Administrative penalty surcharge — Article 64-2 PIPA and the 3%/10% revenue ceiling (2023–2026 amendments) (corrected)
South Korea’s Personal Information Protection Commission (PIPC) may impose an administrative penalty surcharge for violations of the Personal Information Protection Act (PIPA) under Article 64-2, not Article 34-2. This reflects amendments effective since September 2023, with a further upgrade effective September 2026.
Current statutory regime: 3%/10% revenue-based penalty surcharges
- 3% Ceiling (since 15 September 2023): Under the September 2023 amendment (Act No. 19234), the maximum administrative penalty surcharge is set at 3% of the controller’s total annual revenue for ordinary violations. The cap applies to domestic and foreign controllers, both online and offline. The percentage is assessed on the average annual sales for the preceding three business years. Controllers must substantiate if revenue is unrelated to the violation, or the surcharge base includes all revenue (Article 64-2(2) PIPA, as amended).
- 10% Ceiling for Aggravated Violations (from 11 September 2026): The March 2026 amendment (Act No. 20509, promulgated 10 March 2026, effective 11 September 2026) expands PIPC’s authority to levy surcharges up to 10% of total revenue for repeat or severe violations (e.g., intentional or grossly negligent conduct affecting more than 10 million data subjects, or breach after ignoring a corrective order). Where no revenue can be established, the maximum surcharge is KRW 5 billion.
- The 3% cap remains in place for ordinary violations not falling within the specified aggravated categories. Appendix 2 of the Enforcement Decree (as of September 2023) sets aggravating/mitigating criteria, with further implementation detail to be published for the 2026 changes.
Legal process and context Surcharges can be imposed alongside corrective orders or administrative fines. Judicial review is available in the Seoul Administrative Court. The penalty framework applies to conduct post-effective date; for violations prior to September 2023, legacy rules may still control.
Summary of effective dates:
- 3% ceiling: in effect since 15 September 2023 (Act No. 19234)
- 10% ceiling for aggravated violations: effective 11 September 2026 (Act No. 20509)
Correction note: Prior versions of this guide incorrectly cited Article 34-2 as the authority for administrative penalty surcharges. The governing provision is Article 64-2.
Source: Personal Information Protection Act (PIPA), Article 64-2, as amended by Act No. 20509, effective 2023-09-15, 2026-09-11 Source: PIPC — Laws & Regulations
Criminal penalties under Articles 70–73 PIPA — imprisonment and fine tiers
The Personal Information Protection Act (PIPA) retains criminal liability for egregious personal-information violations, notwithstanding the 2023 shift from criminal sanctions to administrative penalty surcharges for many ordinary processing violations. Articles 70 through 73 PIPA establish a three-tier sentencing structure based on the gravity of the offense, with imprisonment terms ranging from three to ten years and fines from KRW 30 million to KRW 100 million. Criminal proceedings under PIPA are prosecuted by the public prosecutor's office following investigation and referral by the Personal Information Protection Commission (PIPC), or upon direct complaint by a data subject when the controller has violated the data subject's rights under Article 4 PIPA.
Article 70 — imprisonment up to 10 years (most severe tier)
Article 70 PIPA provides for imprisonment with labor for not more than ten years or a fine of not exceeding KRW 100 million (approximately USD 70,000 as of 2026) for the following offenses:
- Acquisition or use of personal information through theft or fraudulent means in violation of Article 59 PIPA (as amended 24 July 2015). This offense criminalizes a person who steals personal information from a controller or processor, or obtains it through deception, fraud, or other unlawful means (for example, social engineering, hacking, or impersonation). The ten-year maximum is the highest penalty tier in PIPA and reflects the legislature's determination that theft of personal data is analogous in harm to theft of property or other valuable assets.
- Receipt or use of stolen personal information with knowledge that it was obtained unlawfully. A person who knowingly receives, uses, or discloses personal information obtained by another person through theft or fraud is subject to the same ten-year maximum as the original thief, reflecting joint criminal liability for downstream exploitation of stolen data.
