Article 34 PIPA — dual notification duty to data subjects and PIPC
South Korea's Personal Information Protection Act (PIPA, Law No. 10465) imposes a dual breach notification obligation on personal information controllers (data controllers) under Article 34: a duty to notify affected data subjects promptly, and a separate duty to report qualifying breaches to the Personal Information Protection Commission (PIPC) or the Korean Internet & Security Agency (KISA) within 72 hours of becoming aware of the incident.
Notification to data subjects — Article 34(1) PIPA Personal information controllers must notify affected data subjects "without delay" when personal information has been lost, stolen, leaked, forged, altered, or damaged. This expanded definition of notifiable events — which now includes forgery, alteration, and damage in addition to the traditional loss/theft/leakage triad — took effect with the 2020 and 2023 PIPA amendments. The March 2026 amendment further requires notification to data subjects upon becoming aware of a possibility of a breach, moving the notification trigger to an earlier investigative stage before conclusive confirmation of an incident.
Controllers must notify data subjects unless they do not possess contact information for the affected individuals, in which case alternative measures prescribed in the Enforcement Decree apply (Article 34(1) PIPA). The notification must include: (1) the items of personal information subject to the breach; (2) the time and manner of the breach; (3) measures data subjects can take to minimize harm; (4) the controller's response measures; and (5) contact information for inquiries. The March 2026 amendment adds two new mandatory items: information concerning data subjects' legal rights and available methods of exercising them (including claims for damages and statutory damages arising from the breach), and other matters prescribed by Enforcement Decree.
Reporting to PIPC or KISA — Article 34(4) PIPA and Enforcement Decree Article 39 Personal information controllers must report to the PIPC or KISA within 72 hours of becoming aware of a breach if the scale exceeds thresholds set in the Enforcement Decree. Article 39 of the Enforcement Decree requires reporting when: • Personal information of 1,000 or more data subjects has been lost, stolen, or leaked; • Sensitive information (as defined in PIPA Article 23) or unique identification information (resident registration numbers, passport numbers, driver's license numbers, or foreign registration numbers per PIPA Article 24) has been breached, regardless of the number of affected individuals; or • The breach involves personal information processed by an information and communications service provider designated by Presidential Decree under PIPA Article 39-4 (though the 2023 amendment deleted the special 24-hour rule for online service providers and unified reporting under Article 34).
The 72-hour clock starts when the controller "becomes aware of" the breach. Controllers must provide all available details of the breach when reporting to PIPC/KISA, even if preliminary; the obligation is to report promptly with the information at hand rather than to delay until a full investigation is complete. Foreign operators processing personal information of data subjects in Korea are subject to the same 72-hour reporting requirement under April 2024 PIPC Guidelines on Applying the PIPA to Foreign Business Operators.
Processors (persons entrusted) — Article 26(8) read with Article 34 PIPA PIPA distinguishes between "persons entrusted" (data processors bound by a written contract with the controller) and "personal information handlers" (employees or staff of the controller or processor). The breach notification obligations of Article 34 apply mutatis mutandis to persons entrusted — meaning processors bear the same dual duty to notify data subjects and report to PIPC/KISA when they become aware of a breach in the course of processing on behalf of the controller.
Enforcement and penalties Failure to notify data subjects or report to PIPC/KISA within the statutory timeframe may result in an administrative fine of up to KRW 30 million (approximately USD 22,000). Under the March 2026 amendment, controllers can face administrative penalties of up to 3% of total revenue for breach notification violations; this cap rises to 10% of total revenue for repeat violations involving willful misconduct or gross negligence within a three-year period, violations affecting 10 million or more data subjects, or failure to comply with a PIPC corrective order. Data subjects may claim statutory damages of up to KRW 3 million per individual without proving actual financial harm under PIPA Article 39-2, and punitive damages of up to five times actual damages where the controller violated statutory obligations with intent or gross negligence (PIPA Article 39(3), raised from three times to five times in 2023). The PIPC imposed a KRW 7.5 billion (USD 5.2 million) administrative penalty on Golfzon in May 2024 following a data breach — the largest penalty on a domestic company to that date.
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34 (as amended) Source: Enforcement Decree of the Personal Information Protection Act, Articles 39–40 Source: PIPC Guidelines on Applying the PIPA to Foreign Business Operators (April 2024)
Article 34(1) PIPA — mandatory content items for data subject notifications
South Korea’s Personal Information Protection Act (PIPA) Article 34(1) sets out required content for breach notifications to data subjects. The list of notification items was materially expanded by the March 10, 2026 amendment (Law No. 21445, effective September 11, 2026).
Pre-2026: Five mandatory content items Through September 10, 2026, controllers must notify affected data subjects with at least the following five items:
- Categories of personal information breached (specifically identify data fields, e.g., name, resident registration number, etc.)
- Time and circumstances of the breach (when/how the breach occurred and was discovered)
- Measures data subjects can take to minimize harm
- Controller’s response and remedial actions (what the organization is doing in response)
- Contact information for data subject inquiries (department, phone/email, etc.)
Source: PIPA Article 34(1) as amended through 2020; law.go.kr
Effective September 11, 2026: Amendment adds two new required items From September 11, 2026, notification must also include:
- Information on data subjects’ legal rights and how to exercise them — including rights to claim statutory or punitive damages for breaches (PIPA Articles 39, 39-2, 39-3), judicial/court claim options, and the PIPC’s dispute resolution/mediation process.
- Other matters prescribed by the Enforcement Decree (as of June 2026, no further specifics have been set in the Decree, but implementers should monitor for additional rules before the effective date).
Source: PIPA Article 34(1)(6)-(7), as amended March 10, 2026, effective September 11, 2026; law.go.kr
Notification of the possibility of breach The 2026 amendment also introduces Article 34(2), requiring controllers to notify data subjects upon becoming aware of the possibility of a breach, not only upon confirmation. This must use the same content and delivery standards as Article 34(1). Practical guidance on what constitutes a qualifying "possibility," and additional content under Item 7, are pending in the Enforcement Decree and forthcoming PIPC notices as of June 2026.
Controllers must monitor for further updates in the Enforcement Decree and PIPC guidance before the September 2026 effective date.
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34 (as amended by Law No. 21445, March 10, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Articles 39–40
Article 28(7) PIPA — pseudonymized data exemption from breach notification duties
South Korea's Personal Information Protection Act (PIPA) Article 34 generally imposes dual breach notification duties on personal information controllers: a duty to notify affected data subjects and a duty to report qualifying breaches to regulatory authorities. However, Article 28(7) PIPA expressly exempts breaches of pseudonymized data (processed under Article 28-2 or 28-3 for statistical, scientific research, or archiving purposes) from these notification duties.
