South Korea's Personal Information Protection Commission fined Bithumb 210 million won (about $135,700) for illegally transferring user personal data overseas, the regulator announced Thursday.
The watchdog's investigation found that Bithumb moved user information across borders without meeting the country's data transfer rules. The commission voted to impose the penalty and order corrective measures in a plenary session Wednesday.
Bithumb, one of South Korea's largest crypto exchanges, has faced regulatory scrutiny before. The exchange operates in a jurisdiction where data residency is tightly controlled—personal information tied to financial accounts and identity verification typically cannot leave the country without explicit legal grounds or user consent.
The size of the fine is modest relative to Bithumb's scale, but the underlying violation carries weight in Seoul's regulatory climate. South Korea treats exchange compliance with data protection law as a core licensing requirement. Enforcement has tightened across the sector as regulators work to close gaps between crypto platforms and traditional finance safeguards.
The regulator did not publicly detail what corrective measures Bithumb must take, though such orders typically require the company to audit data flows, implement technical controls to keep personal information domestic, and report back to the commission on remediation steps.
Bithumb did not immediately respond to requests for comment on the fine or remediation timeline.