Chief Privacy Officer (CPO) — universal designation requirement under Article 31 PIPA
Universal designation duty. Article 31(1) of the Personal Information Protection Act (개인정보 보호법, PIPA) requires every personal information controller (개인정보처리자, meaning any government agency, local government, legal entity, organization, or individual that processes personal information for the operation of a personal information file, Art. 2(5) PIPA) to designate a Chief Privacy Officer (CPO, 개인정보 보호책임자). The CPO oversees and manages all personal information processing by the controller. Article 31(2) requires the CPO to be an employee or executive of the controller; there is no statutory nationality or residency restriction.
Failure to designate a CPO exposes the controller to an administrative fine under Article 75(2)(1) PIPA. The Personal Information Protection Commission (PIPC, 개인정보보호위원회) may impose a fine of up to KRW 10 million on a personal information controller that violates the designation duty.
Core CPO duties under Article 31(4). The March 2023 amendments to PIPA (Act No. 19234, effective September 15, 2023, with certain provisions delayed to March 15, 2024) significantly expanded the CPO's statutory responsibilities. Article 31(4) lists eleven duties:
- Establishing and implementing plans for the protection of personal information;
- Managing specialized personnel and securing necessary budgets for the protection of personal information;
- Reporting the current status and key matters of personal information protection to the business owner or representative;
- Performing periodic investigations and improving the status and practices of personal information processing;
- Handling complaints and dealing with damage pertaining to personal information processing;
- Establishing internal control systems for preventing leakage, misuse, and abuse of personal information;
- Establishing and implementing training sessions for the protection of personal information;
- Protecting, managing, and monitoring personal information files;
- Establishing, amending, and implementing the privacy policy;
- Managing materials concerning the protection of personal information; and
- Other duties prescribed by Presidential Decree as necessary for the protection of personal information.
Enhanced qualification requirements — effective March 15, 2024. The Enforcement Decree of PIPA (Presidential Decree No. 34413, effective March 15, 2024) introduced qualification thresholds for larger controllers. Under Article 32-2(1) of the Enforcement Decree, personal information controllers that meet both of the following criteria in the immediately preceding year must designate a CPO meeting enhanced qualifications:
- Annual sales revenue or income of at least KRW 10 billion; and
- Storage and management of personal information of at least 1 million persons during the last three-month period of the preceding year.
Such controllers must appoint a CPO with (i) at least three years of experience in personal information protection, and (ii) a combined career of at least six years in personal information protection, data protection, and information technology (Art. 32-2(2), Enforcement Decree). Controllers that are micro-enterprises under the Framework Act on Micro-Enterprises are exempt from the CPO designation requirement (Art. 32-2(3), Enforcement Decree). Individuals already designated as CPOs as of March 15, 2024, were granted a grace period until March 14, 2026, to meet the enhanced qualification requirements (Addenda, Art. 3, Enforcement Decree No. 34413).
Board approval and PIPC reporting for large controllers. Article 31(3) PIPA (as amended March 2023) requires personal information controllers meeting thresholds prescribed by the Enforcement Decree to obtain board of directors approval for the appointment, change, or dismissal of the CPO, and to report such designation to the PIPC. Unable to confirm the precise revenue and data-subject thresholds triggering this heightened governance requirement from the Enforcement Decree as of 2026-05-29.
Independence safeguards. The Enforcement Decree requires controllers to establish a regular reporting system to ensure the CPO reports to the representative or board of directors, ensure the CPO's access to information on personal information processing, and provide the CPO with necessary human and material resources to fulfill statutory duties effectively.
Source: Personal Information Protection Act, Act No. 19234 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413 Source: Personal Information Protection Commission — Privacy Guidelines
Privacy Impact Assessment (PIA) — mandatory ex-ante assessment for public institutions under Article 33 PIPA
Public-institution obligation; private-sector exemption. Article 33(1) of the Personal Information Protection Act (개인정보 보호법, PIPA) requires the head of a public institution that intends to establish or operate a personal information file meeting criteria prescribed by Presidential Decree to conduct a Privacy Impact Assessment (개인정보 영향평가, PIA) before establishing or operating the file. Public institutions covered by Article 33 are those defined in Article 2(6) PIPA and Article 2 of the Enforcement Decree: government agencies, local governments, and public organizations designated by Presidential Decree. Private-sector personal information controllers are not subject to the mandatory PIA obligation under Article 33 PIPA; the statute applies only to public institutions.
Statutory triggers under Article 35 of the Enforcement Decree. Article 35 of the Enforcement Decree of PIPA (Presidential Decree No. 34413) specifies three threshold-based triggers for mandatory PIAs when a public institution establishes, operates, or changes an electronically processable personal information file:
- General large-scale files: Files containing personal information of at least 1 million data subjects (Art. 35(1), Enforcement Decree);
- System-connection files: Files containing personal information of at least 500,000 data subjects when the file is created or operated by connecting internal and external systems—such as integrating databases across agencies or linking to external third-party systems (Art. 35(2), Enforcement Decree); or
- Sensitive-category files: Files containing personal information of at least 500,000 data subjects when the file includes sensitive information such as ideology, beliefs, labor-union membership, political opinions, health, sex life, genetic or biometric data for unique identification, or criminal records—categories enumerated in Article 23 PIPA as requiring enhanced consent or separate lawful bases (Art. 35(3), Enforcement Decree).
A fourth trigger applies when the public institution changes the operating system of a personal information file—such as modifying the search, retrieval, or access mechanisms for an existing file—after the PIA has already been conducted on that file. Article 35(4) of the Enforcement Decree treats such system changes as new processing activities requiring re-assessment.
Ex-ante timing and designated assessment institutions. Article 33(1) PIPA requires the PIA to be conducted before the public institution establishes or operates the file. Article 33(4) requires the head of the public institution to request the assessment from a privacy impact assessment institution designated by the Personal Information Protection Commission (PIPC). Public institutions may not conduct the PIA in-house using only internal staff; the designated external institution prepares a written evaluation report, which the public institution must submit to the PIPC together with an implementation plan for recommended improvements (Art. 33(5) PIPA).
