Newsroom

South Korea Fines Bithumb $136K for Overseas User Data Transfers

25 June, 2026   /   News   /  AI   /  605 reads   /   Tags:  bithumb, personal, overseas, information, sharing

South Korea Fines Bithumb $136K for Overseas User Data Transfers

South Korea’s Personal Information Protection Commission has imposed a 210 million won penalty on major crypto exchange Bithumb for sharing user data with overseas platforms without proper consent, highlighting stricter enforcement of privacy rules in the sector

Regulatory Action Details

The Personal Information Protection Commission (PIPC) announced the decision following its 12th plenary meeting on June 24, 2026. Bithumb was ordered to pay approximately $136,000 and implement corrective measures to align its overseas data transfer practices with legal requirements.

The violations involved two main areas: order-book sharing and virtual asset transfers to overseas exchanges. Regulators determined that Bithumb transferred personal information abroad without obtaining the necessary separate consent from users as required under the Personal Information Protection Act.

Key Violations Identified
  • Sharing of Tether (USDT) market order book data with overseas platforms between September and November 2025, where data was sent to BingX systems despite user consent specifying Stellar exchange.
  • Provision of user details including names, wallet addresses, and in some cases dates of birth to 13 overseas exchanges for anti-money laundering purposes during virtual asset transfers.

Order-Book Sharing Case

The investigation originated from concerns raised during a 2025 parliamentary audit regarding Bithumb’s liquidity arrangements with foreign platforms. Order-book sharing enables matching of buy and sell orders across exchanges to improve liquidity. However, when user identifiers and related order information cross borders, it triggers personal data protection obligations.

PIPC found that while users consented to data transfers involving Stellar, the actual transmission occurred to a different recipient platform. This mismatch formed the basis for one part of the penalty, amounting to 120 million won for this violation.

“The cross-border transfer of personal information is a matter closely related to the data subject’s right to self-determination, and therefore requires meticulous compliance with the requirements and procedures stipulated in the Personal Information Protection Act.”
Personal Information Protection Commission

Virtual Asset Transfer Issues

In parallel, Bithumb shared personal data with multiple overseas exchanges to support anti-money laundering checks during withdrawals and transfers. While the regulator acknowledged the practical need for such information in AML processes, it stressed that this does not exempt exchanges from following consent and notification rules for overseas transfers. This second violation resulted in a 90 million won penalty.

The corrective order requires Bithumb to revise its overseas transfer protocols and clearly explain these arrangements in its personal information processing policy.

Broader Regulatory Context

This action adds to previous enforcement measures against Bithumb. Earlier in 2026, the exchange faced significant fines related to anti-money laundering compliance issues. South Korean authorities have been increasing oversight of cross-border activities in the crypto sector, including plans for greater international data sharing under frameworks like the OECD Crypto-Asset Reporting Framework.

Key Points
  • The fine underscores the importance of precise consent for specific data recipients in cross-border operations.
  • Privacy obligations apply even when data sharing supports legitimate AML objectives.
  • Regulators continue to balance financial crime prevention with individual data rights.

New Blockchain Privacy Guidelines

Alongside the Bithumb decision, PIPC released updated guidelines for personal information protection in blockchain services. These address the unique challenges of transparent, distributed, and immutable ledgers, recommending that identifiable personal data such as names or identification numbers should not be recorded directly on-chain.

The guidelines emphasize incorporating privacy protections during the design phase of blockchain services, managing on-chain disclosures, tracking risks, and ensuring proper data handling and deletion where possible.

PIPC indicated it will maintain strict enforcement of the Personal Information Protection Act while developing standards that support responsible innovation in new technologies.

AspectDetails
Fine Amount210 million won (~$136,000)
Time Period of ViolationsSeptember to November 2025 (order book sharing)
Corrective MeasuresRevise transfer processes and policy disclosures
Additional GuidanceBlockchain privacy guidelines released
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.