The Korean Bar Association is turning the Tving leak into a legal reform case. It says victim relief must come with stronger tools, not just damage control. It also argues that privacy protection now needs a structural reset.
The Korean Bar Association issued a statement on Sept. 7 and said it was deeply concerned about the Tving personal data leak. The group called for system-level reform, not a narrow cleanup. That shift matters because the case now sits at the point where privacy, liability and public trust meet.
The Korean Bar Association said victims need stronger legal tools. It specifically backed the introduction of the so-called “three livelihood laws”: discovery, punitive damages and class action. It also called for a thorough fact-finding review, plus scrutiny of Tving and CJ Group, which it said should face oversight questions as well.

Why the leak is being treated as more than a single incident
The scale is already severe. A joint public-private investigation team under the Ministry of Science and ICT said on Sept. 3 that information from about 39.54 million Tving accounts had been exposed. The leaked data included IDs, passwords, names, dates of birth, mobile numbers, email addresses and CI data among 20 categories across 70 types. That combination turns the case into a compound privacy breach, not a simple account problem.
What this means for users now
The Bar Association warned that victims may face long-term risk from tailored voice phishing and identity theft. It also framed personal data self-determination as a constitutional right, which changes the case from a technical security failure into a rights issue. In that sense, the Tving leak is now a test of whether privacy law can move from reacting after harm to preventing the next one.