Required PIA content. Article 33(3) PIPA prescribes the minimum contents of a PIA:
- Analysis of the legal basis for collecting, using, and providing the personal information;
- Identification of matters requiring improvement to protect personal information and prevent infringement of data-subject rights;
- Assessment of security measures necessary to ensure safe management of personal information under Articles 24 and 29 PIPA (technical, administrative, and physical safeguards); and
- Other matters prescribed by Presidential Decree (Article 36 of the Enforcement Decree elaborates on required risk-factor analysis and improvement-measure documentation).
The PIPC publishes operational guidance (개인정보 영향평가 수행 안내서) specifying assessment methodologies, risk-scoring frameworks, and detailed procedures, though these guidelines are not binding law and serve as interpretive aids for the designated assessment institutions. As of September 5, 2025, the detailed procedures, minimum personnel qualifications for assessment institutions, and process for institution designation are codified in the PIPC's Privacy Impact Assessment Notification (고시: 개인정보 영향평가에 관한 규정), last amended by PIPC Notice No. 2025-7. This administrative rule provides binding procedural requirements and should be consulted for the latest process and compliance metrics in addition to the PIPA and its Enforcement Decree.
No administrative fine for PIA non-compliance; enforcement through PIPC supervision. Unlike the CPO designation duty (which carries an administrative fine of up to KRW 10 million under Article 75(2)(1) PIPA), Article 33 does not specify a direct monetary penalty for failure to conduct a PIA. The PIPC enforces PIA compliance through its general supervisory and corrective-order powers under Article 64 PIPA, which authorize the PIPC to order the public institution to suspend operation of the file, conduct the required PIA, or implement improvement measures. Persistent non-compliance may expose the head of the institution to disciplinary action or, in cases involving concurrent violations of Articles 15–18 PIPA (unlawful collection, use, or provision of personal information without a valid lawful basis), potential administrative fines under Articles 71 or 75 PIPA.
Comparison to GDPR Article 35 DPIA. South Korea's PIA regime is narrower in application than the GDPR's Data Protection Impact Assessment (DPIA) obligation (Regulation (EU) 2016/679, Article 35). GDPR Article 35 requires DPIAs for high-risk processing by any controller (public or private) when the processing is likely to result in a high risk to data-subject rights—covering systematic monitoring, large-scale processing of special categories of personal data, and automated decision-making with legal or similarly significant effects. South Korea's Article 33 PIA applies only to public institutions and uses bright-line numerical thresholds (1 million / 500,000 data subjects) rather than the GDPR's risk-based and context-dependent test. The substantive analysis required by Article 33—legal basis, necessity, security, data-subject rights—mirrors the GDPR's DPIA methodology in structure, reflecting alignment efforts recognized in the EU's adequacy decision for South Korea (Commission Implementing Decision (EU) 2021/2044 of 17 December 2021).
Transitional rule for existing files. Article 6 of the Addenda to the Enforcement Decree required public institutions operating personal information files covered by Article 35 as of the Decree's effective date to conduct a PIA and submit the result to the PIPC within five years from the date the Decree entered into force (September 29, 2011). Public institutions that registered their files before the Enforcement Decree took effect were exempt from this transitional requirement.
Source: Personal Information Protection Act, Act No. 19234, Article 33 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 35 Source: PIPC — Privacy Impact Assessment Source: PIPC Administrative Rule, Privacy Impact Assessment Notification (고시), PIPC Notice No. 2025-7 (effective September 5, 2025)
Personal information file registration — mandatory public-sector inventory under Article 32 PIPA
Public-institution filing duty; private-sector exemption. Article 32(1) of the Personal Information Protection Act (개인정보 보호법, PIPA) requires the head of every public institution that operates a personal information file (개인정보파일) to register specified particulars of each file with the Personal Information Protection Commission (PIPC, 개인정보보호위원회). The registration duty covers all public institutions defined in Article 2(6) PIPA: government agencies, local governments, and certain public organizations designated by Presidential Decree under Article 2 of the Enforcement Decree. Private-sector controllers are not subject to the Article 32 registration requirement—the filing obligation is strictly limited to the public sector and functions as Korea's closest analogue to the GDPR Article 30 ROPA requirement for public authorities, though South Korea's regime is narrower and uses a centralized registry.
Required particulars for registration (Article 32(1), Enforcement Decree Article 34). The statute and Article 34 of the Enforcement Decree (Presidential Decree No. 34413, as amended through March 15, 2024) enumerate the information that must be registered for each personal information file:
- Name of the personal information file and institution-assigned file number;
- Legal basis for the file (statute, ordinance, or regulation authorizing the processing);
- Purpose for operating the file (the specific task or objective);
- Categories of personal information stored, noting if it includes sensitive or unique identification information as defined by PIPA Article 23;
- Retention period for stored information;
- Persons/institutions to whom information may be provided, with legal basis and purpose;
- Entrustment arrangements (third-party processors), including name and scope of entrusted processing;
- Name, department, and contact of the Chief Privacy Officer or responsible official overseeing the file.
The registration process enforces governance discipline and transparency, as the PIPC maintains a public registry.
Timing and amendment obligations. While Article 32(1) does not fix an absolute deadline, Addenda to the Enforcement Decree have provided transitional windows (e.g., for pre-existing files at the Decree’s inception in 2011, the filing window was 60 days). For new files, registration is ex-ante, i.e., required before operation begins. Article 32(2) further requires prompt amendment (within 60 days) if any registered particulars change (retention period, legal basis, categories, etc.).
Public disclosure. Article 32(4) requires the PIPC to make public the list and details of all registered personal information files, providing transparency and data-subject awareness. The PIPC operates a public registration portal (개인정보 보호 종합지원 포털) for this purpose. As of June 2024, the official live registry is accessible at https://www.law.go.kr/LSW/eng/engLsSc.do?menuId=2&query=personal%20information%20protection%20act#liBgcolor0, instead of the old privacy.go.kr link.
Penalties. Failure to register or to timely amend registration may result in a corrective order (Article 64) and a fine up to KRW 10 million under Article 75(2)(1) PIPA, imposed on the institutional head. Persistent non-compliance risks additional administrative and personnel action.
