New York judge asks whether class action over 33.7 million-user data breach should be heard in Korea
Jurisdiction has emerged as the key issue in a US class-action lawsuit over Coupang’s massive personal data breach.
Judge Ann Donnelly on Tuesday questioned why the case should be heard in New York rather than in South Korea during a preliminary hearing at the US District Court for the Eastern District of New York.
The plaintiffs, represented by South Korean law firm Daeryun and its US partner SJKP, underlined that Coupang Inc. is an American company listed on the New York Stock Exchange and that its leadership exercises influence over the Korean subsidiary.
They also pointed to the US parent company’s report of the breach to the US Securities and Exchange Commission as evidence of its connection to the incident and the US regulatory system.
Coupang’s attorneys from Kirkland & Ellis took the opposite view, noting that Coupang Inc. is a Delaware-incorporated holding company and that Coupang’s Korean business is a separate entity from US parent company Coupang Inc.
As the Korean Coupang is an e-commerce platform doing business in Korea for Korean people, they said bringing the legal dispute to a US court would be a waste of judicial time and resources.
Coupang’s attorneys added that multiple Korean authorities have already been investigating the incident, arguing that the plaintiffs were effectively seeking a more favorable forum and choice of law.
According to the plaintiffs’ side, about 7,800 people have indicated their intention to participate in the class-action lawsuit so far. The suit is seeking $5 million in damages from Coupang Inc. and its founder and chair Bom Kim.
The judge ordered both sides to submit additional written arguments by Oct. 6, after which she is expected to decide whether further proceedings will be scheduled. The judge could dismiss the suit on the lack of jurisdictional grounds.
In November last year, Coupang announced that the names, contact information, delivery addresses and order data of approximately 33.7 million users had been exposed.