Article 70 does not require proof of financial gain or intent to cause harm; knowledge that the personal information was unlawfully obtained is sufficient for conviction. The ten-year ceiling applies even when the defendant is a natural person acting outside an organizational context (for example, an individual hacker or data broker).
Article 71 — imprisonment up to five years (intermediate tier)
Article 71 PIPA, as amended 14 March 2023 (effective 15 September 2023), provides for imprisonment with labor for not more than five years or a fine of not exceeding KRW 50 million for the following offenses:
- Intentional re-identification of pseudonymized personal information in violation of Article 28-5(1) or Article 28-6(3) PIPA. PIPA permits processing of pseudonymized data for statistical analysis, scientific research, and public-records management without consent (Article 28-2), but Article 28-5 prohibits any person from processing pseudonymized information with the intent or for the purpose of re-identifying a specific data subject. A person who deliberately reverses pseudonymization to identify an individual—for example, by combining pseudonymized datasets with auxiliary data to isolate a unique individual—commits a criminal offense under Article 71.
- Unlawful access to or leakage of personal information processed by a video-information processing device in violation of Article 25(5) PIPA. Video-information processing devices (CCTV, surveillance cameras, dashcams, and other recording equipment) are subject to heightened restrictions under PIPA, including installation notice, purpose limitation, retention-period limits, and viewing-access controls. A person who accesses recorded video footage without authorization, leaks footage to a third party, or uses footage for a purpose incompatible with the original collection purpose commits a criminal offense. This provision applies to employees of the controller (for example, building-security staff who improperly access CCTV feeds), as well as third parties who hack into surveillance systems.
- Arbitrary manipulation or alteration of a video-information processing device to perform functions not disclosed in the installation notice or to operate the device in a manner that violates Articles 25(1)–(4) PIPA. For example, a building owner who installs a CCTV camera with facial-recognition capability but does not disclose that capability in the posted notice commits a criminal offense if the camera is later activated to perform facial recognition without updating the notice and obtaining consent.
The five-year maximum under Article 71 reflects legislative concern about the intrusive nature of video surveillance and the heightened privacy harm from re-identification of pseudonymized data. Prior to the 2023 PIPA amendments, Article 71 also criminalized providing personal information to a third party without consent (former Article 71(2)), but that offense was removed from the criminal tier and replaced with the administrative penalty surcharge under Article 34-2(1)(2) PIPA.
Article 72 — imprisonment up to three years (least severe criminal tier)
Article 72 PIPA, as amended 14 March 2023, provides for imprisonment with labor for not more than three years or a fine of not exceeding KRW 30 million for the following offense:
- Violation of Article 59 PIPA by processing personal information beyond the scope permitted for a person who became aware of personal information in the course of performing duties under PIPA or another Act. Article 59 PIPA imposes a confidentiality obligation on current and former employees of the PIPC, designated complaint-handling institutions (such as the Korea Internet & Security Agency, KISA), and sectoral regulators who obtain access to personal information in the course of investigating complaints, conducting audits, or performing other official duties. A PIPC investigator who discloses personal information obtained during an on-site inspection to a third party for personal gain, or who uses that information for a purpose unrelated to the official investigation, commits a criminal offense under Article 72.
This provision also applies to employees of private-sector controllers and processors who process personal information beyond the scope of their duties, but the three-year maximum is reserved for violations by persons who obtained the information because of their official or employment status under PIPA (Article 59), as distinct from theft or fraud under Article 70.
Article 73 — attempt liability
Article 73 PIPA provides that an attempt to commit any offense under Articles 70 or 71 is punishable. PIPA does not criminalize attempts to commit Article 72 offenses. Attempt liability attaches when a person takes a substantial step toward committing the offense but does not complete it—for example, a person who initiates a re-identification algorithm against pseudonymized data with intent to identify a data subject but is stopped before the algorithm completes, or a person who begins unauthorized access to a CCTV system but is detected and blocked before viewing any footage.
