| Title | PIPC Fines Worldcoin Foundation and Tools for Humanity Corporation KRW 1.14 billion for Non-Compliance with PIPA | ||
|---|---|---|---|
| Department | Date | 2024.10.04 | |
| Attachment | press release PIPC Fines Worldcoin Foundation and Tools for Humanity Corporation KRW 1.14 billion for Non-compliance with PIPA.pdf | ||
| Page URL | https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2702 | ||
| Contents |
Press Release PIPC Fines Worldcoin Foundation and Tools for Humanity Corporation KRW 1.14 billion for Non-Compliance with PIPA - Along with penalty surcharges on the, correction orders and recommendations issued for non-compliance with the required duties under PIPA
September 26, 2024 (This is an unofficial translation of a press release, originally prepared in Korean.)
The Personal Information Protection Commission (“PIPC”) held its 16th plenary meeting and reached a resolution to impose a penalty surcharge of KRW 1.14 billion on the Worldcoin Foundation (“Foundation”) and Tools for Humanity Corporation (“TFH”) with correction orders and recommendations for violations of the Personal Information Protection Act (“PIPA”) on September 25th, 2024.
The PIPC started launching investigations against the Foundation upon receiving civil complaints and media reports that it unlawfully collected biometric data of individuals in exchange for virtual assets (Worldcoin) in February.
As a result of the investigations, the PIPC found out that the Foundation and TFH, a personal data processor and operator of World App, failed to comply with the relevant obligations under the PIPA as follows: ● Collected personal information, including iris data of domestic data subjects, without a legal basis for lawful processing; and ● Failed to adhere to obligations with regard to cross-border data transfers.
Procedures for Distributing Worldcoin ① Install World App and create an account: Enter name, email, and phone number. ② Issue a World ID in the App: Automatically issued when creating an account in the App. ③ Scan Iris through an orb outfitted with an eyeball-scanning camera and generate code using scanned iris data ④ Distribute Worldcoin to authenticated accounts on a regular basis
1. Non-Compliance with the Obligations for Processing Sensitive Data
First up, the Foundation scanned domestic data subjects’ iris through the orb and generated code using the iris data, but failed to inform them of the purposes of collection and usage, and data retention periods in an appropriate manner as required under the PIPA. It provided a link regarding ‘Biometric Data Consent Form’ to explain the details of processing biometric data only in English (Korean translation was provided on March 22, 2024).
An iris code, in particular, is biometric data that can uniquely identify an individual and is irrevocable. In order to process such sensitive data, personal data processors should obtain consent and put safeguards in place. However, it failed to do so.
2. Non-Compliance with the Obligations for Cross-Border Data Transfers
The two entities subject to the PIPC’s investigations also failed to send required notifications, such as destinations where personal data was transferred, the name and contact information of those who receive the iris data, and other personal information collected from domestic data subjects.
3. Other Findings
Moreover, the Foundation did not come up with measures and procedures for data subjects to request deletion of an iris code or suspension to process their data. TFH insufficiently put an age verification procedure for those aged under 14 to join the App. During the investigations, the Foundation allowed users to delete their iris code and introduced a procedure to check ID on the spot as it resumed the collection of iris data in April 2024.
4. Administrative Sanctions
In light of the findings, the PIPC decided to fine the Foundation KRW 725 million for noncompliance with the obligations regarding processing sensitive data and cross-border data transfers, and TFH KRW 379 million for violating the obligations with regard to cross-border data transfers.
Along with penalty surcharges, the data protection supervisory authority issued correction orders and recommendations on the two entities. The Foundation is required to obtain separate consent for processing sensitive data, make sure that personal information, including iris data, is only used for the initial purposes, and provide a function to delete an iris code upon request from the data subjects in a practical way. For TFH, the PIPC ordered that it needs to introduce an age verification procedure within the app. Lastly, the two entities shall inform required notifications regarding cross-border data transfers to the data subjects in a compliant manner.
5. Significance of the Investigations and Sanctions During the investigations and deliberation, Worldcoin claimed that an iris code was only used to prevent duplicate membership, not to identify a specific individual, which in turn fell under the category of anonymized data. Moreover, the Foundation explained that it applied a variety of new technologies to enhance security.
However, the PIPC saw that the company dealt with processing sensitive data under the PIPA in consideration of the facts that it directly scans iris from data subjects to create code for data processing; iris data is inalienable and irrevocable, so is for each iris code; the code is assigned to each individual and functions as an identifier; and the code is internally linked to each World ID in practice. In this regard, they failed to gain explicit and valid consent from domestic data subjects for collecting and processing biometric data, leading to non-compliance.
The supervisory authority did not ban the processing of sensitive data as it issued aforementioned correction orders on them to meet a certain set of conditions to comply with the PIPA. The two entities are required to put safeguards in place as follows: ● Sufficient notification regarding processing sensitive data and then gaining separate consent from each data subject; ● Stronger measures to delete an iris code to exercise the rights of data subjects within the app; and ● Use limitations other than the initial purpose of collecting personal data (to authenticate humanness to get a World ID).
Amid the global adoption of artificial intelligence (AI) and the surging digital economy growth, usage of sensitive data, such as biometric data, and cross-border data transfers are on the rise. Against this backdrop, raising awareness of the duties and compliance with the PIPA have become more important than ever before for both business operators and personal data processors in order to safeguard privacy.
The PIPC will make ceaseless efforts to overhaul and support businesses to uphold and promote the rights of data subjects in the domains of emerging technologies and services.
* A PDF file, formatted for better readability, is attached.
|
||