inflearn logo
inflearn logo

[Coupang] Training on Personal Information Processing Policy Inspection Methods, Focusing on Errors in the Policy

The recent Coupang personal information leak has been recorded as the largest data breach in South Korea's history, marking an instance where the personal information of virtually every South Korean citizen was compromised. However, the debate regarding the effectiveness of ISMS-P concluded with meaningless improvement measures such as mock hacking and certification revocation. As of December 11, 2025, companies like Coupang—which were subjects of the Personal Information Processing Policy Evaluation System conducted by the Personal Information Protection Commission in 2024—continue to operate in violation of more than 10 criteria of that evaluation system. The reason for this lies in human error involving Coupang's personal information team (comprised of top domestic and international experts) and ISMS-P auditors (who hold the highest domestic and international qualifications). With basic common knowledge of the Personal Information Protection Act, this recent leak, as well as breaches at Gmarket, Netmarble, SKT, KT, and LG U+, could have all been prevented. In reality, accidents continue to occur because customers' personal information is not protected—or appropriate protective measures are not established and operated—due to human issues such as inadequate preliminary inspections and differences in legal interpretation. Through this lecture, you can acquire the skills to evaluate personal information transparently and objectively, with the hope that personal information protection for customers will be achieved through professional training aimed at proper inspection methods and eliminating blind spots.

4 learners are taking this course

Level Intermediate

Course period 6 months

ISMS-P
ISMS-P
CPPG
CPPG
Engineer information security
Engineer information security
security training
security training
Industrial Security Exper
Industrial Security Exper
ISMS-P
ISMS-P
CPPG
CPPG
Engineer information security
Engineer information security
security training
security training
Industrial Security Exper
Industrial Security Exper
날개 달린 동전

Recommend Course to grow and earn commission!

날개 달린 동전

Marketing Partners

Recommend Course to grow and earn commission!

What you will gain after the course

  • Ability to identify issues in the privacy policies of major corporations, such as Coupang, that have recently experienced personal information leakage incidents.

  • Ability to draft improvement plans for privacy policies based on the criteria of the Privacy Policy Evaluation System

🔥 The Era of Large-Scale Personal Information Leaks: 'Practical Privacy Policy Audit' Lecture Based on the Coupang Case is now OPEN! (No Audio)

Recently, Coupang has been the center of public attention after being hit with a massive fine due to an unprecedented large-scale personal information leak.
However, the bigger problem is the fact that even after the incident, Coupang's currently operating privacy policy (as of December 2025) is still found to have more than 10 serious defects.

📌 This course was created based on the results of my own detailed inspection of Coupang's privacy policy, using the Personal Information Protection Commission's 2024 'Privacy Policy Evaluation System Standards.'


🧩 Why should you learn from the Coupang case?

The shocking fact that even large corporations are missing the basics
– Errors in categorizing consent
– Failure to list countries for overseas transfer
– Misleading information regarding de-identified data
– Complexity in the method of disclosing sub-processing
– Omission of guidance on automated decision-making and data portability rights
– Failure to display pop-ups for behavioral information collection, etc.

Blind spots that even the ISMS-P audit missed
Although Coupang is known to operate a top-tier organization of privacy experts in Korea, many of the issues revealed in this inspection were areas that failed to meet even the basic items typically verified during an ISMS-P audit.

Numerous companies are repeating the same issues
Not only Coupang, but also the three major mobile carriers and large platforms
– Lack of guidance on exercising rights
– Insufficient labeling of sub-processing
– No guidance on automated decision-making
were commonly discovered.

In other words, this lecture is not about the problems of a single company, but rather an exploration of the reality of personal information management across all of South Korea.


🎓 What will you learn in this lecture?

🔍 1. Complete Commentary on the 2024 Privacy Policy Evaluation System Standards

– Understand the evaluation checklist one by one through actual cases
– Clearly distinguish between legal requirements and common misconceptions held by companies

🛑 2. Analysis of more than 10 major defects found in Coupang's privacy policy

– Failure to distinguish between mandatory and optional consent items
– Omission of consent for the collection and provision of behavioral information
– Unclear disclosure of overseas transfer countries, retention periods, and purposes
– UI issues that significantly reduce the visibility of sub-processing information
– Unclear information regarding the Chief Privacy Officer and the responsible department
– Insufficient guidance on automated decision-making, data portability, and the right to object

🧭 3. Providing improvement methods that can be directly applied to actual corporate privacy policies

– Comparison of good practice examples from LGU+, KT, and SKT presented in the PPT
– Provision of practical templates for correcting incorrect phrasing to meet legal standards
– Understanding the practical application procedures for ‘Notification of Behavioral Information Collection’
– Inclusion of a guide for establishing a ‘Systematization of Rights Exercise’

🚨 4. Revealing the points that are always flagged during ISMS-P audits

– Essential checkpoints for personal information flowcharts and outsourcing contracts
– Connectivity between the evaluation system and ISMS-P
– Practical tips for preparing for actual status inspections


💡 This lecture is essential for the following people

🔸 Corporate Privacy Officers
🔸 CPO/Chief Privacy Officers
🔸 Startup Operators
🔸 Organizations preparing for ISMS-P
🔸 Those who want to quickly enhance the capabilities of privacy practitioners
🔸 Legal/Policy officers who need to draft or revise privacy policies


🚀 Practical Privacy Policy Review: Learning from the Coupang Case Study

This lecture is not just a simple explanation.
It is a **"practical lecture that uses Coupang's actual current privacy policy as a benchmark to teach the areas where companies make the most mistakes."**

📌 If you felt that personal information lectures were difficult to apply to actual practice
📌 If you were at a loss on how to write a privacy policy 'in accordance with legal standards'
📌 If you want to know why data breaches occur regardless of company size, as seen in recent incidents

👉 This lecture provides the answer.

Recommended for
these people

Who is this course right for?

  • Privacy Officer

  • CPO

Need to know before starting?

  • Personal Information Protection Act

  • Privacy Policy Evaluation

Hello
This is jueygrace

189

Learners

13

Reviews

4.2

Rating

26

Courses

Security Consulting

Curriculum

All

3 lectures ∙ (1hr 8min)

Published: 
Last updated: 

Reviews

Not enough reviews.
Please write a valuable review that helps everyone!

jueygrace's other courses

Check out other courses by the instructor!

Similar courses

Explore other courses in the same field!

$17.60