Comparison to GDPR Article 30 ROPA. South Korea’s Article 32 duty is more limited than the GDPR's ROPA, applying only to public institutions, but is mandatory for all public-sector files, regardless of file size. Private-sector controllers have no statutory filing duty, though guidelines recommend maintaining internal records.
Source: Personal Information Protection Act, Act No. 19234, Article 32 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 34 Source: PIPC — Personal Information File Registration (Official Law Portal)
Private-sector documentation obligations — no statutory ROPA; privacy policy under Article 30 PIPA required
No statutory record-of-processing-activities (ROPA) requirement for private controllers. The Personal Information Protection Act (개인정보 보호법, PIPA) does not impose a GDPR Article 30-style record-of-processing-activities (ROPA) obligation on private-sector personal information controllers. Article 32 PIPA's personal information file registration duty applies exclusively to public institutions (정부기관, 지방자치단체, and designated public organizations under Article 2(6) PIPA and Article 2 of the Enforcement Decree). Private-sector controllers—corporations, sole proprietorships, non-profit organizations, and other non-governmental entities—are not required by statute to register their personal information files with the Personal Information Protection Commission (PIPC, 개인정보보호위원회) or to maintain an internal written inventory of processing activities in the manner prescribed by GDPR Article 30 for EU controllers and processors.
This is a material divergence from the GDPR, which requires every controller and processor (subject to a narrow small-enterprise exemption for entities employing fewer than 250 persons, applicable only when processing is occasional and does not involve special-category data or pose a risk to data-subject rights) to maintain a written ROPA containing the controller's or processor's name and contact details, purposes of processing, categories of data subjects and personal data, categories of recipients, international transfers, envisaged retention periods, and a general description of technical and organizational security measures (Regulation (EU) 2016/679, Article 30). The EU Commission's December 17, 2021, adequacy decision for South Korea (Commission Implementing Decision (EU) 2021/2044) did not identify the absence of a private-sector ROPA obligation as a gap requiring remedial measures, likely because the adequacy assessment prioritized substantive protections for data-subject rights (access, erasure, restriction, portability under Articles 35–37 PIPA) and lawful-basis requirements (Articles 15–18 PIPA) over controller-side documentation discipline.
Article 30 privacy policy — mandatory public disclosure, not internal inventory. Article 30(1) PIPA requires every personal information controller (public or private) to establish and publicly disclose a privacy policy (개인정보 처리방침) containing nine mandatory elements:
- Purpose of processing personal information (Art. 30(1)(1));
- Categories of personal information processed, including retention periods (Art. 30(1)(2));
- Provision of personal information to third parties, if applicable, specifying the recipient, purpose, and categories of personal information provided (Art. 30(1)(3));
- Consignment (outsourcing) of personal information processing, if applicable, including the name of the consignee and the scope of consigned processing (Art. 30(1)(4));
- Rights of data subjects under Articles 35–38 PIPA (access, correction, erasure, suspension of processing) and the procedures for exercising those rights (Art. 30(1)(5));
- Items of personal information subject to automated collection, if the controller uses automatic collection devices such as cookies (Art. 30(1)(6));
- Measures to ensure the security of personal information under Article 29 PIPA, including administrative, technical, and physical safeguards (Art. 30(1)(7));
- Name and contact information of the Chief Privacy Officer (CPO) designated under Article 31 PIPA (Art. 30(1)(8)); and
- Procedures for filing complaints related to personal information and contact details for the complaint-handling department (Art. 30(1)(9)).
Article 30(2) requires the controller to publicly disclose the privacy policy via the controller's website (if one exists) or, for controllers without an internet homepage, by posting the privacy policy in a conspicuous location at the controller's place of business where data subjects can easily review it. When the controller amends the privacy policy, Article 30(2) requires the controller to publicly announce the amendment at least seven days before the effective date (or at least 30 days' prior notice if the amendment is unfavorable to data subjects).
The Article 30 privacy policy functions as a transparency instrument for data subjects, analogous to GDPR Articles 13–14 (information to be provided when personal data are collected from or not obtained from the data subject) combined with GDPR Article 30's external-facing disclosure requirement in the public-authority context (GDPR Article 30(4) requires public authorities to make the ROPA available to the supervisory authority and, in certain member states, to the public). However, the Article 30 privacy policy is not an internal processing inventory—it does not require the controller to document the legal basis for each processing activity, map data flows between controllers and processors, or maintain versioned records of processing decisions for supervisory-authority inspection. The privacy policy must be updated whenever processing practices change, but PIPA does not mandate that the controller maintain an internal log or audit trail of past processing activities.
PIPC Standard Personal Information Protection Guidelines — best-practice recommendation to maintain internal processing records. The Personal Information Protection Commission publishes Standard Personal Information Protection Guidelines (표준 개인정보 보호지침) under Article 12 PIPA, which authorize the PIPC to recommend measures necessary for the protection of personal information and provide model forms, checklists, and governance frameworks for controllers. The PIPC's guidelines are not binding law—they serve as interpretive aids and governance best practices, and a controller's failure to follow a guideline recommendation does not, by itself, expose the controller to an administrative fine or corrective order under PIPA. However, the PIPC may cite a controller's deviation from the guidelines as evidence of inadequate security measures (Article 29 PIPA) or failure to fulfill the controller's duty to process personal information lawfully and transparently (Article 3 PIPA, general principles) in enforcement actions.
The PIPC's Standard Guidelines recommend that private-sector controllers maintain an internal inventory of personal information processing activities, including the categories of personal information processed, the legal basis for processing, retention periods, third-party recipients, consignees (processors), and security measures applied to each processing activity. This recommendation mirrors the GDPR Article 30 ROPA framework and reflects the PIPC's view that internal documentation is a necessary governance practice to enable the controller to respond to data-subject access requests under Article 35 PIPA, conduct internal audits of compliance with retention-period limits under Article 21 PIPA, and demonstrate compliance with security-safeguard requirements under Article 29 PIPA during a PIPC inspection. The guidelines also recommend that controllers document the CPO's oversight activities, maintain logs of data-subject rights requests and the controller's responses, and prepare written procedures for breach notification under Article 34 PIPA.
