VERSE PRESS

Crypto News, Global First.

South Korea Fines Bithumb for Sending User Data to Undisclosed Foreign Exchanges

South Korea's privacy regulator issued a 210 million won (roughly $135,700) penalty against Bithumb on June 24, 2026, announcing the decision publicly on June 25, after finding the exchange had routed personal user data to overseas platforms without proper consent, including to an entity it had never disclosed in its own privacy notices.

|

The Personal Information Protection Commission (PIPC) announced the fine on June 25, making it the first concluded enforcement action from an investigation that included on-site inspections of both Bithumb and rival Upbit on April 30, 2026. Upbit, which was investigated for a structurally identical arrangement involving the sharing of USDT order book data with Upbit APAC in Southeast Asia, remains under open review. The penalty covers two separate violations of South Korea's Personal Information Protection Act (PIPA), which requires companies to obtain explicit, informed user consent before transferring personal data across borders.

The Stellar Exchange Misdisclosure

The more specific of the two violations concerns Bithumb's USDT spot market, which the exchange ran from September through November 2025. To deepen liquidity, Bithumb entered an order book-sharing arrangement with Stellar Exchange, an Australian brokerage that operates as a subsidiary of Singapore-headquartered BingX. Bithumb's privacy notices identified Stellar Exchange as the overseas data recipient. In practice, user data flowed to bingx.com, which is operated by a separate Singapore corporate entity.

Under PIPA Article 28-8, that distinction matters. Consent must name the specific recipient, the data categories being transferred, the destination country, the purpose of the transfer, and the applicable retention periods. Routing data through a different corporate entity than the one named in a privacy notice is a direct statutory violation, regardless of how closely the two entities are related.

The arrangement drew regulatory scrutiny almost immediately. South Korea's Financial Intelligence Unit (FIU) launched an on-site investigation at Bithumb's Seoul headquarters on October 1, 2025, focused on anti-money laundering (AML) concerns. Reports at the time confirmed that BingX staff were physically present at Bithumb's Seoul office. A Bithumb spokesperson stated in September 2025: "We have been preparing for this for a long time and proceeded after thorough consultation with Stellar." Under mounting regulatory pressure, Bithumb shut down the USDT market and cut ties with Stellar Exchange entirely after approximately two months of operation.

Thirteen Unnamed Exchanges, No Consent

The PIPC identified a second, broader violation: Bithumb transferred personal data to 13 unidentified foreign exchanges during asset transfer operations without obtaining the required user consent before transferring personal data. The regulator has ordered corrective measures in addition to the financial penalty, though the specific remediation steps have not been made public.

Third Major Action in 2026

The PIPC fine is the third significant regulatory action Bithumb has faced this year. In February 2026, the exchange mistakenly distributed approximately 620,000 bitcoin (worth around $56 billion at the time) to users during a promotional event instead of 620,000 won. The PIPC reportedly linked the investigation of this incident to the broader data review. Some recipients sold immediately, triggering a price drop of 10 to 17 percent on the platform. Then in March 2026, the FIU issued the largest AML fine ever levied against a Korean crypto exchange: 36.8 billion won (roughly $24.6 million), plus a six-month partial suspension of new-user services. For context, Upbit had received a 35.2 billion won AML fine in 2025, making Bithumb's subsequent penalty a new record at the time of issuance. The FIU cited approximately 6.65 million individual violations, including 3.55 million failures to verify customer identities and 3.04 million improper transaction allowances. The exchange's CEO also received a formal reprimand. A Seoul administrative court overturned the suspension on April 30, 2026, though the legal status of the underlying fine remains unclear.

By comparison, the PIPC fine of 210 million won is small. PIPA does allow for penalties of up to 3 to 10 percent of annual revenue in severe cases, suggesting the size of this fine reflects the specific scope of the violations rather than the maximum possible exposure. Bithumb's annual revenue figures were not disclosed in the PIPC's announcement, so the practical ceiling of that exposure cannot be calculated from public information alone.

A Structural Tension for Korean Exchanges

The Bithumb case lands in the middle of a broader tension in South Korea's crypto market. Domestic exchanges operate under spot-only rules that prohibit the derivatives products widely available on international platforms. That regulatory gap drove roughly 160 trillion won (about $110 billion) in crypto outflows from Korean exchanges in 2025 alone, as traders sought foreign platforms for more sophisticated products. Exchanges like Bithumb have responded by pursuing international liquidity partnerships. The PIPC's enforcement now makes clear that those partnerships carry real data compliance liability if consent documentation does not keep pace with the underlying data flows.

The January 2025 enforcement action involving Kakao Pay established an important precedent: Kakao Pay was penalized for routing data for approximately 40 million users to Alipay without proper consent. Apple and Alipay were each cited as separate named parties in that same action, with distinct violations attributed to each company. Together, those cases set the framework the PIPC is now applying to crypto. The Bithumb case extends it to exchanges.

What This Means Beyond Korea

The ruling is relevant for exchanges and regulators across Asia and Africa. India's Digital Personal Data Protection Act (DPDP Act, 2023) imposes comparable cross-border transfer restrictions and explicit consent requirements. Any Indian exchange sharing user data with an international liquidity partner faces the same disclosure risk Bithumb ran into: the named recipient in the privacy notice must match the entity actually receiving the data. SEC Nigeria and FSCA South Africa have not yet issued equivalent rules for crypto platforms, but the PIPC's sustained enforcement record provides a working template they could draw from.

The compliance exposure extends beyond traditional exchanges. Smart contract-based liquidity protocols that route order flow through intermediate entities without disclosing those entities to users face analogous legal exposure under frameworks like PIPA, a consideration relevant to any developer building cross-border DeFi infrastructure.

A PIPC official stated in April or May 2026 that the commission planned to conclude its broader investigation into cross-border data sharing by exchanges in the second half of the year. Upbit's results, when they arrive, will indicate the scale of what is already a discernible pattern. The PIPC has now issued cross-border data transfer fines against major Korean and global technology companies across 2025 and 2026, including Kakao Pay, Apple, and Alipay, and has moved from consumer technology into crypto without breaking stride. Bithumb is unlikely to be the last exchange to find out what that costs.