South Korea’s privacy regulator has fined crypto exchange Bithumb 210 million won ($136,000) after finding violations linked to the transfer of user data to overseas platforms.
The decision was announced by the Personal Information Protection Commission (PIPC) following its June 24 plenary meeting. Alongside the fine, the regulator ordered Bithumb to overhaul its data transfer procedures and ensure future overseas transfers comply with the country’s Personal Information Protection Act.
Bithumb has been fined approximately $136,$000 by South Korean regulators for sharing user data internationally without consent. This highlights increasing scrutiny of crypto exchanges regarding data privacy and compliance #SouthKorea pic.twitter.com/CIPTAzqRgW
— John Morgan (@johnmorganFL) June 25, 2026
Why did regulators investigate Bithumb?
The investigation started from concerns raised during a 2025 parliamentary audit over Bithumb’s order-book sharing arrangements with foreign crypto exchanges.
Order-book sharing allows exchanges to combine buy and sell orders to improve liquidity and trading efficiency. However, regulators found that between September and November 2025, Bithumb transferred user-related data from its Tether (USDT) market to systems operated by overseas exchange BingX.
According to the PIPC, users had agreed to overseas data transfers involving another platform, Stellar, but the information was ultimately sent to a different recipient. The transferred data included member identification numbers and order-related information.
The regulator concluded that the actual recipient of the data differed from what users had approved, creating a breach of South Korea’s privacy rules.
What other data transfers were flagged?
The PIPC also reviewed Bithumb’s virtual asset transfer operations involving 13 overseas exchanges.
During those transfers, the exchange shared personal information such as names, wallet addresses, and, in some cases, dates of birth. The data was used to meet anti-money laundering (AML) requirements and verify transaction participants.
While the regulator acknowledged that some personal information may be necessary for AML compliance, it stressed that cross-border transfers still require clear user consent and proper disclosure.
The commission said overseas transfers directly affect a user’s right to control personal information and that crypto firms must follow all legal notification and consent requirements before moving data abroad.
Privacy rules add to growing pressure on crypto exchanges
Bithumb was previously hit with a 36.8 billion won penalty tied to AML compliance failures, including shortcomings in customer verification, transaction monitoring, and dealings with unregistered foreign virtual asset service providers.
At the same time, South Korea is advancing stricter oversight of cross-border crypto activity through proposed AML reporting rules and plans to share crypto transaction data with 48 countries under the OECD Crypto-Asset Reporting Framework.
Alongside the Bithumb ruling, the PIPC released new blockchain privacy guidelines, warning that public and permanent blockchain records can create unique challenges for personal data protection.
The regulator said blockchain firms should incorporate privacy safeguards from the earliest stages of development and pledged continued enforcement against violations involving personal information in digital asset services.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.























































