Practical consequence: voluntary adoption of ROPA-style documentation by multinational controllers. Because PIPA does not mandate an internal ROPA for private controllers, a purely domestic Korean company operating exclusively within South Korea and not subject to the GDPR, LGPD, or other regimes with statutory ROPA requirements could theoretically limit its documentation to the Article 30 public privacy policy and forego maintaining a detailed internal processing inventory. However, most multinational controllers operating in South Korea voluntarily maintain GDPR-style ROPAs for the following reasons:
- EU adequacy bridge. The EU Commission's adequacy decision for South Korea (Commission Implementing Decision (EU) 2021/2044 of December 17, 2021) permits transfers of EU personal data to Korean controllers without requiring Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), but only when the Korean controller processes the EU data in compliance with PIPA and demonstrates accountability mechanisms substantially equivalent to GDPR requirements. A controller that processes both Korean and EU personal data typically maintains a unified ROPA covering both data sets to satisfy GDPR Article 30 obligations for the EU data and to demonstrate governance maturity to the PIPC for the Korean data.
- PIPC enforcement posture. Although the PIPC cannot issue an administrative fine solely for failure to maintain an internal ROPA, the Commission has increasingly cited inadequate internal documentation as an aggravating factor in enforcement actions under Article 64 PIPA (corrective orders) and Article 75 PIPA (administrative fines). In high-profile breach investigations (including the 2020 enforcement actions against online service providers following large-scale credential-stuffing attacks), the PIPC has emphasized that controllers unable to produce contemporaneous records of processing decisions, security-measure implementation, and CPO oversight activities face heightened exposure to corrective orders and higher fine amounts under the proportionality analysis in Article 75(2) PIPA.
- Cross-border data transfer requirements. Article 17(3) PIPA (as amended in March 2023) requires controllers transferring personal information to foreign countries to obtain the data subject's separate consent after notifying the data subject of the receiving country, the transferee's name and contact information, the purpose and retention period of the cross-border transfer, and the fact that the data subject may refuse consent and the consequences of refusal. Controllers operating in multiple jurisdictions typically maintain an internal cross-border transfer inventory—functionally equivalent to a GDPR Article 30 ROPA section on international transfers—to enable the controller to provide accurate Article 17(3) notices and respond to PIPC inquiries during cross-border transfer compliance audits.
No penalty for lack of internal ROPA under PIPA. Article 75(2) PIPA, which enumerates administrative fines of up to KRW 10 million for specified violations, does not include failure to maintain an internal processing inventory among the fineable offenses. The only documentation-related fines under Article 75(2) are:
- KRW 10 million for failure to designate a Chief Privacy Officer under Article 31 PIPA (Art. 75(2)(1)); and
- KRW 10 million for public institutions' failure to register personal information files under Article 32 PIPA or to amend the registration within 60 days of a change (Art. 75(2)(1)).
Private-sector controllers that choose not to maintain an internal ROPA face no direct monetary penalty, though they may encounter operational difficulty demonstrating compliance during PIPC inspections, responding to data-subject access requests, or defending against allegations of unlawful processing under Articles 15–18 PIPA.
Comparison to peer regimes. South Korea's private-sector exemption from statutory ROPA requirements diverges from the GDPR (Article 30 mandatory ROPA for all controllers and processors, subject to the narrow <250-employee exemption), Brazil's LGPD (Art. 37 requires controllers to maintain records of processing operations, though the ANPD has not yet finalized the regulatory standard specifying the required contents), and China's PIPL (Article 54 requires controllers handling large volumes of personal information to designate a personal information protection officer and establish an independent oversight body, implicitly requiring documented processing inventories to enable oversight, though no explicit ROPA provision exists). The absence of a statutory ROPA obligation in South Korea reflects the statute's historical emphasis on ex-ante transparency to data subjects (Article 30 privacy policy, Article 15 collection notice) and ex-post supervisory-authority oversight (Article 64 PIPC inspection powers) rather than on continuous internal controller documentation. The adequacy decision's acceptance of this framework suggests that the EU Commission views the Article 30 privacy-policy requirement, combined with the PIPC's guideline-based encouragement of voluntary ROPA adoption and the Commission's enforcement posture rewarding documented governance, as functionally sufficient to protect EU data subjects transferred to South Korea under the adequacy bridge.
Source: Personal Information Protection Act, Act No. 19234, Articles 30–32 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 2 Source: PIPC — Privacy Guidelines
Domestic representative designation — mandatory for foreign controllers meeting Article 31-2 PIPA thresholds
April/October 2025 amendments — material expansion and clarification of foreign-controller agent obligations.
The regime for mandatory domestic representative (국내대리인) designation by foreign personal information controllers under South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법) was substantively amended by Act No. 20897 (promulgated April 1, 2025; effective October 2, 2025) and updated via the Enforcement Decree. These amendments broaden the triggers, add priority-use rules for affiliates, and implement specific supervision and training obligations, with new penalty and agency-relationship consequences for non-compliance.
Who must designate a domestic representative? As of October 2, 2025, any foreign personal information controller (without a Korean business presence) must appoint a domestic representative if ANY ONE of the following is true (Enforcement Decree Art. 32-3):
- The controller had KRW 1 trillion or more in total annual sales in the preceding year;
- The controller processed personal information of 1 million or more data subjects per day on average over the last three months of the most recent year;
- The PIPC issues an individual compliance order under Article 63(1) PIPA, based on risk or impact, requiring such appointment.
Priority-use of Korean affiliates and “significant influence” definition. A foreign controller that directly or indirectly established, or exercises significant influence (e.g., appointment/dismissal of CEO or >30% voting power) over, a domestic corporation must appoint that entity as its agent (PIPA Art. 31-2(4) & Enforcement Decree Art. 32-3(2)). Outsourcing to a third-party-only is now prohibited for such cases. Definition of "significant influence" tracks board and equity powers (Enforcement Decree Art. 32-3(3)).
Supervision, training, and compliance performance plan — new statutory duties (2025). Foreign controllers must:
- Provide annual training to the designated agent;
- Establish a written compliance performance plan for the representative;
- Conduct and document regular checks of the agent’s fulfilment of PIPA duties;
- Address inadequacies proactively and maintain evidence available for PIPC audit (Enforcement Decree Art. 32-3(4)-(6)).