The sentencing range for an attempt is the same as for the completed offense under Articles 70–71 (up to ten or five years, respectively), but South Korean courts have discretion to mitigate the sentence under Article 25 of the Criminal Act when the attempt did not result in harm.
Confiscation of criminal proceeds — Article 74 PIPA
Article 74 PIPA authorizes the court to confiscate any money, goods, or other profits acquired by a person who has violated Articles 70 through 73 in relation to the violation, or to collect the equivalent value if confiscation is impossible (for example, if the proceeds have been spent or transferred). Confiscation or collection may be levied in addition to the imprisonment or fine imposed under Articles 70–72. For example, if a data broker knowingly purchased stolen personal information for KRW 10 million and resold it for KRW 50 million, the court may confiscate the KRW 50 million gross proceeds (or collect that value if the funds are no longer available) in addition to imposing a sentence of up to ten years' imprisonment and a fine of up to KRW 100 million.
Prosecution discretion and the 2023 decriminalization trend
The March 2023 PIPA amendments narrowed the scope of criminal liability by removing several offenses from Articles 70–72 and replacing them with administrative penalty surcharges under Article 34-2. Prior to the reform, a controller who provided personal information to a third party without consent faced criminal liability (imprisonment up to five years or a fine of up to KRW 50 million under former Article 71(2)). The 2023 amendments eliminated that criminal exposure for ordinary controllers and replaced it with an administrative fine of up to 3% of total revenue, reserving criminal penalties for theft, intentional re-identification, and video-surveillance violations.
However, the PIPC retains discretion to refer cases to the public prosecutor even when an administrative penalty has been imposed. In practice, the PIPC refers for criminal prosecution only when the violation involves intentional misconduct, significant harm to data subjects, or refusal to comply with corrective orders. The shift from criminal to administrative enforcement reflects a legislative judgment that economic sanctions are more effective than imprisonment for deterring ordinary processing violations by corporate controllers, while preserving imprisonment for natural persons who commit theft, fraud, or other intentional harms.
Interplay with administrative penalties
Article 75 PIPA clarifies that no additional administrative fine shall be imposed under Article 75 for any act subject to criminal penalties under Articles 70–73. However, the PIPC may impose an administrative penalty surcharge under Article 34-2 before referring the case for criminal prosecution, and the surcharge is not automatically refunded if the prosecutor declines to indict or the court acquits the defendant. Controllers subject to both criminal investigation and an administrative penalty proceeding should coordinate their legal strategy to avoid inconsistent defenses.
Private right to damages — Articles 39, 39-2, and 39-3 PIPA civil compensation and punitive damages
The Personal Information Protection Act (PIPA) grants data subjects a private right of action to claim compensatory and punitive damages directly from personal-information controllers and processors who violate PIPA obligations. Articles 39 through 39-3 PIPA establish a three-tier civil-liability framework: (1) general tort-based damages under Article 39(1) PIPA, requiring proof of fault and actual harm; (2) statutory damages under Article 39-2 PIPA (up to KRW 3 million per violation) when the amount of loss is difficult to prove but a qualifying breach occurred; and (3) punitive damages under Article 39-3 PIPA of up to five times actual damages when the violation resulted from intentional or grossly negligent conduct. This private-enforcement regime operates in parallel with the Personal Information Protection Commission's (PIPC) administrative penalty surcharge under Article 34-2 PIPA and criminal penalties under Articles 70–73 PIPA, giving data subjects independent standing to seek compensation without awaiting PIPC enforcement action.
Article 39(1) — general damages for fault-based violations
Article 39(1) PIPA provides that a personal-information controller or processor who violates PIPA obligations and thereby causes property damage or mental suffering to a data subject shall be liable to compensate for the resulting damages. This provision adopts a fault-based negligence standard consistent with the Korean Civil Act (Articles 750–751): the data subject must prove (i) that the controller violated a PIPA obligation (for example, processed personal information without a lawful basis under Article 15 PIPA, provided data to a third party without consent under Article 17 PIPA, or failed to implement security measures under Article 29 PIPA), (ii) that damage occurred (pecuniary loss or mental distress), (iii) causation between the violation and the harm, and (iv) that the controller acted with intent or negligence.