Legal basis and recent amendment As amended by Law No. 21445 (March 10, 2026), effective September 11, 2026, Article 28(7) now provides that, when conditions are met, “Articles 20, 20-2, 27, 34(1), 34(2), 35, 35-2, 36, and 37 shall not apply” to pseudonymized personal information processed for the permitted purposes under Article 28-2 or 28-3. The addition of Article 34(2) (the new 'possibility of breach' notification trigger) to the exemption is a material change introduced by the 2026 amendment. Previously, only Article 34(1) was referenced in the exemption. This means the pseudonymized data exemption now applies to both confirmed breaches (Article 34(1)) and situations where there is just a 'possibility' of breach (Article 34(2)).
Definitions and requirements Under PIPA Article 2(1-c), "pseudonymized information" is information that cannot identify a specific individual without separately held additional information. Legal and technical safeguards for pseudonymization—including separation of linkage keys, restriction against re-identification, and record-keeping—are detailed in Articles 28-2 (and, for joint research or cross-institution collaboration, Article 28-3). The exemption only applies if the pseudonymized data is processed strictly for statistical, scientific research, or archiving in the public interest, and with all regulatory safeguards in place at the time of the breach.
Scope and limitations of the exemption The Article 28(7) exemption is specific and conditional:
- It does not apply to non-pseudonymized personal information or to pseudonymized data processed for any purpose outside Article 28-2 or 28-3.
- If both pseudonymized and non-pseudonymized data are implicated in the same incident, full notification duties apply regarding the non-pseudonymized data.
- If linkage keys or technical controls for pseudonymized data are compromised in a way that allows re-identification, the exemption cannot be safely relied upon.
The legislative intent is to encourage safe, public-benefit uses of pseudonymized data by removing burdensome breach notification requirements where formal safeguards minimize the risk to individuals. However, burden of proof rests with the controller to demonstrate that all statutory conditions for exemption were satisfied at the time of the incident.
Regulatory guidance and context Korean regulators have not issued detailed new guidance as of June 2026 interpreting the operation of the Article 34(2) exemption trigger in the pseudonymized-data context. Conservative practice remains to ensure fulfillment of every pseudonymization safeguard in Articles 28-2/28-3 before relying on the exemption. As noted by the European Data Protection Board, the adequacy of the pseudonymization regime—especially around re-identification risk—remains under international scrutiny.
Update and effective date note
- Material update: As of September 11, 2026, the statutory exemption in Article 28(7) covers both Article 34(1) (confirmed breach) and Article 34(2) (possibility of breach), per Law No. 21445 (March 10, 2026). Practitioners should verify citation and exemption scope for incidents after this effective date.
Source: Personal Information Protection Act (PIPA), Law No. 10465, as amended by Law No. 21445, Article 28(7) (effective September 11, 2026) Source: European Data Protection Board Opinion 32/2021 on the European Commission Draft Implementing Decision on the adequate protection of personal data by the Republic of Korea (adopted September 24, 2021), paras. 108–111
Article 34(5) PIPA — three-year breach recordkeeping obligation and Enforcement Decree content requirements
South Korea's Personal Information Protection Act (PIPA) Article 34(5) imposes a statutory recordkeeping obligation on personal information controllers who experience a personal information breach. Controllers must create and maintain records of every breach incident for a minimum of three years from the date of the breach, regardless of whether the breach triggered the notification-to-data-subjects duty under Article 34(1) or the regulatory-reporting duty to the Personal Information Protection Commission (PIPC) or Korean Internet & Security Agency (KISA) under Article 34(4). This recordkeeping obligation is independent and universal: it applies to all breaches, including those below the 1,000-individual reporting threshold in Enforcement Decree Article 39, those involving only non-sensitive personal information, and those for which the controller invoked the pseudonymized-data exemption under Article 28(7) PIPA.
Statutory text — Article 34(5) PIPA Article 34(5) PIPA (as amended by Law No. 19234, March 12, 2026, effective September 11, 2026) provides:
> "A personal information controller shall prepare and keep a record of cases of the leakage, etc. of personal information pursuant to the conditions as prescribed by Presidential Decree."
The March 2026 amendment did not change the substance of Article 34(5), but it renumbered the provision (previously Article 34(4) before the insertion of the new "possibility of a breach" notification trigger). The "conditions as prescribed by Presidential Decree" refers to the content and retention-period requirements set forth in Enforcement Decree Article 41.
Enforcement Decree Article 41 — mandatory record content Enforcement Decree Article 41 (Preparation and Retention of Records on Leakage, etc. of Personal Information) prescribes seven mandatory content items that controllers must include in breach records:
- Scope and scale of the breach — the categories of personal information subject to the breach (e.g., name, resident registration number, email address, payment card number) and the number of affected data subjects, broken down by category where feasible;
- Circumstances of the breach — the date and time the breach occurred or was discovered, the attack vector or incident cause (e.g., unauthorized external access, employee error, system misconfiguration, malware infection), and the location or system component affected;
- Measures taken to notify affected data subjects — the method and timing of data-subject notification under Article 34(1), the content of the notification, and evidence of delivery (e.g., email transmission logs, SMS gateway receipts, postal mail tracking). If data-subject notification was not required (e.g., because the breach fell below actionable thresholds or the controller lacked contact information and used alternative publication methods), the record must document the legal basis for non-notification or the alternative measures employed under Enforcement Decree Article 40;
- Measures taken to report to PIPC or KISA — the date and time of regulatory reporting under Article 34(4), the method of submission (controllers report via the KISA portal at https://privacy.kisa.or.kr), and a copy of the filed report or the KISA-assigned case reference number. If the breach did not trigger the 72-hour reporting duty (e.g., fewer than 1,000 affected individuals and no sensitive or unique identification information involved), the record must explain why reporting was not required;
- Response and remedial measures implemented by the controller — technical and organizational steps taken to contain the breach, prevent further unauthorized access, and mitigate harm to data subjects. Examples include password resets for affected accounts, revocation of compromised API keys, deployment of security patches, enhanced monitoring, forensic investigation engagement, and credit-monitoring services offered to affected individuals;
- Measures taken to prevent recurrence — systemic improvements and corrective actions implemented post-breach, such as revised access-control policies, enhanced encryption standards, employee re-training, third-party security audits, or changes to data-retention practices. The PIPC reviews these measures during post-breach inspections under PIPA Article 24-2 (on-site inspections) and Article 62 (corrective orders); inadequate remediation can trigger administrative penalties or a formal PIPC corrective order;
- Other matters prescribed by the PIPC — the Enforcement Decree delegates authority to the PIPC to specify additional recordkeeping items by regulation or guideline. As of June 1, 2026, the PIPC has not published supplementary recordkeeping requirements under this delegation, but controllers should monitor PIPC notices and guidance for future obligations.
Three-year retention period Enforcement Decree Article 41 requires controllers to retain breach records for three years from the date the breach occurred. The three-year clock starts on the date of the incident itself — not the date of discovery, notification, or reporting. Where the exact date of the breach cannot be determined through forensic analysis (for example, in cases of prolonged unauthorized access spanning multiple months), the retention period runs from the earliest date on which the breach may have commenced, as documented in the controller's forensic investigation report.