Agent’s legal responsibilities and agency relationship. The agent must respond to data subject requests (Arts. 35–38), perform breach reporting (Art. 34), and cooperate fully with PIPC. Notably, violations/failures by the agent (if within the scope of material obligations) are imputed to the controlling foreign entity, with full overseas liability under Korean law (PIPA Art. 31-2(7)).
Penalties and enforcement enhancements. Failure to meet designation, training, affiliate-priority, or supervision obligations may trigger:
- PIPC corrective orders (Art. 64),
- Fines up to 3% of relevant revenue (Art. 64-2, as amended),
- Naming in PIPC compliance press releases.
Historical context: These 2025 changes raised Korea’s regime closer to GDPR Article 27 representative rules, but with a uniquely strict affiliate-mandate and ongoing supervision duties. Prior rules did not require routine agent training or restrict agent-selection to in-group entities.
Effective date and transition: Rules apply for all triggers met on or after October 2, 2025. Ongoing agency and training records must be maintained from this date.
Source: Personal Information Protection Act, Act No. 19234, Article 31-2 (as amended by Act No. 20897, eff. Oct. 2, 2025) Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Arts. 32-3, 32-4, as amended Sept./Oct. 2025
Chief Privacy Officer (CPO) liability and legal protections under PIPA — administrative, civil, and criminal exposure
Material 2026 PIPA amendments — CPO and representative liability, board oversight, and administrative penalty expansion
South Korea’s Personal Information Protection Act (PIPA), as amended by Act No. 20501 (promulgated March 10, 2026, with primary provisions effective September 11, 2026; ISMS-P requirements effective July 1, 2027), makes substantial changes to the liability and legal protections of Chief Privacy Officers (CPOs) and their organizations.
Administrative, civil, and criminal exposure — 2026 regime
- The CPO continues not to bear strict or vicarious civil or criminal liability merely for holding the office. Administrative fines for violations of PIPA’s CPO-related obligations (such as failure to designate or to empower a CPO, or non-performance of statutory duties) are imposed on the personal information controller or its statutory representative (usually the CEO or equivalent) — not on the CPO as an individual (Article 75(2)(1)), unless the CPO personally commits a direct violation (e.g., willful data leakage).
- Criminal liability under PIPA Articles 70–74 attaches only to parties who directly commit unlawful acts such as intentional disclosure or destruction of personal information; CPOs are not subject to strict or vicarious liability by virtue of their role.
Key statutory changes in 2026:
- CEO (representative director) accountability: New Article 30-3 (effective Sept 11, 2026) makes the business owner or representative ultimately responsible for ensuring personal information protection compliance. The representative is now expressly obligated to secure sufficient personnel, budgets, and authority for the CPO.
- CPO elevated governance status: Article 31(3) now requires, for large controllers (as defined by the Enforcement Decree):
- Board of directors’ resolution for CPO appointment, change, or removal.
- Prompt PIPC notification of any CPO change.
- Scope of administrative penalties expanded: Article 75(1)(12) raises the maximum available administrative fine to 10% of total annual sales for designated, severe, or repeated violations (previously capped at 3%). Incentives for proactive investments in data protection and remediation measures apply to reduce fines.
- No statutory indemnity, whistleblower, or refusal-right protections: As before, no explicit CPO-specific indemnity or anti-retaliation protection exists under PIPA or its Decree. Personal protections are governed by general labor law and the employment contract, not PIPA.
Effective dates:
- Most relevant amendments (Articles 30-3, 31, penalty regime) effective September 11, 2026.
- ISMS‑P certification and related IT governance measures (not directly tied to CPO liability) effective July 1, 2027.
Summary: The 2026 regime provides more explicit corporate liability and board-level oversight but maintains that CPOs bear personal risk only for direct violations of law, not for organizational or governance failures unless those violations are directly attributable to CPO action or omission. The new statutory maximum penalty heightens the organization’s exposure.
Source: Personal Information Protection Act, Act No. 19234 as amended by Act No. 20501, Articles 30-3, 31, 70–75 (Korean/English) Source: PIPC update notice on 2026 PIPA amendments
Personal information file amendment and unregistration — Article 32(2)(3) PIPA and Article 34 Enforcement Decree procedural rules
Statutory amendment and unregistration duties. Article 32(2) of South Korea’s Personal Information Protection Act (PIPA, Act No. 19234) requires the head of a public institution to promptly amend the registration of a personal information file when any registered particulars change. Article 32(3) further requires prompt unregistration (deregistration) when the institution no longer manages the file. These requirements operationalize PIPA’s principle of data accuracy and accountability for public-sector processing.
Scope and process for amendments. The triggering events for mandatory amendment are any changes to the particulars detailed at filing, including the name or legal basis of the file, purpose of processing, categories or retention period of personal information, recipients, entrustment details, or responsible CPO/official. Under Article 34(3) of the Enforcement Decree (Presidential Decree No. 34413), amendments must be registered with the Personal Information Protection Commission (PIPC) within 60 days of the change. The obligations apply to both wholly new particulars and corrections—e.g., adding new categories of sensitive information, changing consignees, or shortening a retention period. Failure to submit a timely amendment is subject to an administrative fine of up to KRW 10 million (Art. 75(2)(1) PIPA).
Unregistration (deregistration). When a public institution ceases to operate a personal information file—either through data minimization, merger, reorganization, or the conclusion of a statutory retention period—Article 32(3) PIPA requires the head to deregister the file promptly. Article 34(4) of the Enforcement Decree handles the process: The institution files a deregistration application to the PIPC, providing the file name, file number, reason for unregistration, and evidence that all personal information in the file has been deleted or transferred in accordance with law. The PIPC then updates the public registry accordingly. There is no prescribed grace period; deregistration is expected immediately on cessation of operation. As with amendments, failure to deregister is subject to the same administrative fine scheme under Article 75(2)(1) PIPA.
