South Korea fines TikTok and Apple over privacy violations

South Korea fined TikTok and Apple over unlawful data transfers and privacy violations affecting millions of users.

South Korea announced plans for an industrial growth fund supporting manufacturing AI transformation, robotics, AI factories, and future mobility projects.

South Korea has fined TikTok and Apple more than US$7.7 million for violating the country’s personal data protection rules, with regulators citing unlawful data collection practices, insufficient transparency and improper overseas data transfers.

The Personal Information Protection Commission (PIPC) imposed a US$7.6 million fine on TikTok after finding that the platform collected behavioural data from around 9.45 million South Korean users through tracking technologies embedded in third-party websites and mobile applications. According to the regulator, TikTok linked information such as browsing activity, purchases, clicks and device identifiers to user accounts for personalised advertising without adequately explaining how the data would be collected.

Investigators also found that TikTok failed to properly inform users about overseas transfers of personal data, including the categories of information being shared and the purposes of those transfers.

Two Apple affiliates were fined a combined US$185,000 after regulators found that Siri voice recordings and transcripts had been used to improve the service without an appropriate legal basis.

The commission also concluded that Apple transferred personal data to its headquarters in the United States without adequately informing users about the nature and purpose of those transfers. The penalty was reduced after Apple introduced stronger privacy controls, updated its policies and expanded user options for managing Siri transcripts during the investigation.

TikTok said it would review the regulator’s findings, while Apple said it would accept the decision.

Why does it matter?

The decision reflects increasing regulatory scrutiny of how global technology companies collect personal data for advertising and AI-powered services, particularly when that information is transferred across national borders. As privacy regulators strengthen enforcement, companies are expected to provide clearer explanations of how personal data is collected, processed and shared.

The case also reinforces the principle that multinational platforms must comply with domestic privacy rules regardless of where data is ultimately processed. Transparency, meaningful user consent and safeguards for international data transfers are becoming increasingly central to data governance frameworks around the world.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!