← All case files
pending deployment software · KR · cross

South Korea's first AI privacy sanction: the PIPC fined Scatter Lab KRW 103.3 million for training the Iruda chatbot on 9.4 billion KakaoTalk messages

On 28 April 2021 the Republic of Korea's Personal Information Protection Commission fined Scatter Lab KRW 103.3 million for eight violations of the Personal Information Protection Act — the first time it sanctioned an AI company for indiscriminate personal-information processing. The regulator found Scatter Lab had used around 9.4 billion KakaoTalk messages from 600,000 users of its dating-advice apps to train the Iruda (Lee Luda) chatbot without proper consent. The fine, the eight violations, the KRW 55.5m / 47.8m split and the 9.4 billion-message / 600,000-user training-data scale are quoted verbatim from the PIPC's own primary record (press release and official decision document), corroborated by independent secondary reporting.

MetricBeforeAfter
PIPC fined Scatter Lab KRW 103.3 million (USD ~92,900) for eight violations of the Personal Information Protection Act on 28 April 2021, its first sanction of an AI company for indiscriminate personal-information processing (PIPC press release and official decision document, Tier 1; corroborated by Future of Privacy Forum, The Register and Digital Policy Alert)
The KRW 103.3 million total broke down into a penalty surcharge of KRW 55.5 million and an administrative fine of KRW 47.8 million (PIPC official decision table, Tier 1; The Register; Byline Network, contemporaneous Korean tech press)
Scatter Lab used around 9.4 billion KakaoTalk messages from 600,000 users of its Text At and Science of Love apps to train the Iruda model, without deleting or anonymising the data (PIPC official decision document, native HWP source, Tier 1; corroborated by Future of Privacy Forum and The Register)
The regulator also found Scatter Lab collected the personal information of over 200,000 children under the age of 14 without parental consent, and had posted 1,431 KakaoTalk messages revealing 22 names and 34 locations to GitHub (Future of Privacy Forum; The Register)

Verification status: PENDING (graduated by the checker; awaiting the owner’s final green sign-off) — all three critical figures are now anchored on the PIPC’s own primary record (its 28 April 2021 press release and the official decision attachment, both fetched and archived this session, Tier 1): the KRW 103.3 million fine, the “first AI-company sanction” framing and the eight PIPA violations; the KRW 55.5m / 47.8m split, stated verbatim in the official decision table; and the 9.4 billion-message / 600,000-user training-data scale, recovered verbatim from the same decision attachment in its native HWP format (the PDF render had dropped those numerals through a font subset). Each is also corroborated by independent Tier-2 reporting. The weakest load-bearing sourcing is the two supporting details that rest on a single source each: the GitHub disclosure (1,431 messages revealing 22 names and 34 locations) and the “750,000 users in under a month” figure, both from the Future of Privacy Forum only; each is flagged where it appears.

The problem

Scatter Lab, a Seoul start-up, launched Iruda (Lee Luda) in December 2020: a Korean-language conversational chatbot that assumed the persona of a 20-year-old college student and “attracted more than 750,000 users on Facebook Messenger less than a month after release” (source). Within weeks the chatbot drew complaints for lewd, homophobic and discriminatory speech, and, more consequentially for the regulator, users noticed it repeating fragments of real private conversations; media reports prompted the Personal Information Protection Commission to open an official investigation on 12 January 2021 (source). The Register’s account records that the bot “had a proclivity towards lewd and homophobic speech, and she also leaked personal data” (source).

