South Korea’s Personal Information Protection Commission has fined the matchmaking company Duo 1.2 billion won — approximately $810,000 — over a breach that exposed the personal information of nearly 430,000 users. The decision was announced on 28 April 2026 and is reported by Global Dating Insights, which is our source for everything that follows.

What was penalised

Per that report, the breach occurred in January 2025, when an employee’s work computer was hacked. The company then failed to notify authorities for three days after discovering it, and South Korean law requires companies to report a possible leak immediately upon discovery. The delay is not incidental to the penalty; it is a named part of it.

We are going to be careful about what we do not say. The published account describes “personal information” and does not itemise it, and we will not characterise categories the source declines to. Nor is there anything here about any other firm: one company, one enforcement action, one jurisdiction.

Why this desk is reading it closely

The interest here is not in what sat on Duo’s server, which the report does not describe, but in what the retainer model asks of a client generally.

A consumer app knows what you typed into a profile. A personal matchmaker, by design, knows considerably more: income, profession, family circumstances, marital history, the shape of your week. That disclosure is not an excess of the service, it is the service. A firm cannot make a considered introduction on material it does not hold, which is why the retainer client hands over a file no dating app asks for.

That file has always been the quiet term in the transaction. What has changed is that in at least one jurisdiction, losing it now carries a published number.

The questions worth asking first

Matchmaking agencies are not a licensed profession, and nobody should read an enforcement action as evidence of routine supervision. Data-protection law reaches them the way it reaches anyone holding personal records — after the fact.

So the questions belong at the front of the relationship. What is retained, and for how long after the engagement closes. Who inside the firm sees it, and whether any of it goes to third parties. Whether deletion on termination is offered, and whether it is written down. A firm that has thought about this will have answers ready; a firm that has not will improvise, and the improvisation is the finding.

Readers should be 18 or over, and terms of this kind — retention included — change quietly, so confirm the current position with any provider in writing before you commit to one.