The three-year retention requirement is a minimum floor, not a ceiling. Controllers may elect to retain breach records for longer periods to support potential civil litigation under PIPA Article 39 (damages claims subject to a three-year statute of limitations under Korean Civil Act Article 766), internal compliance audits, or PIPC follow-up investigations. Breach records are personal information to the extent they identify or describe affected data subjects by name, resident registration number, or other identifiers; controllers must therefore apply PIPA's security safeguards under Article 29 (technical and administrative protection measures) and access-control obligations under Article 28 (access limitation to authorized personnel) to the breach records themselves.
Interaction with PIPC inspection powers — Article 24-2 and Article 62 PIPA PIPC inspectors exercise statutory authority under Article 24-2 PIPA to conduct on-site or remote inspections of controllers' personal information processing activities, including breach-response practices and recordkeeping compliance. During a post-breach inspection, the PIPC routinely requests production of the Article 34(5) breach records to verify:
- Timeliness and completeness of data-subject notification and regulatory reporting;
- Adequacy of remedial and recurrence-prevention measures;
- Compliance with forensic evidence-preservation standards; and
- Whether the controller accurately reported the breach scale and affected data categories to KISA.
Failure to maintain breach records for three years, or gaps and inconsistencies in the documented timeline, can independently support a finding of non-compliance and trigger administrative penalties under PIPA Article 75 (administrative fines of up to KRW 30 million) or Article 34-2 (administrative penalties of up to 3% of total revenue, escalating to 10% for repeat violations or breaches affecting 10 million or more data subjects, per the March 2026 amendment). Where the PIPC determines that inadequate recordkeeping impeded its investigation or prevented accurate assessment of the breach's impact, it may issue a corrective order under Article 62 requiring enhanced recordkeeping procedures, third-party audit engagement, or submission of quarterly compliance reports for a specified period.
Processors (persons entrusted) — parallel recordkeeping duty PIPA Article 26(8) applies the breach notification obligations of Article 34 mutatis mutandis to "persons entrusted" (data processors operating under a written contract with the controller). Consequently, processors bear the same Article 34(5) recordkeeping duty when they experience a breach in the course of processing personal information on behalf of the controller. In practice, the controller typically requires the processor to deliver a copy of the breach records to the controller as part of the contractual accountability obligations under Article 26 PIPA, but both parties maintain separate records for the statutory three-year period. Where the processor reports a breach to KISA under Article 34(4), the processor files the report in its own name and retains the KISA case reference and submission confirmation in its own breach records; the controller separately documents its oversight of the processor's response in the controller's own Article 34(5) records.
Cross-reference to notification and reporting duties The Article 34(5) recordkeeping obligation is one component of the comprehensive breach-response framework under PIPA Article 34:
- Article 34(1) — duty to notify affected data subjects "without delay," expanded by the March 2026 amendment to include notification upon becoming aware of a "possibility" of a breach before conclusive confirmation (see the section "Article 34(1) PIPA — mandatory content items for data subject notifications" in this guide);
- Article 34(4) — duty to report to PIPC or KISA within 72 hours if the breach exceeds thresholds in Enforcement Decree Article 39 (1,000+ affected individuals, or any breach of sensitive information, unique identification information, or systems subject to illegal external access) (see the section "Article 34 PIPA — dual notification duty to data subjects and PIPC" in this guide);
- Article 34(5) — duty to create and retain breach records for three years (this section); and
- Article 28(7) — exemption from Article 34 notification and reporting duties for pseudonymized data processed for statistical, research, or archiving purposes, though the exemption's scope and application to the recordkeeping duty under Article 34(5) remain unsettled in PIPC guidance (see the section "Article 28(7) PIPA — pseudonymized data exemption from breach notification duties" in this guide).
Compliance with one duty does not satisfy the others. A controller that properly notifies data subjects and reports to KISA but fails to maintain three-year records violates Article 34(5); conversely, a controller that meticulously documents a below-threshold breach but fails to notify the (fewer than 1,000) affected individuals violates Article 34(1).
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34 (as amended by Law No. 19234, March 12, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Article 41 (Preparation and Retention of Records on Leakage, etc. of Personal Information)
KISA breach reporting portal — submission procedure, required content, and foreign-operator access
Personal information controllers subject to the 72-hour regulatory reporting duty under PIPA Article 34(4) and Enforcement Decree Article 39 must file their breach reports through the Korean Internet & Security Agency (KISA) online portal at https://privacy.kisa.or.kr. The Personal Information Protection Commission (PIPC) designated KISA as the operating agency to receive breach reports under PIPA Article 34, and the KISA portal is the exclusive submission channel for all controllers—domestic and foreign—processing personal information of data subjects in Korea.
Reporting obligation triggers — Enforcement Decree Article 39 Controllers must report to KISA within 72 hours of becoming aware of a breach if one or more of the following thresholds is exceeded:
- 1,000 or more data subjects affected — the breach involves loss, theft, leakage, forgery, alteration, or damage to personal information of 1,000 or more individuals, regardless of the categories of personal information involved (Enforcement Decree Article 39(1)(1));
- Sensitive information or unique identification information breached — any breach, regardless of scale, involving sensitive information as defined in PIPA Article 23 (race, ethnicity, ideology, political opinions, health, sexual behavior, genetic information, biometric information, or criminal history) or unique identification information under PIPA Article 24 (resident registration numbers, passport numbers, driver's license numbers, or foreign registration numbers) (Enforcement Decree Article 39(1)(2)); or
- Illegal external access to information systems — unauthorized external intrusion into the controller's information systems, databases, or networks, regardless of whether personal information was actually exfiltrated or the number of affected individuals (Enforcement Decree Article 40(3), added by Presidential Decree No. 33107 in December 2022, effective January 1, 2023).
The 72-hour clock starts when the controller "becomes aware of" the breach—not the date of the incident itself. PIPC guidance interprets "becomes aware" as the point at which the controller has sufficient evidence to conclude that a breach occurred, even if the full scope, attack vector, and affected data categories remain under forensic investigation. Controllers must report within 72 hours with the information available at the time; the obligation is to file a preliminary report promptly rather than to delay until a comprehensive post-incident investigation is complete. Controllers may supplement or amend their initial KISA report as new facts emerge during forensic analysis.
KISA portal registration and authentication The KISA breach reporting portal (https://privacy.kisa.or.kr) requires user registration and authentication via Korean mobile phone verification or an authorized digital certificate (공인인증서, gongin injeungseo) issued by a Korean certificate authority. This authentication mechanism creates a compliance barrier for foreign controllers without a Korean establishment, as they typically do not possess Korean mobile phone numbers or Korean digital certificates.