What was built

The chatbot was not the data problem; the pipeline behind it was. Scatter Lab had trained Iruda on messages harvested by two of its other products, the dating-advice apps Text At and Science of Love: “around 9.4 billion KakaoTalk messages from 600,000 users were employed in training algorithms to develop the ‘Iruda’ AI model, without any efforts by ScatterLab to delete or” anonymise the data (source). The Register described the same reuse independently, reporting that the company “illegally harvested data from 9.4 billion conversations conducted by 600,000 users of its other apps, ‘Science of Love’ and ‘Text At’” (source). The PIPC’s own decision states the scale verbatim, that Scatter Lab “약 60만 명에 달하는 이용자의 카카오톡 대화문장 94억여 건을 이용하였고” (used approximately 9.4 billion-plus KakaoTalk conversation sentences from approximately 600,000 users) without deleting or encrypting the personal information they contained; the numerals are text-extractable from the native HWP source of the decision attachment, though the fileSn=2 PDF render of the same document had dropped those digits through a font subset (source). Scatter Lab also exposed part of that data publicly: it posted training material to “the code sharing and collaboration platform Github from October 2019 to January 2021, which included 1,431 KakaoTalk messages revealing 22 names (excluding last names), 34 locations (excluding districts and neighborhoods), gender, and relationships” — a detail carried here by a single source (source).

The outcome

On 28 April 2021 the PIPC imposed “a fine of KRW 103.3 million (USD 92,900) on ScatterLab, Inc., developer of the chatbot ‘Iruda,’ for eight violations of the Personal Information Protection Act (PIPA),” and the commission stated that “this is the first time PIPC sanctioned an AI technology company for indiscriminate personal information processing” (source). This is confirmed by the PIPC’s own primary record: the commission’s 28 April 2021 press release states that it “총 1억 330만원의 과징금과 과태료 등을 부과했다” (imposed a total of KRW 103.3 million in penalty surcharge and administrative fines) and that this “인공지능(AI) 기술 기업의 무분별한 개인정보 처리를 제재한 첫 사례” (is the first case sanctioning an AI technology company for indiscriminate personal-information processing) (source). The official decision attachment enumerates the eight violations and records the total of KRW 10,330만원 (103.3 million) in its 참고1 행정처분 (administrative-disposition) table (source). The Register reported the same sanction independently, noting Scatter Lab “was ordered to pay 103.3 million won (US$93k) for not obtaining proper user permissions” (source), and the Digital Policy Alert official-record entry records the same total, the 28 April 2021 decision date, the PIPC as the authority, and the eight-violation count (source).

The total split into two components. The PIPC’s own decision table states the breakdown verbatim in its 합계 (total) row: “과징금 5,550만원 · 과태료 4,780만원 · 총 10,330만원” (penalty surcharge KRW 55.5 million, administrative fine KRW 47.8 million, KRW 103.3 million in total) (source). The Register reports the same split independently, that “the 103.3 million won charges break down to a penalty surcharge of 55.5 million won (US$50k) and an administrative fine of 47.8 million won (US$43k)” (source), and the contemporaneous Korean tech-press outlet Byline Network reported the same split from the PIPC decision, that the commission imposed “a penalty surcharge of KRW 55.5 million and an administrative fine of KRW 47.8 million, KRW 103.3 million in total” (translating the Korean “과징금 5550만원과 과태료 4780만원 등 총 1억330만원”) (source). The decision also reached the youngest users: the commission found Scatter Lab had collected “personal information of over 200,000 children under the age of 14 without parental consent in the development and operation of its app services” (source), a figure The Register corroborates in reporting that the company “did not obtain parental consent before allowing 200,000 users under the age of 14 to join Science of Love and Text At” (source). The commission framed the principle it was enforcing in plain terms, stating that the case “has made clear that companies are prohibited from indiscriminately using personal information collected for specific services without clearly informing and obtaining explicit consent from data subjects” (source).

