meritz to propose the cover and price best suited to your risk. Each insurer's full wording is provided at application and binding.
Privacy / data-breach liability insurance covers the legal liability and response costs for harm to data subjects from the leak, loss, theft or alteration of personal data a company manages. It addresses the damages standards of the Personal Information Protection Act (Article 39) and the Network Act.
Information & communications service providers that exceed the annual-revenue and user-number thresholds are under a statutory duty to take out insurance or set aside reserves (Article 39-9 of the Personal Information Protection Act).
Issues a policy for operators subject to the duty to insure under Article 39-9 of the Personal Information Protection Act.
Covers incident-handling costs such as notifying data subjects, running a call centre and providing credit-monitoring services.
Supports legal and expert-witness costs for responding to collective dispute mediation and civil litigation.
Where linked to cyber events such as hacking or ransomware, it can be designed together with cyber liability insurance.
Operators processing personal data — portals, online malls, game companies, social networks, O2O platforms.
Sectors processing large volumes of sensitive data — to hedge risk even where exempt from the duty.
IT and marketing firms that process clients’ personal data under contract.
| Policy period | 1 year (Claims-Made basis) |
|---|---|
| Payment | Single (annual) payment |
| Insurers | AIG · Chubb · DB · Meritz · Hyundai |
| Channel | Individual consultation with our broker (010-5755-6465) |
| Turnaround | 5–7 business days (security review) |
If the insured event has already occurred at the time the contract is made, the contract is void. However, where the contract is void due to the company's intent or negligence, or where the company knew or could have known of the nullity before acceptance yet did not refund the premium, the company refunds the premium with interest at the policy-loan rate published by the Korea Insurance Development Institute, compounded annually, for the period from the day after payment to the day of refund.
The specific losses not covered (exclusions) are set out in each insurer's policy wording and product description; on this page, see the “Cover” tab(or the “Losses not covered” section) for the main exclusions. For other cover-specific grounds on which claims are not paid, please refer to the policy wording.
The company provides cover, in accordance with the policy, from the time it accepts the application and receives the first premium. Where the company accepts the application after receiving the first premium with it, cover also begins from the time the first premium was received.
The application must be completed by the policyholder, and the policyholder and the insured must sign it by hand. Failure to sign by hand may result in disadvantages regarding the validity of the contract. On an internet cyber-mall, an electronic signature may be used instead.
The policyholder has the right to be given and have explained the information needed about the product they wish to buy.
The insurer and N2N Insurance Brokerage must explain the important matters of the product to ordinary financial consumers.
When applying, the policyholder, the insured or their agent must disclose truthfully the facts they know regarding the questions in the application (including the questionnaire). Otherwise the claim may be declined or the contract cancelled. Where insurance is taken out by telephone or other means of communication, the duty is performed by answering the seller's questions, which are recorded, without a separate written questionnaire, so answers must be given with particular care.
If, after the contract is made, any of the following arises in respect of the subject-matter insured, the policyholder or the insured must notify the company in writing without delay and obtain endorsement on the policy.
The surrender value is the amount paid if the contract is cancelled early. Unlike bank savings, insurance combines risk protection and savings: part of the premium is paid out as claims to other policyholders who suffer accidents, and part covers the insurer's operating expenses, so the surrender value on early cancellation may be less than the premiums paid, or nil.
Under Article 59-4(1) of the Income Tax Act (special tax credit), for protection-type insurance taken out by an employee only, a tax credit of 12% of the premium paid (capped at KRW 1 million per year) is available. Tax matters may change with amendment or repeal of the relevant tax law.
Except as provided by law, the insurer and N2N Insurance Brokerage do not collect, use, inspect or provide personal data related to this contract — for its conclusion, maintenance and claim payment — without the consent of the policyholder, the insured or the beneficiary. However, for those purposes the insurer may, with the consent of the policyholder and the insured and in accordance with law, provide personal data to other insurers and insurance-related bodies.
The above is a summary and excerpt of the policy wording; for grounds on which claims are not paid and other details, please refer to the policy wording and product description.
Common risk patterns in personal-data processing — a five-scenario self-check
Operators processing large volumes of personal data — portals, online malls, game companies, social networks, platforms — bear the risk of compensating many data subjects after a breach.
The Personal Information Protection Act requires operators above a certain threshold to take out insurance or mutual-aid cover, or set aside reserves, to secure their liability.
A sensitive-data breach causes large harm to data subjects, so cover is needed even where the duty does not apply.
Operators that process personal data under contract, such as B2B SaaS and marketing firms, can also be liable for a breach.
A breach can lead to collective dispute mediation and litigation by many data subjects, so defence-cost protection is needed.
When personal data is breached, damages are not the only cost a company bears. “Incident-handling costs” — notifying and disclosing to data subjects, running a call centre, providing free credit-monitoring — arise immediately, followed by the costs of responding to collective dispute mediation and civil litigation and, where awarded, statutory and punitive damages. Privacy / data-breach liability insurance covers not only the damages for harm suffered by data subjects but also these incident-handling and defence costs. Meanwhile the Personal Information Protection Act requires operators above a certain threshold to insure, take mutual-aid cover or set aside reserves, so the cover itself can be a legal requirement.
Source: (standard insurance-textbook scenario)
The wording and structure points decision-makers most often overlook
A breach brings handling costs — notifying and disclosing to data subjects, running a call centre, providing credit-monitoring. Check that these are included in the cover.
The Personal Information Protection Act provides for statutory and punitive damages. Check in the wording how far the policy covers them.
An operator that processes clients’ personal data under contract is also liable for a breach. Design the insured scope to match the processing arrangement.
The questions asked most when considering privacy / data-breach liability insurance
The Personal Information Protection Act requires operators above a certain threshold to take out insurance or mutual-aid cover, or set aside reserves, to secure their liability. Whether it applies depends on business size, user numbers and other factors, so check against the relevant law.
It covers property and emotional damages suffered by data subjects from a leak, loss, theft or alteration of personal data, statutory and punitive damages, defence costs for collective dispute mediation and litigation, and incident-handling costs such as notification, disclosure, call-centre and credit-monitoring.
Incident-handling costs — notifying and disclosing to data subjects, running a call centre, providing free credit-monitoring — make up a large share of a breach. Check that the policy includes them.
Privacy / data-breach liability insurance is specialised in personal-data breaches and focused on meeting statutory duties, while cyber liability insurance covers cyber incidents broadly — hacking, ransomware, business interruption. They are often designed together for cases where the two risks overlap, such as a breach caused by hacking.
A processor handling clients’ personal data under contract can also be liable for a breach. The insured scope and cover should be designed to match the processing arrangement.
The insurer calculates it based on the volume and sensitivity of personal data held, user numbers, revenue, security level, the limit and cover structure, and past incident history. The exact premium and terms are confirmed after underwriting by insurers such as AIG, Chubb, DB, Hyundai, KB and Meritz.