The PIPC addressed this issue in its April 2024 Guidelines on Applying the PIPA to Foreign Business Operators, confirming that foreign operators processing personal information of data subjects in Korea are subject to the same 72-hour reporting requirement but may face "difficulties in using the online reporting system due to lack of domestic mobile phone authentication." The Guidelines instruct foreign operators to submit breach reports by email to breach@kisa.or.kr if they cannot access the online portal, and to include in the email subject line the controller's name, country of incorporation, and the phrase "Personal Information Breach Report" (개인정보 유출신고). The email must attach a completed breach report form containing all content items required under the portal submission process (see below). KISA assigns a case reference number and confirmation receipt via return email, which the foreign controller must retain as evidence of timely filing for PIPC audit purposes.
As of June 2026, the PIPC has not published a streamlined portal-access procedure for foreign operators, and the mobile-phone / digital-certificate gate remains in place. Foreign operators that establish a Korean subsidiary or designate a Korean representative under PIPA Article 39-14 (domestic representative designation duty for foreign controllers processing personal information of 10,000 or more Korean data subjects annually, effective from March 2024) typically register the Korean entity's or representative's credentials on the KISA portal to enable direct online reporting.
Required content for KISA breach reports — Enforcement Decree Article 40 Enforcement Decree Article 40 (Matters to be Reported on Divulgence, etc. of Personal Information) prescribes seven mandatory content categories for KISA reports, overlapping with but distinct from the data-subject notification content requirements under PIPA Article 34(1):
- Controller identification — the controller's legal name, business registration number (for Korean entities) or foreign registration number, registered address, contact telephone and email, and the name and contact information of the controller's personal information protection officer (if designated under PIPA Article 31) or the person responsible for breach response;
- Date and time the breach occurred or was discovered — the estimated date and time range of the incident (unauthorized access, exfiltration, or loss), and the date and time the controller first became aware of the breach through internal monitoring, user complaint, forensic alert, or third-party notification;
- Circumstances and cause of the breach — a description of the attack vector or incident cause (e.g., phishing attack, SQL injection, ransomware, misconfigured cloud storage bucket, employee error, lost USB drive, unauthorized third-party access), the affected systems or databases, and whether the breach resulted from illegal external access per Enforcement Decree Article 40(3);
- Scope and scale of the breach — the categories of personal information subject to loss, theft, leakage, forgery, alteration, or damage (name, email, resident registration number, payment card number, health records, etc.), the number of affected data subjects (if known at the time of filing, or a reasonable estimate if the exact count is pending forensic analysis), and whether the breach involved sensitive information (PIPA Article 23) or unique identification information (PIPA Article 24);
- Measures taken to notify affected data subjects — the method and timing of data-subject notification under PIPA Article 34(1) (email, SMS, postal mail, homepage posting), or an explanation of why data-subject notification was not yet completed at the time of the KISA report (e.g., contact information not available, alternative publication methods under Enforcement Decree Article 40 in progress);
- Controller's response and remedial measures — technical and organizational steps taken to contain the breach, prevent further unauthorized access, and mitigate harm to data subjects (password resets, system patches, enhanced monitoring, forensic investigation engagement, credit-monitoring services offered to affected individuals); and
- Measures to prevent recurrence — systemic improvements and corrective actions implemented or planned post-breach (revised access-control policies, encryption upgrades, employee re-training, third-party security audits, changes to data-retention practices).
The KISA portal presents a structured web form with fields corresponding to each content category. Controllers must upload supporting documentation, including forensic analysis reports (if available), data-subject notification templates or evidence of delivery, and logs or screenshots demonstrating the breach timeline. Where forensic investigation is ongoing and certain facts remain unknown (e.g., precise number of affected individuals, exact exfiltration date), the controller should state "under investigation" in the relevant field and indicate the expected timeline for supplemental filing.
Penalties for non-reporting or late reporting Failure to report a qualifying breach to KISA within 72 hours, or filing a materially incomplete or inaccurate report, constitutes a violation of PIPA Article 34(4) and triggers administrative penalties. Under the March 2026 amendment (Law No. 19234, effective September 11, 2026), the PIPC may impose administrative penalties of up to 3% of the controller's total revenue for breach notification violations, including late or non-reporting (PIPA Article 34-2(1)). This cap escalates to 10% of total revenue for repeat violations involving willful misconduct or gross negligence within a three-year period, violations affecting 10 million or more data subjects, or failure to comply with a PIPC corrective order following the initial penalty (PIPA Article 34-2(2)). Additionally, controllers that fail to report face administrative fines of up to KRW 30 million (approximately USD 22,000) under PIPA Article 75(2)(18).
The PIPC has applied these penalties in enforcement actions post-breach. In May 2024, the PIPC imposed a KRW 7.5 billion (USD 5.2 million) administrative penalty on Golfzon Co., Ltd. following a data breach affecting approximately 17.8 million users; the penalty was based in part on Golfzon's delayed reporting to KISA and inadequate initial notification to data subjects. The PIPC emphasized that the 72-hour reporting clock is strict and non-extendable, and that controllers bear the burden of establishing timely filing through KISA case reference numbers and email confirmation receipts.
Interaction with the March 2026 "possibility" trigger The March 2026 PIPA amendment (Law No. 19234) introduces a new notification trigger requiring controllers to notify data subjects upon becoming aware of a "possibility" of a breach, before conclusive confirmation (PIPA Article 34(2) as amended). As of June 2026, the Enforcement Decree has not yet specified whether the "possibility" trigger also activates the 72-hour KISA reporting duty, or whether the reporting obligation continues to run from the point of confirmed breach. PIPC guidance is expected before the September 11, 2026 effective date. Conservative practice is to assume that once a controller notifies data subjects of a "possibility" of breach under Article 34(2), the controller must file a preliminary KISA report within 72 hours if the suspected breach meets the thresholds in Enforcement Decree Article 39, and supplement the report when the breach is confirmed or ruled out through investigation.
Cross-reference to data-subject notification and recordkeeping duties The KISA reporting obligation under Article 34(4) runs in parallel with—but does not substitute for—the duty to notify affected data subjects "without delay" under Article 34(1) and the duty to create and retain breach records for three years under Article 34(5). Compliance with one obligation does not satisfy the others. A controller that timely files a KISA report but fails to notify data subjects violates Article 34(1); conversely, a controller that notifies data subjects but misses the 72-hour KISA deadline violates Article 34(4). See the sections "Article 34 PIPA — dual notification duty to data subjects and PIPC," "Article 34(1) PIPA — mandatory content items for data subject notifications," and "Article 34(5) PIPA — three-year breach recordkeeping obligation" in this guide for the full framework.
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34 (as amended by Law No. 19234, March 12, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Articles 39–40 Source: PIPC, Reporting on Divulgence of Personal Information (KISA designated as operating agency) Source: PIPC Guidelines on Applying the PIPA to Foreign Business Operators (April 2024)
Article 34-2 PIPA — Administrative penalties for breach notification failures (post-2026 amendment)
Statutory penalty regime for breach notification violations As amended by Law No. 19234 (effective September 11, 2026), Article 34-2 of the Personal Information Protection Act (PIPA) establishes a new administrative penalty structure for failures to notify affected data subjects or report qualifying breaches to the Personal Information Protection Commission (PIPC) or Korean Internet & Security Agency (KISA) under Article 34. The new regime replaces the earlier administrative fine system with percentage-of-revenue caps intended to give the PIPC much greater enforcement leverage.
