Skip to content

Comparison of Personal Information Protection Levels by Company Size and Type: From the Perspective of Privacy Policy Assessment

Kim, Hui Young Primary Contact
Abstract

The growing emphasis on ESG management has elevated data privacy protection as a key corporate competitiveness factor. While cybersecurity and data privacy are now recognized as essential ESG risk elements by global investors, empirical evidence on how company size and type relate to privacy protection levels remains limited. (1) Background/Purpose: This study evaluates personal information protection levels across 33 domestic and global companies operating in the Korean market to examine whether company size, revenue scale, service platform type, and domestic versus global status are associated with differences in privacy protection. (2) Methodology/Approach: Using the Privacy Policy Assessment System (개인정보 처리방침 평가제) introduced by the Personal Information Protection Commission of Korea in 2024, the study assessed the publicly available privacy policies of 33 companies across 11 service sectors as of August 1, 2024. Evaluation covered 20 items, 29 indicators, and 41 sub-indicators across three domains: Compliance (적합성), Rights Protection (권리보장), and Security (안전성). Companies were sourced from Rankey.com site rankings. (3) Findings: Domestic companies generally achieved higher compliance rates with Korean privacy laws than global companies. No significant correlation was found between revenue scale and privacy protection levels. Technical protection compliance ranged 30–75% and policy protection ranged 32–75%, indicating wide variance across companies. No company was found to score high on policy protection while scoring low on technical protection, suggesting that meeting policy standards is more difficult than meeting technical standards. (4) Originality/Value: This study provides the first empirical cross-sector evaluation of privacy protection levels in the Korean market using the newly introduced Privacy Policy Assessment System, demonstrating that global company status—not revenue size—is the primary differentiator of privacy compliance, and identifying actionable improvement priorities for policymakers and companies.

References
  1. 신일순 (2016). 개인정보보호 대책의 효과 및 인과관계: 기업 및 개인의 개인정보보호 행동에 대한 실증분석 및 그 시사점. Journal of The Korea Institute of Information Security & Cryptology.
  2. 자본시장 연구원, KOREA CAPITAL MARKET INSTITUTE 2024-14: 금융기관의 사이버보안 위험과 과제.
  3. Giorgio Presidente, Carl Benedikt Frey (2022). The GDPR effect: How data privacy regulation shaped firm performance globally. Centre for Economic Policy Research.
  4. Mert Demirer, Diego J. Jiménez Hernández, Dean Li, Sida Peng (2024). Data, Privacy Laws and Firm Production: Evidence from the GDPR. National Bureau of Economic Research.
  5. Morrow Sodali. (2021). Institutional Investor Survey 2021. http://www.sodali.com
  6. Harvard Law School Forum on Corporate Governance. Directors' Duties in an Evolving Risk and Governance Landscape. https://corpgov.law.harvard.edu/
  7. 랭키닷컴. http://www.rankey.com
  8. 개인정보보호위원회. 개인정보 처리방침 평가제. https://www.pipc.go.kr
Keywords
Personal Information Protection Privacy Policy Assessment ESG Data Privacy Compliance GDPR Cybersecurity Platform Companies Domestic vs. Global Companies Personal Information Protection Act (PIPA) Privacy by Design Corporate Social Responsibility
Details

Authors
Kim, Hui Young Primary Contact
㈜ 씨드젠
How to Cite
Comparison of Personal Information Protection Levels by Company Size and Type: From the Perspective of Privacy Policy Assessment. (2026). ASSIST Business Review, 2(4). https://jnl.ampla.page/abr/article/view/69