How this was verified

  • Method. Independent validation against the public record. Every figure is quoted verbatim from a source fetched this session and archived to the Wayback Machine. The headline fine (KRW 103.3 million), the “first AI-company sanction” framing and the eight PIPA violations are now anchored on the PIPC’s own primary record — its 28 April 2021 press release (Tier 1) and the official decision attachment (Tier 1), whose 참고1 행정처분 table also states the KRW 55.5m surcharge / KRW 47.8m administrative-fine split verbatim — and are additionally corroborated by two independent Tier-2 reports (the Future of Privacy Forum’s analysis quoting the PIPC decision, and The Register’s independent report), with the Digital Policy Alert official-record entry corroborating the fine amount, the 28 April 2021 date and the eight-violation count. The 9.4 billion-message / 600,000-user training-data scale is now also anchored on the same PIPC primary (Tier 1): its numerals are not text-extractable from the fileSn=2 PDF render because that document’s font subset dropped the digits, but they are present verbatim in the fileSn=1 native HWP source of the same decision attachment (“약 60만 명에 달하는 이용자의 카카오톡 대화문장 94억여 건”), recovered by parsing the HWP OLE/CFB container and inflating its BodyText/Section0 stream; it remains corroborated by two independent Tier-2 reports (FPF and The Register). The over-200,000 under-14 figure is carried by both FPF and The Register.
  • Date. Researched and drafted 3 September 2026; the fine split corroborated with a second source (Byline Network) 3 September 2026; the PIPC primary (press release, official decision PDF and native HWP) retrieved and archived 3 September 2026.
  • Weakest load-bearing sources. Two supporting details rest on a single source each: the GitHub disclosure (1,431 messages revealing 22 names and 34 locations) and the “750,000 users in under a month” figure, both from the Future of Privacy Forum only. Both are attributed in the prose. All three critical figures (the fine total, the 55.5m/47.8m split and the 9.4bn/600,000 training-data scale) are now anchored on the PIPC’s own primary record with the numerals text-extractable verbatim. No party was contacted to confirm any figure.

Sources

  1. Future of Privacy Forum (Dooho Lim / FPF) · “South Korea: The First Case Where the Personal Information Protection Act was Applied to an AI System” · 2021 · https://fpf.org/blog/south-korea-the-first-case-where-the-personal-information-protection-act-was-applied-to-an-ai-system/Tier 2 (independent privacy think-tank analysis quoting the PIPC decision; Wayback 20260816023205)
  2. The Register (Laura Dobberstein) · “Korean app-maker Scatter Lab fined for using private data to create homophobic and lewd chatbot” · 29 April 2021 · https://www.theregister.com/2021/04/29/scatter_lab_fined_for_lewd_chatbot/Tier 2 (independent press; Wayback 20260114162421)
  3. Digital Policy Alert · “Fined Scatterlab Inc for violations of Personal Information Protection Act in developing AI chatbot Iruda” · 28 April 2021 · https://digitalpolicyalert.org/event/12005-fined-scatterlab-inc-for-violations-of-personal-information-protection-act-in-developing-ai-chatbot-irudaTier 2 (independent official-record aggregator; Wayback 20250814170620)
  4. Byline Network (이유지) · “‘이루다’ 개발사 과징금 등 1억원…AI 기업 무단 개인정보 처리 첫 제재” · 28 April 2021 · https://byline.network/2021/04/29-101/Tier 2 (independent Korean tech press reporting the PIPC decision; corroborates the fine split, the total, the “first AI-company sanction” framing and the 9.4bn/600,000 figures; Wayback 20250713110717)
  5. Personal Information Protection Commission (대변인) · “개인정보위, ‘이루다’ 개발사 ㈜스캐터랩에 과징금·과태료 등 제재 처분” (press release) · 28 April 2021 · https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=7298Tier 1 (the regulator’s own primary press release; states the KRW 1억 330만원 / 103.3m total and the “first AI-company sanction” framing verbatim; Wayback 20250430202129)
  6. Personal Information Protection Commission · official decision attachment, “개인정보위, ‘이루다’ 개발사 ㈜스캐터랩에 과징금·과태료 등 제재 처분” (참고1 사업자별 위반사항에 대한 행정처분 + Q&A, PDF) · 28 April 2021 · https://www.pipc.go.kr/np/cmm/fms/FileDown.do?atchFileId=FILE_000000000551859&fileSn=2&fileExtsn=pdf&cnvCnt=Tier 1 (the regulator’s own primary decision document; its 합계 row states 과징금 5,550만원 · 과태료 4,780만원 · 총 10,330만원 and it enumerates the eight violations ①–⑧; Wayback 20260903200516)
  7. Personal Information Protection Commission · official decision attachment, native HWP source (the fileSn=1 sibling of the same FILE_000000000551859 attachment as source 6’s PDF) · 28 April 2021 · https://www.pipc.go.kr/np/cmm/fms/FileDown.do?atchFileId=FILE_000000000551859&fileSn=1&fileExtsn=hwpTier 1 (the regulator’s own primary decision document in its native Hancom format; its BodyText/Section0 stream carries the training-data scale verbatim, “약 60만 명에 달하는 이용자의 카카오톡 대화문장 94억여 건” (600,000 users / 9.4 billion+ messages), which the PDF render dropped through a font subset, plus the 총 1억 330만원 total and the 5,550/4,780/10,330 split; Wayback 20260903202736)

