VERSE PRESS

Crypto News, Global First.

South Korea Fines Bithumb ₩210 Million for Illegal Overseas Data Transfers

South Korea's privacy regulator has hit crypto exchange Bithumb with a ₩210 million (approximately $145,000 to $150,000) administrative fine for sharing order book data linked to user identification information with Stellar, an Australia-based crypto exchange unrelated to the Stellar blockchain network, without legal authorization, adding a third distinct regulatory action against the firm in 2026.

|

The Personal Information Protection Commission (PIPC) issued the penalty on June 25, following on-site inspections completed April 30. The violation centered on Bithumb's transfer of order book data to Stellar without satisfying the requirements set out in South Korea's Personal Information Protection Act (PIPA). PIPA provides four legal bases for cross-border personal data transfers: explicit user consent, notification to users of the transfer, an adequacy agreement with the recipient country, and an approved contractual safeguard with the recipient. Although order books are operational trading records, the PIPC found they contained sufficient user identification information to constitute a regulated cross-border personal data transfer, and Bithumb had satisfied none of the applicable requirements.

A Third Strike in One Year

The PIPC fine is the latest in a rapid sequence of regulatory actions against Bithumb. In March, the Financial Intelligence Unit (FIU) levied a ₩36.8 billion fine (roughly $24.6 million) and ordered a six-month suspension of new-user onboarding after investigators identified approximately 6.65 million anti-money laundering (AML) violations. Those included 3.55 million KYC failures and 3.04 million improperly processed transactions. Separately, Bithumb's CEO received a formal reprimand warning from the FIU in connection with the AML case, a development that becomes relevant to the personal accountability provisions discussed below. A Seoul Administrative Court reversed the suspension in May, granting a stay of execution on the same day Bithumb filed its application, though the status of the large financial penalty remained unclear at time of publication. Bithumb did not provide a public comment in response to the PIPC fine at time of publication.

These actions are part of a broader regulatory sweep across South Korea's crypto sector. In 2025, Dunamu, the operator of Upbit, was fined ₩35.2 billion and received a three-month suspension. Korbit was fined ₩2.73 billion in December 2024, and Coinone received a ₩5.2 billion fine and a three-month suspension in April 2026. Korean regulators have made clear that crypto exchanges are subject to the full scope of the country's financial and data compliance frameworks.

What PIPA Requires and Why It Matters for Exchanges

PIPA is one of Asia's most rigorous data privacy frameworks. It prohibits transferring personal data outside South Korea unless the operator satisfies at least one of four legal requirements: obtaining explicit user consent, notifying users of the transfer, concluding an adequacy agreement with the recipient country, or putting in place an approved contractual safeguard with the recipient.

Simply embedding user-linked metadata inside an operational data feed, such as an order book, does not exempt that feed from the cross-border transfer rules. The PIPC completed its investigation of Bithumb and launched a parallel inquiry into Upbit for sharing data with its Southeast Asian affiliate Upbit APAC. A PIPC spokesperson stated earlier this year that the commission planned to "finalize the investigation results within the second half of the year."

Small Fine, Large Precedent

At ₩210 million, the penalty is modest compared to other recent PIPC actions. In January 2025, the commission fined Kakao Pay ₩8.3 billion for routing 40 million users' data to Alipay without consent; the commission also ordered Alipay to destroy an AI credit-scoring model built on that data. Apple was fined approximately $3.2 million in the same enforcement action, a further signal of the PIPC's willingness to pursue large international entities. In June 2026, e-commerce giant Coupang received a record ₩624.7 billion fine (approximately $409 million) for a data breach. The Bithumb penalty is comparatively small, but its target is notable: this appears to be the first PIPC enforcement action to treat a crypto exchange's operational liquidity data as regulated personal information. That framing has direct consequences for every exchange running cross-border order routing or market-making arrangements with a Korean counterparty.

Implications Beyond Korea

The ruling carries practical weight for exchange operators and developers across South Asia, Southeast Asia, and Africa who connect to Korean liquidity infrastructure.

No South Asian or African jurisdiction currently holds adequacy recognition under PIPA, meaning any data flow from a Korean exchange to a local partner in those regions must rely on one of the four available compliance pathways: explicit user consent, user notification, an adequacy agreement with the recipient country, or an approved contractual safeguard. The adequacy status of Southeast Asian jurisdictions under PIPA varies by country and should be verified independently before assuming any particular compliance posture applies.

Operators integrating order book APIs from Korean exchanges should audit whether user-linked metadata is transmitted as part of those feeds.

A PIPA amendment taking effect September 11, 2026 for most of its provisions raises the ceiling for high-severity violations to 10 percent of total revenue and formally attaches personal accountability to CEOs for data protection failures. The formal FIU reprimand already issued to Bithumb's CEO signals that individual liability is a live enforcement consideration, not merely a prospective one.

Separately, legislation passed May 7, 2026 requires virtual asset service providers (VASPs) conducting cross-border transfers to register under South Korea's Foreign Exchange Transactions Act. African and South Asian exchanges receiving transfers from Korean users should treat this as a near-term compliance obligation, not a distant regulatory concern.

What Comes Next

The Upbit investigation remains active, and the PIPC has indicated it expects to publish findings before year end. With the upgraded PIPA fine structure arriving in September for most provisions, any enforcement action pursued or decided after that date could carry penalties far larger than the Bithumb or Kakao Pay cases. The enforcement pattern is now consistent across the industry: Bithumb, Dunamu, Korbit, and Coinone have all faced significant regulatory action within a compressed timeframe, demonstrating that Korean regulators treat crypto exchanges as full-scope financial and data compliance subjects. Firms operating on the periphery of Korean liquidity markets should assume they are already inside that regulatory perimeter.