Home › Law library › PIPA
KR
PIPA
Personal Information Protection Act (Republic of Korea)
Sourced. Last verified 9 October 2026
South Korea Privacy
- Status
- In force; major overhaul in force 15 Sep 2023. Domestic representative amendment in force 2 Oct 2025. 2026 amendment (promulgated 10 Mar 2026) largely in force from 11 Sep 2026; mandatory ISMS-P certification for major controllers from 1 Jul 2027.
- Who it applies to
- Anyone processing personal information of people in Korea. The PIPC's April 2024 guidance says foreign firms are covered if they target Korean users, significantly affect Korean data subjects, or have a business presence in Korea.
- Size thresholds
- No general size threshold. Domestic representative needed for foreign firms with no Korean office that have KRW 1 trillion+ total revenue, or data of 1 million+ Korean users on average (last 3 months of the prior year), or a PIPC request.
- Regulator
- Personal Information Protection Commission (PIPC); breach reports via KISA
- Breach or incident reporting
- Notify affected individuals within 72 hours of becoming aware. Report to the PIPC or KISA within 72 hours if 1,000+ people, sensitive or unique ID data, or outside hacking is involved. From 11 Sep 2026 notice also covers possible breaches and forgery or alteration (e.g. ransomware).
- Deadline to answer personal data requests
- Being verified
- Data protection officer
- Every controller must designate a Chief Privacy Officer (CPO). Larger controllers need a qualified CPO with set experience. From 11 Sep 2026 certain controllers need board approval and a PIPC filing when appointing or changing the CPO.
- Local representative
- Foreign firms meeting the thresholds must appoint a domestic representative and list it in their privacy policy. Since 2 Oct 2025, if they have a Korean entity they set up or control, that entity must be the representative.
- Sending data abroad
- Consent, or since 2023: a law or treaty, a contract need disclosed in the privacy policy, PIPC-recognised certification of the recipient, or a PIPC adequacy decision (EU recognised 3 Sep 2025). PIPC can order transfers to stop.
- Cookies and consent
- Cookies, logs and IP addresses can be personal data if they easily identify someone. Consent must be separate for each purpose and data type; guardian consent for under-14s; marketing needs explicit consent.
- Maximum penalty
- Fines up to 3% of total revenue (excluding unrelated revenue). From 11 Sep 2026, up to 10% for repeated, intentional or grossly negligent breaches, very large breaches, or ignoring PIPC orders. Punitive damages up to 5x actual losses.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Get separate, purpose-specific consent or rely on another listed legal basis
- Designate a CPO and, if applicable, have the board approve and file the appointment
- Notify affected users within 72 hours of a breach and report qualifying breaches to PIPC/KISA
- Appoint a Korean representative if you meet the thresholds, using your local entity if you have one
- Disclose overseas transfers in your privacy policy and use a valid transfer basis
- Get legal guardian consent before processing data of children under 14
Recent changes
2 Oct 2025: local entity must act as domestic representative. 3 Sep 2025: EU adequacy recognised. 2026 amendment (10 Mar 2026; most from 11 Sep 2026): 10% revenue fines, CEO accountability, CPO board approval, wider breach notice; ISMS-P required for major controllers from 1 Jul 2027.
Sources
- Primary source: https://www.pipc.go.kr/eng/user/lgp/law/lawDetail.do
- Second source: https://www.dlapiperdataprotection.com/index.html?t=law&c=KR
- Regulator: Personal Information Protection Commission (PIPC); breach reports via KISA
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].