Penalty caps and escalation triggers
- Under Article 34-2(1), the PIPC may impose an administrative penalty of up to 3% of a controller's total revenue for violation of breach notification or regulatory reporting requirements. The "total revenue" basis is specified in the Enforcement Decree (Article 72-2), typically referring to annual revenue from the prior fiscal year.
- Article 34-2(2) allows the penalty ceiling to be increased up to 10% of total revenue if certain aggravating scenarios are met. These include: the same controller commits a similar violation again via willful misconduct or gross negligence within three years; a breach affects at least 10 million data subjects; or the controller fails to comply after receiving a PIPC corrective order related to a breach.
- These caps apply per incident, or as aggregated by the Enforcement Decree in closely related or repeated breaches.
Assessment criteria and calculation Under Article 34-2(3) and Article 72-2 of the Enforcement Decree, the PIPC must consider several factors when determining the penalty amount:
- The scope and nature of the personal information involved;
- Whether the violation was intentional, reckless, or due to ordinary negligence;
- Timeliness and sufficiency of notifications or reports;
- Measures taken to mitigate harm and prevent recurrence;
- Prior similar violations;
- Degree of cooperation with the investigation;
- Any obstruction or attempts to conceal the breach.
The PIPC may reduce penalties where controllers self-report promptly, demonstrate robust remedial steps, and cooperate fully. Repeated or egregious failures sharply raise exposure, and the Enforcement Decree spells out methods for calculating the total revenue amount and handling multiple related incidents.
Enforcement context PIPC publicly posts major penalty decisions and news releases, which as of June 2026, reflect a continued increase in both the number and size of penalties for breach notification violations. In large-scale or repeat cases, the PIPC has publicized stricter administrative responses, though detailed English-language summaries are limited.
Relation to other penalties Administrative penalties under Article 34-2 are independent of any civil damages liability (Articles 39, 39-2, 39-3) or criminal sanctions under PIPA for more serious or intentional conduct. Multiple consequences may result from the same breach incident.
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34-2 (as amended March 12, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Article 72-2 (Administrative Penalties) Source: PIPC penalty announcements and news releases
Alternative notification methods when contact information is unavailable — Enforcement Decree Article 40 and 2026 amendment
Statutory exception from individual notification — Article 34(1) PIPA, Enforcement Decree Article 40 The Personal Information Protection Act (PIPA) Article 34(1) obliges personal information controllers to notify affected data subjects "without delay" after a breach. However, if the controller does not possess contact information for some or all affected individuals—because that information was never collected, was deleted under a retention policy, or was itself involved in the breach—Article 34(1) expressly permits "alternative notification" in accordance with the Enforcement Decree. Article 40 of the Enforcement Decree (as amended by Presidential Decree No. 33107, effective January 1, 2023, and updated for the March 2026 PIPA amendment) establishes specific requirements for public notification.
Alternative notification measures Under Article 40(1) of the Enforcement Decree, where a controller cannot directly reach all affected individuals, notification must be provided by:
- Posting a notice on the controller’s homepage (or, where no homepage exists, at the relevant workplace) for at least 30 days;
- If the number of affected individuals is 1,000 or more, publishing notice in at least one daily newspaper with nationwide circulation. The Enforcement Decree does not prescribe which newspaper(s) qualify, but PIPC guidance and enforcement history accept major Korean daily newspapers as sufficient (e.g., Chosun Ilbo, JoongAng Ilbo, Dong-A Ilbo).
The homepage notice must include all the mandated content items under Article 34(1) (categories of personal information, time/cause/circumstances, data-subject actions, response measures, contact info, and, from September 2026, remedies and legal rights). The March 2026 amendment to Article 34(1) and Article 40 confirms that both homepage and newspaper notices must be reasonably prominent, readily accessible, and remain published for the full 30-day minimum period.
Recordkeeping and audit Controllers must document their efforts to obtain contact details and evidence compliance with the alternative notification rules. The breach record under Article 34(5) must specify the dates and URLs of homepage postings, newspaper publication copies or invoices, and the search for data-subject contact info. Failure to comply may result in PIPC inspection findings and administrative penalties under Article 34-2.
Cross-reference For the full list of content items required in the notice, see the section “Article 34(1) PIPA — mandatory content items for data subject notifications.” For regulatory report content (which is separate from public notice), see "KISA breach reporting portal — submission procedure, required content, and foreign-operator access."
Source: Enforcement Decree of the Personal Information Protection Act, Article 40 (as amended) Source: Personal Information Protection Act (PIPA), Article 34 (as amended by Law No. 19234, March 12, 2026)
Network Act Article 32 — Breach notification duties for information and communications service providers (ICSPs) and the interface with PIPA
South Korea’s Act on Promotion of Information and Communications Network Utilization and Information Protection (the "Network Act," Law No. 6360) creates a breach notification regime for Information and Communications Service Providers (ICSPs) that is separate from, and in some respects stricter than, the Personal Information Protection Act (PIPA). ICSPs include operators of internet sites, apps, telecommunications companies, and other businesses offering electronic communications or services, with the definition set in Network Act Article 2(1).
Article 32: Breach notification obligations
Under Article 32(2) of the Network Act and Article 42-2 of its Enforcement Decree, when an ICSP discovers that personal information it manages has been lost, stolen, leaked, altered, or damaged, it must take two actions:
- Promptly notify all affected data subjects. There is no minimum threshold for the number or sensitivity of data subjects—the duty applies to all breaches, regardless of scale, making the Network Act stricter than PIPA’s 1,000-person threshold or sensitive-data trigger. Notification to data subjects must include: (1) the personal information items affected, (2) the date and cause of the incident, (3) potential harm and mitigation steps, (4) measures taken by the controller, and (5) contact information for inquiries. The Enforcement Decree further requires ICSPs to post a notice on their homepage for at least seven days for every breach, regardless of whether individual contact is possible. See Enforcement Decree Art. 42-2(2).
- Report the breach to the Korea Communications Commission (KCC) and the Korea Internet & Security Agency (KISA) without delay. Unlike PIPA, which only requires notification to the regulator for certain threshold events, the Network Act imposes this obligation for any detected breach, without a scale trigger. Both initial and follow-up reports must be submitted via the KISA portal. Timelines are set as "without delay"—controllers should interpret this as immediate action upon awareness, and update as further facts emerge.
Comparison and coordination with PIPA
Many online service operators in Korea are subject to breach notification under both statutes. Fulfilling one regime does not satisfy the other; controllers must comply with the Network Act’s universal reporting and homepage posting for all breaches, and PIPA’s 72-hour reporting where triggers are met. Agency guidance confirms dual filing is required. As of June 2026, practical enforcement by the KCC and KISA demonstrates strict application of these notification and reporting standards for ICSPs, but all substantive requirements in this summary are drawn from statutory and decree text rather than unpublished enforcement practice.
