On July 23, 2026, the commission imposed fines on TikTok and two Apple affiliates, ordering them to rectify their violations and disclose the facts regarding their illegal collection, use, and cross-border transfer of South Korean users’ personal information. TikTok was fined 10.306 billion won (approximately 47.54 million yuan), while Apple was fined 252 million won (equivalent to approximately 1.16 million RMB).
The TikTok Case
Regarding TikTok, the investigation found that through behavioral tracking tools deployed on third-party websites and apps (such as TikTok Pixel and Events SDK), the company collected behavioral records—including browsing, clicks, and purchases—from approximately 9.45 million active South Korean users without their explicit knowledge. It then linked this data to user device identifiers and accounts for the purpose of delivering targeted advertisements.
TikTok claimed to have obtained user consent, but the Commission determined that this consent was obtained coercively by bundling it with mandatory terms of service during the registration process, leaving users effectively unable to opt out. Additionally, when TikTok Lite transferred user information to affiliated companies as part of its reward points redemption service, it failed to disclose statutory requirements—such as the scope of the transfer, its purpose, and the retention period—as required by law.
Apple Case
Regarding Apple, the investigation focused on the data processing procedures for its voice assistant, Siri. As of August 2019, Apple collected voice recordings and corresponding transcripts when users used Siri without obtaining separate consent, and used this data to improve speech recognition and search results. After October 2019, although Apple obtained separate consent for the collection of voice recordings, it continued its previous practice regarding the processing of transcribed text without providing any opt-out mechanism. At the same time, when Apple transferred the aforementioned data across borders to its affiliated companies in the United States, it failed to fully specify in its privacy policy the types of data transferred, the recipients’ purposes, and the retention periods.
However, during the investigation, Apple took proactive corrective measures: it added an opt-in option for transcribed text, implemented de-identification measures to filter out personal information, and revised its privacy policy. Based on this, the Commission imposed a fine of 252 million won on Apple’s affiliate ADI and issued a corrective order to another affiliate, ASPL, requiring it to strengthen its review of cross-border data transfers.