Praeferre/Frameworks/PIPA
Privacy & Data Protection · South Korea

Personal Information Protection Act

South Korea's comprehensive data protection law, enforced by an independent regulator with strong investigative and penalty powers. A 2026 amendment significantly raises maximum penalties and formalises board-level accountability for privacy.

REGULATORPersonal Information Protection Commission (PIPC) REGIONSouth Korea EFFECTIVE2011, with major amendments taking effect September 2023 and September 2026

Who it applies to

  • Any personal information controller processing data in South Korea
  • Online and offline businesses, following the 2023 unification of previously separate rules
  • Organisations transferring personal data outside South Korea

Key requirements

  • Lawful basis and purpose-specific consent for processing
  • Board-approved appointment of a Chief Privacy Officer at qualifying organisations
  • Breach notification covering loss, theft, leakage, forgery or damage
  • Rules governing automated decision-making and profiling
  • Restrictions and safeguards on cross-border data transfers

Maximum penaltyAdministrative penalties of up to 10% of relevant revenue in aggravated cases (raised from 3% under the 2026 amendment)

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates PIPA compliance

Continuous monitoring, evidence and reporting for PIPA — alongside every other framework you need to satisfy.