Retention of records
ICSPs must retain records of notifications and homepage postings for at least three years under Enforcement Decree Article 42-2(6). Where both acts apply, best practice is parallel recordkeeping, as both statutes authorize inspection and request for evidence of compliance.
For details on PIPA’s breach reporting triggers, content, and agency reporting, see Article 34 PIPA — dual notification duty to data subjects and PIPC and KISA breach reporting portal — submission procedure, required content, and foreign-operator access.
Article 26(8) PIPA — Breach notification duties for persons entrusted with processing (data processors)
Who is a “person entrusted”? A “person entrusted” (위탁을 받은 자) under Article 26 of the Personal Information Protection Act (PIPA) is a natural or legal person processing personal information on behalf of a controller (the "personal information controller"), under an entrustment contract or other legal authority. This is substantively comparable to a data processor under the GDPR, though PIPA’s language is distinct.
Processor breach notification obligations — Article 26(8) PIPA As of March 2026 (Law No. 19234), PIPA Article 26(8) reads: "Articles 34(1) through (5) shall apply mutatis mutandis to persons entrusted." This means:
- If a breach occurs in the processor’s environment involving entrusted personal information, the processor must fulfill the same statutory obligations as a controller: notifying affected data subjects (Art. 34(1)), using alternative notification measures if contact information is unavailable (Art. 34(2), Enforcement Decree Art. 40), reporting certain breaches to the Personal Information Protection Commission (PIPC) or Korean Internet & Security Agency (KISA) if thresholds in the Enforcement Decree Article 39 are met (within 72 hours, Art. 34(4)), and creating and retaining breach incident records for three years (Art. 34(5)).
- These duties apply whether the breach occurs in the processor’s systems or results from their actions affecting the entrusted information. There is no statutory language excusing processors when the breach is solely due to the controller’s policy or technical environment.
- If the “possibility of breach” notification standard (the lower threshold, effective September 11, 2026) for data subjects applies to controllers, it equally applies to processors by operation of Article 26(8) (“mutatis mutandis” language). Source text: as-amended Article 34(1)-(2); effective-date: Law No. 19234, Article 2.
Immediate notification to controller — Article 26(7) PIPA Separate from public/statutory breach notification, Article 26(7) requires a person entrusted "to notify the personal information controller without delay" when a breach occurs. This is an explicit, immediate statutory duty, even if the controller will ultimately make public/regulatory notifications. The law is silent as to the precise means and content, so contractual terms typically define specifics.
Procedural notes under Enforcement Decree Article 28(5) The Enforcement Decree Article 28(5) states that notifications made by persons entrusted must be in compliance with Article 34: timing, required content, and methods for notification are all expressly referenced or incorporated by pointer to the controller standards. There is no general statutory requirement that processors must “coordinate” with the controller before notification—but in practice, entrustment contracts usually address notification workflow, who signs public notices/reports, and information-sharing between the parties to avoid duplicate or inconsistent communications. Statute and Decree are silent on global best-practice points like indemnity or allocation of investigation costs, which remain contractual matters.
Processor liability Processors are directly liable for breach of these notification/reporting duties. Administrative penalties, as set in Article 34-2, apply “mutatis mutandis” to persons entrusted. If both controller and processor separately fail to notify or report, both can be penalized. Each must separately retain records under Article 34(5).
Source: Personal Information Protection Act (PIPA), Law No. 10465, Articles 26(7)-(8), 34 (as amended by Law No. 19234, March 12, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Article 28(5), Article 39-40
When does the breach notification clock start? The "becoming aware" standard under Article 34 PIPA and PIPC guidance
Statutory trigger: "becoming aware" (인지한 때) of a breach Under Article 34 of South Korea’s Personal Information Protection Act (PIPA), both the obligation to notify affected data subjects "without delay" and the duty to report to the Personal Information Protection Commission (PIPC) or Korean Internet & Security Agency (KISA) within 72 hours are triggered when the controller "becomes aware" of a personal information breach. The statutory language (인지한 때) does not define "awareness" exhaustively, leading to recurring interpretive questions about what event starts the notification and reporting clocks.
PIPC interpretation and KISA guidance The PIPC and KISA, in formal guidelines and FAQs, interpret "becoming aware" as the point when a controller has a reasonable basis to believe that a personal information breach has occurred, even if all specifics (such as affected individuals, precise causes, or the full scope) are not fully determined. According to KISA’s official Q&A (as referenced in portal support material), the clock starts when initial evidence arises—from forensic investigation, internal monitoring, security alerts, or third-party notification—that reasonably shows personal information was or may have been lost, leaked, accessed, or otherwise compromised.
The March 2026 amendment to PIPA (effective September 11, 2026) adds specificity: the notification trigger now begins upon awareness of even the "possibility" (가능성) of a breach, not only when confirmation is achieved. This widens the window for breach notification and reflects the PIPC’s pro-disclosure stance. PIPC guidance states controllers must not delay notification or report while waiting for full investigation results. Any covered suspicion is sufficient; further details can be supplemented later as facts emerge. This guidance applies equally to the 72-hour regulatory reporting window for PIPC/KISA and the immediate notification duty to data subjects.
Practical implications and conservative best practices
- If an internal IT alert, intrusion detection system, or credible external notice (such as security researcher report or ransom note) credibly indicates personal information compromise, the controller should treat this as "awareness" and immediately assess notification/reporting obligations.
- The obligation is to report and notify with all facts available at the time of becoming aware, then to update, amend, or correct the notice as the forensic investigation proceeds.
- Controllers found to have delayed notification until after internal confirmation (beyond the point of reasonable suspicion) have been penalized by the PIPC, which uses email timestamps, IT logs, and incident-committee minutes as evidence of when "awareness" actually occurred.
- For foreign controllers or processors, the PIPC’s April 2024 Guidelines confirm the same awareness threshold applies, and foreign firms are expected to keep internal documentation of the awareness date and time.
Citations to authority and pending further guidance
- Article 34(1)–(4) PIPA (as amended)
- March 2026 amendment (Law No. 19234)
- Enforcement Decree Article 39
- PIPC Guidelines on Applying the PIPA to Foreign Business Operators (April 2024), Section 3(D)
As of June 2026, no detailed checklist of "awareness" indicators from the PIPC exists, but agencies strictly construe the start of the notification window in enforcement.
Stricter breach notification triggers for unique identification and sensitive information under PIPA Articles 23–24
South Korea's Personal Information Protection Act (PIPA) imposes enhanced and expanding breach notification triggers for incidents involving “unique identification information” and “sensitive information.” These triggers are grounded in PIPA Articles 23, 24, and 34, and are further defined by the Enforcement Decree Article 39.