Supervisory verification, corrective orders, and enforcement. The PIPC may review amended or deregistered files to verify substantive compliance—i.e., that changes were accurately reported and that deletion/transfer has been properly carried out (Art. 64 PIPA, corrective orders). Deliberate omission or delay may trigger both a corrective order and an administrative fine. In cases of willful misstatement or obscuration (e.g., failing to report a new category of special-category data or a new processor), the PIPC may apply aggravating factors when setting the fine within the statutory cap.
Operational impact. Ongoing compliance with the amendment and deregistration duties requires public institutions to maintain close internal tracking of file lifecycle events, statutory retention triggers, and all operational changes that might affect the contents of the public registry. It is standard practice to tie file-registration update reviews to periodic internal audit and record-destruction cycles.
Source: Personal Information Protection Act, Act No. 19234, Article 32 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 34
PIA procedural standards and designated assessment institutions under the PIPC Administrative Rule
The detailed process for conducting Privacy Impact Assessments (PIAs) in South Korea’s public sector is set by the Personal Information Protection Commission (PIPC) Administrative Rule, “Regulation on Privacy Impact Assessments” (개인정보 영향평가에 관한 규정). Article 33 of the Personal Information Protection Act (PIPA, Act No. 19234) establishes the requirement for public institutions to conduct PIAs, but the step-by-step requirements and institutional roles are implemented through this Rule, which was last amended on March 8, 2024.
Stepwise PIA workflow and procedural content
The Administrative Rule (고시) lays out a required PIA workflow:
- The institution conducts an initial self-assessment to determine whether a PIA is required, applying triggers set in PIPA and the Enforcement Decree (고시 Art. 2–4).
- If a PIA is triggered, the institution must formally request assessment from a PIPC-designated assessment institution (고시 Art. 7–9).
- The assessment institution conducts the PIA. This includes document review, physical or technical investigation if relevant, interviews with staff, and risk analysis following the evaluation framework set in Annex 2 (고시 Art. 10–12, Annex 2).
- The institution submits the completed assessment report, along with any improvement action plans, to the PIPC (고시 Art. 14).
Standards and designation of assessment institutions
Only institutions specifically designated by the PIPC may perform official PIAs (고시 Art. 4). Personnel qualifications are regulated: under 고시 Art. 5, an assessment body must have at least two assessors per assessment, each holding relevant personal information protection qualifications or a minimum of three years’ experience in privacy, law, or IT security. Designated institutions face conflict-of-interest requirements (cannot assess systems in which they have design roles, 고시 Art. 6), are periodically reviewed by PIPC, and may have designation revoked for breaches (고시 Art. 16–18).
PIA report content and public disclosure
The Rule’s Annex 2 specifies required PIA report contents: legal basis for processing, necessity and proportionality, assessment of risk to data subjects, adequacy of security and technical measures, third-party consultation, and residual risk documentation. The completed report must be disclosed to the public except where disclosure would violate other laws or endanger national security, security of the institutions, or public safety (고시 Art. 15 lists the exceptions).
The current text of the Administrative Rule, as published on law.go.kr, is the primary authority for the latest PIA process. Practitioners should check for updates before each new PIA to ensure compliance with current requirements.
Source: PIPC Administrative Rule on Privacy Impact Assessments (고시: 개인정보 영향평가에 관한 규정, as amended through March 8, 2024), Articles 2–6, 10–12, 14–18, Annex 2 Source: Personal Information Protection Act, Act No. 19234, Article 33
Chief Privacy Officer (CPO) independence and conflict-of-interest safeguards under the Enforcement Decree
South Korea’s Enforcement Decree of the Personal Information Protection Act (PIPA) sets out specific measures to ensure the independence of the Chief Privacy Officer (CPO, 개인정보 보호책임자) in large organizations.
Structural supports for CPO independence. Article 32-2 of the Enforcement Decree (Presidential Decree No. 34413, effective March 15, 2024) requires personal information controllers that exceed both KRW 10 billion in annual sales and process at least 1 million data subjects’ personal information during the last three months of the previous year to implement documented measures reinforcing the CPO’s independence:
- Direct reporting: The CPO must report directly and regularly to the organization’s representative or board of directors, ensuring the reporting line cannot be bypassed (Art. 32-2(6)).
- Information access: The CPO must have access to all necessary information on personal information processing to perform statutory duties (Art. 32-2(7)).
- Resources and staffing: Adequate personnel, budget, and operational authority must be provided to the CPO, so that privacy oversight is not subordinated to other functions (Art. 32-2(8)-(9)).
Conflict-of-interest restrictions. The Enforcement Decree specifically prohibits CPOs from occupying certain concurrent roles that would threaten independence:
- The CPO may not serve as the organization’s representative responsible for business operations.
- The CPO cannot perform duties as an internal auditor for personal information protection.
- The CPO cannot occupy other conflicting posts prohibited by law or by an external audit firm (Art. 32-2(10)-(11)).
Documentation and compliance. Qualifying organizations must keep records of how they satisfy CPO independence and conflict safeguards and be prepared to present these to the Personal Information Protection Commission (PIPC) upon request. The statutory framework does not categorically prohibit a CPO from holding all other positions, but mandates clear functional and supervisory separation for these key duties.
Failure to comply with these requirements can result in corrective orders by the PIPC or administrative fines under Article 64-2 PIPA, subject to the Commission’s findings on compliance failures.
PIA report content and risk analysis — required statutory elements under PIPA Article 33 and Enforcement Decree Article 36
South Korea’s Personal Information Protection Act (PIPA) and its Enforcement Decree set out specific minimum content requirements for Privacy Impact Assessment (PIA) reports prepared by public institutions under Article 33. Practitioners must closely follow these statutory and regulatory elements, as failure to do so may lead to corrective orders by the Personal Information Protection Commission (PIPC).
PIA core elements under Article 33(3) PIPA: The PIA report must include, at a minimum:
- An analysis of the legal grounds for collection, use, and provision of personal information as planned by the institution;
- Identification of matters requiring improvement with respect to data protection and prevention of infringement of data subjects’ rights;
- Assessment of security measures deemed necessary for safe management and protection of personal information in line with Articles 24 and 29 PIPA;
- Any additional items prescribed by Presidential Decree.
