Skip to content

South Korea PIPA

Amended South Korea · In force Sep 30, 2011 · next deadline Jul 1, 2027 (in 9 months)

Deadlines

DateWhat happens
Mar 10, 20262026 PIPA amendment promulgated (Act No. 21445)7 months ago
Sep 11, 20262026 PIPA amendments take effect13 days ago
Jul 1, 2027Mandatory ISMS-P certificationin 9 months

Summaries for reference, not legal advice. Check the official text.

What it does

Korea's comprehensive privacy law, with consent-centric processing, breach notification, cross-border transfer rules, automated decision rights (since 2024), and revenue-based penalty surcharges. The 2026 amendment, effective 11 September 2026, raises the maximum fine to 10% of total revenue for aggravated cases, makes the CEO the ultimate responsible person, requires notice when a breach is merely possible, and makes ISMS-P certification mandatory for certain entities from 1 July 2027.

Who it applies to
All personal information controllers (public and private) processing personal information of people in Korea; foreign controllers above set thresholds must designate a domestic representative. 10% fines apply to repeat intentional or grossly negligent violations within 3 years, intentional or grossly negligent conduct affecting 10 million+ people, or a breach after ignoring a PIPC corrective order.
Penalties
Before 11 Sept 2026: penalty surcharge up to 3% of total revenue (excluding revenue unrelated to the violation), in place since 2023. From 11 Sept 2026: up to 10% of total revenue in aggravated cases, with reductions for qualifying privacy investment. Criminal penalties also apply.
Enforced by
Personal Information Protection Commission (PIPC)
Official name
Personal Information Protection Act (as amended by Act No. 21445, 2026)
Citation
Act No. 10465 (2011); latest amendment Act No. 21445 (promulgated 10 Mar 2026)
Topics
privacy, breach-notification, biometrics, data-residency
Verified 2026-09-22 pipc.go.kr hunton.com iapp.org yulchon.com
Research notes

The National Assembly passed the amendment on 12 Feb 2026 and the PIPC announced promulgation for 10 Mar 2026 with effect from 11 Sep 2026. Fact-check 2026-09-22 confirmed on law.go.kr: 개인정보 보호법 [시행 2026. 9. 11.] [법률 제21445호, 2026. 3. 10., 일부개정]; Addendum Art 1 sets effect 6 months after promulgation, except the Art 32-2(1) proviso (mandatory certification for controllers meeting Presidential Decree criteria on revenue and processing scale) and Art 75(2)15, which apply from 1 July 2027; Art 64-2(2) sets the 10% of total revenue cap (KRW 5 billion where revenue cannot be calculated) for repeat intentional or grossly negligent violations within 3 years, violations affecting 10 million+ people, or breaches after ignoring a corrective order. The 3% pre-existing cap comes from the 2023 amendment. The 2011 enactment and effective dates come from general knowledge. The ISMS-P scope criteria are set by decree.

Related

Questions about South Korea PIPA
What are the South Korea PIPA compliance deadlines?
Mar 10, 2026: 2026 PIPA amendment promulgated (Act No. 21445). Sep 11, 2026: 2026 PIPA amendments take effect. Jul 1, 2027: Mandatory ISMS-P certification.
When does South Korea PIPA take effect?
South Korea PIPA took effect on Sep 30, 2011. The next milestone is Jul 1, 2027: Mandatory ISMS-P certification.
Who does South Korea PIPA apply to?
All personal information controllers (public and private) processing personal information of people in Korea; foreign controllers above set thresholds must designate a domestic representative. 10% fines apply to repeat intentional or grossly negligent violations within 3 years, intentional or grossly negligent conduct affecting 10 million+ people, or a breach after ignoring a PIPC corrective order.
What are the penalties under South Korea PIPA?
Before 11 Sept 2026: penalty surcharge up to 3% of total revenue (excluding revenue unrelated to the violation), in place since 2023. From 11 Sept 2026: up to 10% of total revenue in aggravated cases, with reductions for qualifying privacy investment. Criminal penalties also apply.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.