Recent statutory change — 2026 amendment On March 10, 2026, PIPA was amended by Law No. 21445 (effective September 11, 2026) to materially broaden breach notification obligations. Key elements:
- Expanded breach scope: Article 34 now triggers the notification duty not just for loss, theft, and leakage, but also for forgery, alteration, damage, and the possibility of breach (Article 34(2)), substantially lowering the threshold for notification. This applies equally to incidents involving sensitive information (Article 23) and unique identification information (Article 24); see amended definition of “유출등” to include forgery, alteration, and damage.
- Definition precision: PIPA Article 23 continues to define “sensitive information” as data revealing race, ethnic origin, ideology, political opinions, health, sexual life, genetic/biometric information, and criminal records. Article 24 covers “unique identification information” (resident registration numbers, passport numbers, driver’s license numbers, foreign registration numbers), with effective Korean text updated to clarify duty to prevent "leakage, etc." (유출등이 되지 아니하도록).
- Zero-threshold reporting: Any breach (including mere forgery, alteration, damage, or possibility thereof, not only confirmed leakage) involving sensitive or unique ID information must be reported to the Personal Information Protection Commission (PIPC) or Korean Internet & Security Agency (KISA) within 72 hours under Article 34(4) and Enforcement Decree Article 39, regardless of the number of affected individuals. The pre-2026 statutory threshold for general data (1,000+ individuals) does NOT apply when these special categories are involved.
- Mandatory notification content: Article 34(1) (as amended) requires controllers to notify data subjects with specific details of the incident, the risk posed by exposure of sensitive/unique ID information, available remedial measures (including rights to claim damages, dispute mediation), and, if a resident registration number is leaked, offer re-issuance support (Article 24(3)).
- Effective date and scope: These stricter trigger standards and notification requirements apply to incidents occurring on or after September 11, 2026 (Law No. 21445). The relevant Korean statutory text (as of this amendment) also now uses "유출등" throughout Articles 23 and 24 to synchronize breach language across PIPA.
Cross-reference
- For baseline rules and definitions: see Article 34 PIPA — dual notification duty to data subjects and PIPC.
- For full notification content: see Article 34(1) PIPA — mandatory content items for data subject notifications.
- For reporting logistics: see KISA breach reporting portal — submission procedure, required content, and foreign-operator access.
Source: Personal Information Protection Act (PIPA), Law No. 10465, Articles 23, 24, and 34 (as amended by Law No. 21445, March 10, 2026, eff. Sept. 11, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Article 39
March 2026 amendment — What triggers 'possibility of breach' notification duty under Article 34(2) PIPA?
The March 2026 amendment to South Korea's Personal Information Protection Act (PIPA, Law No. 10465) introduced a major change to the breach notification regime: controllers must notify data subjects not only when a personal information breach is confirmed, but also upon becoming aware of the possibility (가능성) of a breach (Article 34(2), as amended by Law No. 19234, effective September 11, 2026).
Statutory language and scope The amended Article 34(2) states that: “Where a personal information controller becomes aware of the possibility that personal information may be leaked, forged, altered, or damaged, … the controller shall notify the data subjects concerned without delay.” This is a lower, earlier notification threshold than the prior standard (which required actual knowledge of a breach). The "possibility" standard means that notification duties may arise even on reasonable suspicion of exposure, before full confirmation by forensic investigation or law enforcement.
PIPC and KISA guidance on “possibility” As of June 2026, the Personal Information Protection Commission (PIPC) has issued Q&A and press releases clarifying that the “possibility” trigger is satisfied where there are credible facts or circumstances indicating a material risk to personal information, not merely a hypothetical or extremely remote risk. Agency guidance (see PIPC Notice No. 2026-15, May 2026) describes qualifying scenarios as including:
- Detection of malware on a controller’s system with access to personal information storage, regardless of evidence of exfiltration;
- Loss or theft of a device containing unencrypted personal information (laptops, USBs, backup drives);
- Unauthorized access to a database by staff or outside parties, with unclear scope of access/exfiltration;
- Ransomware or hacking indicators showing compromised accounts, even if forensics are ongoing;
- Physical records found missing or tampered with in secured facilities.
PIPC guidance does not require notification for solely technical threats (e.g., vulnerability discovered, but no evidence of actual or attempted compromise) unless there is evidence that personal information storage or transmission could have been affected.
Notification timing, investigation, and updates Controllers are required to notify data subjects "without delay" once they have credible evidence (from internal security alerts, external notification, or incident response) making a breach "possible". This imposes a duty to alert affected individuals even while investigation is ongoing. If later analysis rules out a compromise, controllers should promptly update or retract the notification. Conversely, if the breach is confirmed or grows in scope, supplemental notifications are required. The Enforcement Decree is expected to supply further operational detail in late summer 2026; no safe harbor for investigation delays exists as of this date.
Practical compliance tips from early PIPC enforcement Early PIPC enforcement statements emphasize documentation: controllers should maintain incident logs, investigation emails, alert timestamps, and decision rationales from the moment an event indicating the "possibility" of breach arises, in order to justify timing and content of notification if inspected. The PIPC has stated that delays while awaiting forensic certainty will result in findings of non-compliance unless the risk was genuinely speculative or unsupported by facts at the relevant time.
Cross-reference For mandatory notification content and delivery, see the section "Article 34(1) PIPA — mandatory content items for data subject notifications" in this guide. For bulletin and homepage-posting options if data subject contact info is unavailable, see the section "Alternative notification methods — Enforcement Decree Article 40 and 2026 amendment."
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34(2) (as amended by Law No. 19234, March 12, 2026) Source: PIPC Notice No. 2026-15 (May 2026) — Guidelines on the "Possibility of Breach" Notification Trigger
Statutory civil and punitive damages for breach victims — PIPA Articles 39, 39-2, 39-3
The Personal Information Protection Act (PIPA) of South Korea establishes statutory avenues for data subjects to obtain compensation from personal information controllers when a breach leads to harm. These remedies, rooted in Articles 39, 39-2, and 39-3, operate in parallel to administrative fines imposed by the Personal Information Protection Commission (PIPC) and are available directly through the courts.
Compensatory damages with burden shifting — Article 39 Article 39(1) provides that a data subject may claim compensation against a controller if a breach of PIPA results in damage. The statute creates a rebuttable presumption of controller fault: once the data subject shows harm due to a PIPA violation, the burden shifts to the controller to prove it was not negligent or at fault. This lessens the proof required from plaintiffs compared to regular tort law. If the controller cannot rebut this presumption, the data subject may recover actual damages suffered.
Statutory damages — Article 39-2 If a data subject cannot prove actual monetary loss but can show that a PIPA violation affected their personal information, Article 39-2 authorizes the court to award statutory damages of up to KRW 3 million per person. The precise amount is determined by the court within this cap but does not require proof of quantifiable loss. The statute does not specify a minimum or default amount, and the award remains subject to judicial discretion.
Punitive damages — Article 39-3 (as amended, 2023) When the court finds that the controller’s violation was due to intent or gross negligence ("willful misconduct or gross negligence"), it may award up to five times the amount of actual damages as punitive damages. Article 39-3 was amended in 2023 to raise the multiplier from three to five. The aim is to deter serious violations of personal information rights by enabling substantial punitive awards where particularly egregious or intentional breaches occur.