Detailed requirements under Enforcement Decree Article 36: The Enforcement Decree provides further instruction on required PIA content. According to Article 36, the PIA report must include:
- An analysis and evaluation of risk factors related to each phase of personal information processing—specifically, the likelihood of leakage or infringement of data subjects’ rights or interests.
- The specific improvement measures to address identified risks, with indications of how the improvements will be implemented.
- Other matters as determined necessary for risk reduction and protection of data subjects, as detailed by the PIPC in rules or forms made under its authority (but only to the extent required by law or decree).
Notably, the Decree does not require public consultation, third-party stakeholder input, or a prescribed risk-matrix format; such practices may be recommended in non-binding PIPC guidelines, but are not statutory requirements. The PIA must assess risk and document the improvement measures that the public institution will implement to address those risks.
If further standards are established by the PIPC, or if additional forms are prescribed administratively, institutions must consult those as well, but only requirements arising from the PIPA and its Decree are compulsory.
Source: Personal Information Protection Act, Act No. 19234, Article 33 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 36
Chief Privacy Officer (CPO) change, removal, and succession — statutory notification and appointment procedures under PIPA (including 2026 amendments)
Updated statutory requirements for CPO changes — 2026 amendments and enforcement procedures
South Korea’s Personal Information Protection Act (PIPA), as amended by Act No. 21445 (passed February 12, 2026; promulgated March 10, 2026; effective September 11, 2026), materially strengthens the statutory procedures for designating, changing, or removing a Chief Privacy Officer (CPO).
1. Board resolution and PIPC notification for large controllers (effective September 11, 2026) Under Article 31(3) PIPA, as amended, any personal information controller meeting thresholds to be specified by Presidential Decree must:
- Obtain a board of directors’ resolution before appointing, changing, or dismissing its CPO;
- Promptly notify the Personal Information Protection Commission (PIPC) of any CPO appointment, change, or removal.
As of June 2026, the relevant thresholds and procedural details (e.g., "large controller" definition) are pending finalization in the Enforcement Decree. The June 2026 draft proposes a threshold consistent with existing standards: controllers with annual sales of at least KRW 10 billion AND processing data of 1 million or more data subjects in the previous quarter. Monitor the evolving Decree text for changes before the September 2026 effective date.
2. Continuous CPO coverage and public disclosure All controllers must always have a designated CPO in function (Art. 31(1)-(2) PIPA). Article 30(1)(8) further requires public disclosure on the controller’s website or privacy policy of the current CPO’s name and contact details. Any change (including temporary or acting status) must be updated both internally and publicly with no statutory gaps allowed.
3. Interim status and succession The statute remains silent on interim or acting CPO designation during short-term leave or vacancy. However, uninterrupted CPO function is required. Best practice, as acknowledged by PIPC guidance, is to promptly document and disclose interim arrangements if the permanent CPO is unavailable.
4. Penalties for violation Controllers failing to comply with the board approval or notification requirements, or leaving the CPO role unfilled, are subject to PIPC corrective orders and administrative fines up to KRW 10 million under Article 75(2)(1) PIPA.
Recent material change:
- Article 31(3) PIPA now requires, as of September 11, 2026, both a board resolution and PIPC reporting for CPO appointments/changes/removals at large controllers. Thresholds and notification specifics to be confirmed by the pending amended Enforcement Decree.
Source: Personal Information Protection Act, Act No. 21445 (2026), Article 31, 75 Source: Draft amended Enforcement Decree of the Personal Information Protection Act (June 2026 notice)
Personal information retention and destruction obligations under PIPA — statutory timelines, methods, and documentation (Articles 21 & 26)
Retention limitation principle and destruction duty.
South Korea’s Personal Information Protection Act (PIPA, Act No. 19234) sets out clear statutory requirements for how long controllers may retain personal information and the procedures to be followed for its destruction once the purpose of processing has been achieved. Article 21 PIPA establishes the core principle: a controller must, without delay, destroy personal information when the retention period agreed with the data subject or set by law has expired, or when the personal information becomes unnecessary for its originally stated purpose (such as when the data subject withdraws consent or the business relationship ends).
Mandatory destruction triggers.
- Expiration of a statutory or agreed retention period. Article 21(1)(1).
- Achievement of purpose, cessation of service, or withdrawal of consent. Article 21(1)(2).
Controllers must take immediate action to destroy personal information in these cases unless another statute requires continued retention (e.g., accounting or tax law). The law forbids indefinite storage and imposes a proactive duty to monitor and act.
Destruction methods and documentation.
- Article 21(3) PIPA requires destruction “without delay” using irrecoverable physical or technical means—such as incineration, physical shredding, or secure deletion for digital media. The specific methods are to be prescribed by Presidential Decree, and Article 16 of the Enforcement Decree mandates that destroyed information cannot be restored or reconstructed.
- Controllers must keep records of destruction, including the date, method, and scope (Art. 21(4) PIPA; Enforcement Decree Art. 16(3)). These records must be preserved for three years and presented to the Personal Information Protection Commission (PIPC) upon request.
Separate storage for dormant accounts. Article 39-6 PIPA (originally “dormant account” provisions, introduced by 2014 and updated) requires information related to users of online services who have not used the service for the previous one year or more to be stored separately and managed, and to be destroyed on reaching the retention or dormancy period unless otherwise required by law. Service providers must notify users at least 30 days in advance of destruction or separate storage.
Processor (entrustment) destruction duty. Article 26(2)(6) PIPA requires any processor (a consignee entrusted with processing personal information, 위탁받은자) to destroy personal information immediately after the termination of the outsourcing contract—mirroring the requirements on controllers for direct collection.
Enforcement and fines. Failure to destroy personal information in accordance with Article 21 and/or 26 is subject to corrective orders and may expose the controller or processor to administrative fines of up to KRW 50 million (Article 75(1)(5) PIPA; as amended 2023).
Practical compliance tips:
- Regularly schedule destruction events/timelines.
- Log every destruction and retain destruction logs for three years.
- Promptly separate data for dormant users and notify them as required.
- Ensure processors contractually agree and execute destruction post-engagement.
