South Korea PIPA
Amended South Korea · In force Sep 30, 2011 · next deadline Jul 1, 2027 (in 9 months)
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Korea's comprehensive privacy law, with consent-centric processing, breach notification, cross-border transfer rules, automated decision rights (since 2024), and revenue-based penalty surcharges. The 2026 amendment, effective 11 September 2026, raises the maximum fine to 10% of total revenue for aggravated cases, makes the CEO the ultimate responsible person, requires notice when a breach is merely possible, and makes ISMS-P certification mandatory for certain entities from 1 July 2027.
- Who it applies to
- All personal information controllers (public and private) processing personal information of people in Korea; foreign controllers above set thresholds must designate a domestic representative. 10% fines apply to repeat intentional or grossly negligent violations within 3 years, intentional or grossly negligent conduct affecting 10 million+ people, or a breach after ignoring a PIPC corrective order.
- Penalties
- Before 11 Sept 2026: penalty surcharge up to 3% of total revenue (excluding revenue unrelated to the violation), in place since 2023. From 11 Sept 2026: up to 10% of total revenue in aggravated cases, with reductions for qualifying privacy investment. Criminal penalties also apply.
- Enforced by
- Personal Information Protection Commission (PIPC)
- Official name
- Personal Information Protection Act (as amended by Act No. 21445, 2026)
- Citation
- Act No. 10465 (2011); latest amendment Act No. 21445 (promulgated 10 Mar 2026)
- Topics
- privacy, breach-notification, biometrics, data-residency
Research notes
The National Assembly passed the amendment on 12 Feb 2026 and the PIPC announced promulgation for 10 Mar 2026 with effect from 11 Sep 2026. Fact-check 2026-09-22 confirmed on law.go.kr: 개인정보 보호법 [시행 2026. 9. 11.] [법률 제21445호, 2026. 3. 10., 일부개정]; Addendum Art 1 sets effect 6 months after promulgation, except the Art 32-2(1) proviso (mandatory certification for controllers meeting Presidential Decree criteria on revenue and processing scale) and Art 75(2)15, which apply from 1 July 2027; Art 64-2(2) sets the 10% of total revenue cap (KRW 5 billion where revenue cannot be calculated) for repeat intentional or grossly negligent violations within 3 years, violations affecting 10 million+ people, or breaches after ignoring a corrective order. The 3% pre-existing cap comes from the 2023 amendment. The 2011 enactment and effective dates come from general knowledge. The ISMS-P scope criteria are set by decree.
Related
Questions about South Korea PIPA
- What are the South Korea PIPA compliance deadlines?
- Mar 10, 2026: 2026 PIPA amendment promulgated (Act No. 21445). Sep 11, 2026: 2026 PIPA amendments take effect. Jul 1, 2027: Mandatory ISMS-P certification.
- When does South Korea PIPA take effect?
- South Korea PIPA took effect on Sep 30, 2011. The next milestone is Jul 1, 2027: Mandatory ISMS-P certification.
- Who does South Korea PIPA apply to?
- All personal information controllers (public and private) processing personal information of people in Korea; foreign controllers above set thresholds must designate a domestic representative. 10% fines apply to repeat intentional or grossly negligent violations within 3 years, intentional or grossly negligent conduct affecting 10 million+ people, or a breach after ignoring a PIPC corrective order.
- What are the penalties under South Korea PIPA?
- Before 11 Sept 2026: penalty surcharge up to 3% of total revenue (excluding revenue unrelated to the violation), in place since 2023. From 11 Sept 2026: up to 10% of total revenue in aggravated cases, with reductions for qualifying privacy investment. Criminal penalties also apply.