Privacy & Data Protection · South Korea
Personal Information Protection Act
South Korea's comprehensive data protection law, enforced by an independent regulator with strong investigative and penalty powers. A 2026 amendment significantly raises maximum penalties and formalises board-level accountability for privacy.
REGULATORPersonal Information Protection Commission (PIPC)
REGIONSouth Korea
EFFECTIVE2011, with major amendments taking effect September 2023 and September 2026
Who it applies to
- Any personal information controller processing data in South Korea
- Online and offline businesses, following the 2023 unification of previously separate rules
- Organisations transferring personal data outside South Korea
Key requirements
- Lawful basis and purpose-specific consent for processing
- Board-approved appointment of a Chief Privacy Officer at qualifying organisations
- Breach notification covering loss, theft, leakage, forgery or damage
- Rules governing automated decision-making and profiling
- Restrictions and safeguards on cross-border data transfers
Maximum penaltyAdministrative penalties of up to 10% of relevant revenue in aggravated cases (raised from 3% under the 2026 amendment)
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates PIPA compliance
Continuous monitoring, evidence and reporting for PIPA — alongside every other framework you need to satisfy.