Source: Personal Information Protection Act, Act No. 19234, Articles 21, 26, 39-6, 75 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 16
CPO internal audit duty and compliance monitoring under Article 31(4) PIPA — statutory requirements and PIPC expectations
Statutory audit and compliance-monitoring duty. Article 31(4) of South Korea’s Personal Information Protection Act (PIPA, Act No. 19234) lists as a core duty of the Chief Privacy Officer (CPO) the obligation to “conduct regular investigations and improvements on the current status of personal information processing.” This is interpreted as a requirement for ongoing internal audit and compliance monitoring covering both policy and operational practice. The implementing detail appears in the CPO duties list (Article 31(4)(4) PIPA), but neither the PIPA nor its Enforcement Decree prescribes a specific audit cycle, methodology, or reporting format, leaving these to be set by each controller’s governance framework subject to PIPC oversight.
Governance best practices and audit records. While the law is silent on fixed audit periodicity, the Personal Information Protection Commission (PIPC) has, through its Standard Personal Information Protection Guidelines (표준 개인정보 보호지침, issued under Article 12 PIPA), recommended:
- An annual or biannual audit covering compliance with PIPA requirements (lawful basis, minimization, retention, breach management, and data-subject rights procedures);
- Documentation of audit findings, including identified risks/gaps and corrective actions taken;
- Retention of audit records for at least three years to demonstrate to the PIPC, if inspected, that governance activities are ongoing and substantive;
- Inclusion of audit scope and results in management or board reporting (for mid-to-large controllers, especially those subject to Article 32-2 Decree obligations);
- Use of both self-assessment checklists (commonly based on PIPC sample forms) and, for larger enterprises, periodic internal or external legal review.
Controllers are expected, if inspected by the PIPC, to produce audit logs, evidence of corrective action, and updated status reports reflecting addressing of prior findings. Failure to document an actual, periodic audit cycle risks a finding of ineffective CPO function, and may be cited as an aggravating factor if other violations (breach, unauthorized processing, etc.) are found.
Connection to CPO’s reporting and independence. For controllers meeting the large-entity thresholds of Article 32-2 of the Enforcement Decree (annual sales ≥ KRW 10 billion and 1 million+ data subjects processed), audit results must be reported directly to the organization’s head or board, and the audit must cover all material risks identified by CPO or internal audit. The CPO’s independence protections include not only authority to conduct such audits, but also a right to access all relevant documentation and systems. This regime is intended to supplement—not replace—PIPC’s own ex-post inspection and corrective authority under Articles 63–64 PIPA.
No fixed template, but failure to audit is enforceable as a compliance failure. The PIPC’s guidelines emphasize substantive, documented effort rather than box-ticking. A controller that fails to carry out and record regular internal audits is at risk of a corrective order (Article 64 PIPA) or, in aggravating cases, administrative fines if absence of internal audit supports other compliance failings. There is no statutory penalty for a single missed audit if all other compliance measures are in place, but recidivism or evidence of willful neglect heightens regulatory consequence.
Source: Personal Information Protection Act, Act No. 19234, Article 31(4) Source: PIPC — Personal Information Protection Guidelines
CPO suspension, incapacity, and interim appointment — statutory treatment of temporary absence or conflict under PIPA and Enforcement Decree
No explicit statutory regime for interim CPO appointment or suspension due to incapacity/conflict.
Neither the Personal Information Protection Act (PIPA, Act No. 19234, as amended through 2026) nor the Enforcement Decree (Presidential Decree No. 34413) prescribes a detailed statutory procedure for the temporary suspension of a Chief Privacy Officer (CPO), appointment of an interim/acting CPO, or forced recusal due to conflict of interest or incapacity.
Continuous CPO presence required; no statutory gap allowed. Article 31(1) PIPA mandates that every controller must always have a designated CPO in function. While Article 31(3) (as elaborated by Art. 32-2 of the Enforcement Decree) governs the process for formal appointment or removal (e.g., resignation, board-approved change in large organizations), neither the Act nor the Decree contain provisions for temporary leave, incapacity, recusal, disciplinary suspension, or automatic succession for periods of absence. There is no specific article or clause requiring the designation of an "acting" or "interim" CPO, nor formal recognition of such status by the Personal Information Protection Commission (PIPC).
Controller’s governance responsibility in practice. In the absence of a statutory regime, the burden falls on the personal information controller to ensure that someone with suitable authority and qualifications is continuously in position to fulfill CPO duties. Best practice, recognized in PIPC guidelines and referenced in enforcement materials, is to promptly designate and document an acting CPO (e.g., via internal decision, board minutes, or HR orders) whenever the designated CPO is unable to fulfill duties due to leave, conflict, or external investigation. The acting CPO should have decision-making authority equivalent to that required by Article 31(4) PIPA for the substantive discharge of CPO functions. Failure to have an in-function CPO, even briefly, exposes the controller to an administrative fine up to KRW 10 million under Article 75(2)(1) PIPA.
Conflict of interest and independence safeguards. Article 32-2 of the Enforcement Decree prohibits CPOs at large controllers from holding certain conflicting roles (such as being the organization’s representative or internal auditor), but does not provide for suspension or recusal procedures. If a conflict is discovered, the controller must remedy the situation—either by removing the CPO or changing internal assignments—without statutory delay. No provision details recusal, partial suspension, or independent review procedures. Guidance from the PIPC encourages immediate correction but does not require a formal suspension framework.
Current enforcement and recommended practice. As of June 2026, the PIPC has not published binding guidance or a required protocol for temporary CPO absence or conflict. Controllers are expected to document their approach, promptly ensure coverage, and update their privacy policy and registry disclosures as soon as practicable. There is no statutory penalty for appointing an acting/interim CPO, provided the role is filled without gap.
Unable to confirm the existence of a detailed statutory procedure or PIPC binding guideline addressing interim CPO designation, suspension, or incapacity as of 2026-06-17. All statements above are grounded in statutory and regulatory silence, confirmed by absence of relevant rules on law.go.kr and pipc.go.kr as of the review date.
Source: Personal Information Protection Act, Act No. 19234, Article 31 Source: Enforcement Decree of the Personal Information Protection Act, Presidential Decree No. 34413, Article 32-2