Skip to content
GlanceDeskJurisdiction

Home › Law library › PIPA

KR

PIPA

Personal Information Protection Act (Republic of Korea)

Sourced. Last verified 9 October 2026

South Korea Privacy

Status
In force; major overhaul in force 15 Sep 2023. Domestic representative amendment in force 2 Oct 2025. 2026 amendment (promulgated 10 Mar 2026) largely in force from 11 Sep 2026; mandatory ISMS-P certification for major controllers from 1 Jul 2027.
Who it applies to
Anyone processing personal information of people in Korea. The PIPC's April 2024 guidance says foreign firms are covered if they target Korean users, significantly affect Korean data subjects, or have a business presence in Korea.
Size thresholds
No general size threshold. Domestic representative needed for foreign firms with no Korean office that have KRW 1 trillion+ total revenue, or data of 1 million+ Korean users on average (last 3 months of the prior year), or a PIPC request.
Regulator
Personal Information Protection Commission (PIPC); breach reports via KISA
Breach or incident reporting
Notify affected individuals within 72 hours of becoming aware. Report to the PIPC or KISA within 72 hours if 1,000+ people, sensitive or unique ID data, or outside hacking is involved. From 11 Sep 2026 notice also covers possible breaches and forgery or alteration (e.g. ransomware).
Deadline to answer personal data requests
Being verified
Data protection officer
Every controller must designate a Chief Privacy Officer (CPO). Larger controllers need a qualified CPO with set experience. From 11 Sep 2026 certain controllers need board approval and a PIPC filing when appointing or changing the CPO.
Local representative
Foreign firms meeting the thresholds must appoint a domestic representative and list it in their privacy policy. Since 2 Oct 2025, if they have a Korean entity they set up or control, that entity must be the representative.
Sending data abroad
Consent, or since 2023: a law or treaty, a contract need disclosed in the privacy policy, PIPC-recognised certification of the recipient, or a PIPC adequacy decision (EU recognised 3 Sep 2025). PIPC can order transfers to stop.
Cookies and consent
Cookies, logs and IP addresses can be personal data if they easily identify someone. Consent must be separate for each purpose and data type; guardian consent for under-14s; marketing needs explicit consent.
Maximum penalty
Fines up to 3% of total revenue (excluding unrelated revenue). From 11 Sep 2026, up to 10% for repeated, intentional or grossly negligent breaches, very large breaches, or ignoring PIPC orders. Punitive damages up to 5x actual losses.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

2 Oct 2025: local entity must act as domestic representative. 3 Sep 2025: EU adequacy recognised. 2026 amendment (10 Mar 2026; most from 11 Sep 2026): 10% revenue fines, CEO accountability, CPO board approval, wider breach notice; ISMS-P required for major controllers from 1 Jul 2027.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].