Iruda (Lee Luda) Korean-language conversational AI chatbot

Verification record
Status
pending
Method
Independent validation against the public record. Every figure is quoted verbatim from a source fetched this session and archived to the Wayback Machine. The headline fine (KRW 103.3 million), the 'first AI-company sanction' framing and the eight PIPA violations are anchored on the PIPC's own primary record (its 28 April 2021 press release and the official decision attachment, both Tier 1), whose 참고1 행정처분 table also states the KRW 55.5m surcharge / KRW 47.8m administrative-fine split verbatim; these are additionally corroborated by two independent Tier-2 reports (the Future of Privacy Forum's analysis quoting the PIPC decision, and The Register), with the Digital Policy Alert official-record entry corroborating the fine amount, the 28 April 2021 date and the eight-violation count. The 9.4 billion / 600,000 training-data scale is now also anchored on the same PIPC primary in its native HWP format (Tier 1): the fileSn=2 PDF render dropped those digits through a ToUnicode font subset, but the fileSn=1 HWP sibling of the same decision attachment carries them text-extractable and verbatim in its body-text stream ('약 60만 명에 달하는 이용자의 카카오톡 대화문장 94억여 건'), and it remains corroborated by two independent Tier-2 reports (FPF and The Register). The GitHub disclosure detail (1,431 messages) and the '750,000 users in under a month' figure remain single-source (Future of Privacy Forum) and are flagged in the prose. No confirmation was sought from Scatter Lab; only the regulator's own record and independent reporting are used.
Provider
Scatter Lab Inc. (Seoul), developer of the Iruda / Lee Luda chatbot; sanctioned by the Personal Information Protection Commission (PIPC), Republic of Korea
Client
Personal Information Protection Commission (PIPC), Republic of Korea — enforcing regulator; the subject is Scatter Lab Inc. Honest-negative: no deployer-client exists. · software
Disclosure
named
Questions this file answers
What did Korea's PIPC decide about the Iruda chatbot?

On 28 April 2021 the Personal Information Protection Commission fined Scatter Lab KRW 103.3 million for eight violations of the Personal Information Protection Act. It was the first time the PIPC sanctioned an AI technology company for indiscriminate personal-information processing. The commission found Scatter Lab had used around 9.4 billion KakaoTalk messages from 600,000 users of its Text At and Science of Love apps to train the Iruda model without proper consent.

How much was the fine and how was it split?

The total was KRW 103.3 million (about USD 92,900). It broke down into a penalty surcharge of KRW 55.5 million and an administrative fine of KRW 47.8 million, a split reported by both The Register and the contemporaneous Korean tech-press outlet Byline Network in its account of the PIPC decision.

Why does the case matter?

It was the first application of Korea's Personal Information Protection Act to an AI system. The PIPC treated data collected for one service (dating-advice apps) and reused to train a chatbot as a consent violation, establishing that companies cannot indiscriminately repurpose personal information gathered for a different service to build AI models.