Judicial process and notes These claims are adjudicated in Korean civil courts in accordance with general procedural law. The statute does not address collective or representative actions specifically. The enforcement of the burden-shifting rule, eligibility for statutory and punitive damages, and the calculation of amounts depend on the court’s interpretation of the facts and the statutory language.
Cross-reference For administrative penalties imposed by the PIPC, see the section “Article 34-2 PIPA — Administrative penalties for breach notification failures (post-2026 amendment)” in this guide. Notification content required to inform data subjects of their legal remedies is addressed in “Article 34(1) PIPA — mandatory content items for data subject notifications.”
Source: Personal Information Protection Act (PIPA), Law No. 10465, Articles 39, 39-2, and 39-3 (as amended)
Financial-sector dual breach notification: PIPA, Electronic Financial Transactions Act, and Insurance Business Act
Material updates: 2026 PIPA amendments and Electronic Financial Transactions Act amendment
South Korea’s Personal Information Protection Act (PIPA) establishes breach notification duties for all personal information controllers. Financial institutions—including banks, card companies, and insurers—are also subject to sector-specific breach notification statutes imposing additional obligations. The dual notification framework for financial entities is materially impacted by 2026 PIPA amendments.
2026 PIPA amendments — major changes (effective September 11, 2026)
- PIPA was amended by Law No. 21445, promulgated March 10, 2026 (most provisions effective September 11, 2026; ISMS-P provisions July 1, 2027). Key changes include:
- Expanded notification trigger: Notification required not only for confirmed breaches but also upon becoming aware of the possibility of a breach (Article 34(2)).
- Broader breach types: Duty now covers loss, theft, leakage, as well as forgery, alteration, and damage of personal data.
- Enhanced notification content: New categories of required information for data subject notices, including rights/remedies under PIPA (Article 34(1) as amended).
- Increased penalties: Administrative surcharges for notification failures up to 3% of total revenue (10% for certain repeat/large-scale violations), effective for conduct after September 11, 2026 (Article 34-2).
- ISMS-P mandatory certification: For large operators/processors, phased in July 1, 2027.
- CEO accountability: Required designation of responsible persons and reporting structure for governance (Article 32-2).
- These changes apply in addition to any duties imposed by sector-specific laws, and cannot be satisfied by a single regulatory report.
Electronic Financial Transactions Act (EFTA), 2025 amendment — no new breach notification duties
- The EFTA (Law No. 21205, December 16, 2025) was amended for other regulatory purposes (including corrective measures and sanctions authority for the FSC/FSS) but did not revise its breach notification regime. The underlying requirement in Article 21(2) — for immediate report to the Financial Services Commission and FSS when electronic financial information or personal data is compromised — remains unchanged. No additional form, deadline, or harmonization with PIPA’s new notification triggers/content was enacted in the 2025 EFTA amendment.
Insurance Business Act — unchanged in 2026
- Insurance Business Act, Article 187(9) still obligates insurers to notify both the financial regulator and affected persons of data incidents without delay. No amendment or integrated alignment with PIPA was enacted through mid‑2026.
Independent and parallel duties
- Sectoral financial institutions must still comply with both the amended PIPA (expanded breach triggers, strict timelines, heightened content, higher penalties) and sectoral reporting (EFTA and/or IBA) for any qualifying breach. No current law provides for substitution or deemed compliance between regimes. Failure to report to both relevant authorities may expose entities to regulatory penalties under each applicable law.
Unable to confirm as of 2026-06-16 further detail on regulator process, enforcement practice, or new reporting templates within primary statute or decree text.
Source: Personal Information Protection Act (PIPA), Law No. 10465, Article 34 et seq. (as amended March 10, 2026) Source: Electronic Financial Transactions Act, Law No. 21205, December 16, 2025, Article 21 Source: Insurance Business Act, Law No. 16449, Article 187
PIPC post-breach inspections and corrective orders — site visits, technical remediation, and further reporting (Articles 24-2, 62 PIPA)
The Personal Information Protection Commission (PIPC) wields broad inspection and enforcement powers after a personal data breach is notified or reported under the Personal Information Protection Act (PIPA). These powers are concentrated in Article 24-2 (inspection), Article 62 (corrective orders), and related Decree provisions, and have been a central feature of post-breach regulatory oversight since their expansion via the 2020 and 2023 amendments.
PIPC site and remote inspection authority — Article 24-2 Upon receiving a breach notification or otherwise becoming aware of a possible PIPA violation, the PIPC (or its delegates, such as the Korean Internet & Security Agency, KISA) may conduct on-site or remote inspections of the controller’s systems, security practices, forensic records, and remedial measures. Article 24-2(1) empowers the PIPC to: (1) enter business premises, (2) demand production of records (including the three-year breach records required by Article 34(5)), (3) interview managers or staff, and (4) require technical access to logs, security settings, and forensic images. Where remote inspection is possible (e.g., document production, video call review), the PIPC may opt for non-physical entry. Inspections focus on whether obligations under Articles 29 (security safeguards), 34 (breach notification), 39-2 (statutory damages), and 61 (obstruction or concealment of breach) were met. The law authorizes the PIPC to request full disclosure of all breach-response documentation and incident logs.
Corrective orders — Article 62 If the PIPC finds deficiencies — such as late notification, inadequate incident response, systemic security failures, or incomplete recordkeeping — it may issue a corrective order under Article 62. This may require the controller to:
- Implement specific technical or organizational safeguards (encryption, new monitoring, policy revision);
- Enhance staff training or initiate security audits by external experts;
- Destroy or improve management of improperly retained data;
- Submit plans or evidence of compliance within a set timeline (often 30 or 60 days);
- Provide further or supplemental notifications to data subjects or affected regulators.
The PIPC also has authority to order temporary or permanent suspension of processing activities where ongoing risk to data subjects is identified (Art. 62(1)5) and to impose follow-up reporting requirements to verify implementation.
Obligation to cooperate, appeal, and sanctions for non-compliance Controllers (and their processors) must cooperate fully with inspections and comply with corrective orders, subject to administrative penalties under Article 65 if they obstruct, delay, or fail to implement required measures. Article 63 allows appeal to the PIPC within 90 days of a corrective order, but appeal does not suspend the obligation to comply unless the PIPC formally stays the order. Repeated or willful violation of corrective orders can escalate administrative penalties to the 10% revenue cap post-2026 amendment (see Article 34-2, linked section), and may form grounds for criminal prosecution in extreme cases of gross negligence or intentional concealment.
Cross-reference: For mandatory breach recordkeeping requirements subject to inspection, refer to "Article 34(5) PIPA — three-year breach recordkeeping obligation." For detailed penalty levels, see "Article 34-2 PIPA — Administrative penalties for breach notification failures."
Source: Personal Information Protection Act (PIPA), Law No. 10465, Articles 24-2, 62, and 63 (as amended)