Burden of proof on the controller — Article 39(2) reversal
Article 39(2) PIPA reverses the burden of proof on fault once the data subject establishes that a PIPA violation occurred and that damage resulted. The statute provides that "when personal information has been infringed, the relevant personal information controller shall be liable for such damage," and the controller may avoid liability only if it proves that "there was no intention or negligence on its part." This reversal places the burden on the controller to affirmatively demonstrate that it took all reasonable measures to comply with PIPA and that the violation occurred despite those measures (for example, a security breach caused by a novel zero-day exploit against which the controller had implemented state-of-the-art defenses).
In practice, Korean courts have interpreted the reversed burden narrowly: a controller that did not implement baseline security measures required under Article 29 PIPA and the Security Safeguard Standards (Notification No. 2023-63 of the PIPC, effective 15 September 2023) will not satisfy the no-fault defense merely by showing that the breach was committed by a sophisticated third-party attacker. The controller must demonstrate specific, documented compliance efforts (encryption of sensitive data at rest and in transit, access controls, penetration testing, and incident-response planning) and show that the breach was unforeseeable notwithstanding those measures.
Compensable harm — pecuniary and non-pecuniary damages
Article 39(1) compensates both property damage and mental suffering (정신적 고통). Property damage includes direct financial loss such as fraudulent charges on a credit card after a data breach, identity-theft remediation costs, and loss of business reputation for a legal-entity data subject. Mental suffering encompasses emotional distress, anxiety, and loss of privacy, which Korean courts treat as compensable non-pecuniary harm analogous to pain and suffering in personal-injury cases.
However, Korean courts have imposed a high evidentiary bar for non-pecuniary damages in data-breach cases. The Supreme Court of Korea, in a February 2026 decision involving encrypted email-address leaks, held that a data subject must prove that the leaked information was sufficiently sensitive and identifiable to cause actual mental distress; the mere fact that a breach occurred does not, without more, establish compensable mental harm. The Court ruled that lower courts should consider the nature of the leaked data (highly sensitive categories such as resident registration numbers, health records, or financial account details versus less-sensitive identifiers such as encrypted email addresses), the identifiability of the data subject (whether the leaked data included the data subject's name or other direct identifiers), and the risk of misuse (whether the data was accessed by malicious third parties or remained within a controlled environment). This decision sharply limits Article 39(1) damages for low-sensitivity breaches and signals that controllers may successfully defend mental-distress claims by showing that leaked data was anonymized, encrypted, or otherwise not linked to an identifiable individual.
Article 39-2 — statutory damages of up to KRW 3 million
Article 39-2 PIPA, as amended effective 15 September 2023, authorizes Korean courts to award statutory damages of up to KRW 3 million (approximately USD 2,100 as of June 2026) per violation when a data subject proves that personal information was lost, leaked, stolen, altered, or damaged due to the controller's intent or negligence, but the exact amount of damages is difficult to prove. This provision eliminates the need for the data subject to quantify pecuniary or non-pecuniary harm, shifting the court's inquiry from damages calculation to whether a qualifying breach occurred.
The KRW 3 million cap is a statutory ceiling, not a presumptive award. Courts retain full discretion to award any amount from zero to KRW 3 million based on the severity of the violation, the sensitivity of the data, the number of data subjects affected, and the controller's degree of fault. In practice, Korean district courts have awarded statutory damages in the range of KRW 100,000 to KRW 500,000 per plaintiff in class-action data-breach cases (for example, the ongoing Coupang litigation as of June 2026, involving claims by thousands of data subjects for a December 2024 breach of delivery-address and contact data).
Statutory damages do not apply when no compensable harm exists
The Supreme Court of Korea clarified in February 2026 that Article 39-2 does not impose a damages-compensation obligation where no actual damage exists, notwithstanding that a technical breach occurred. The Court held that statutory damages are available only when the data subject proves that the breach caused at least some minimal harm (for example, a risk of identity theft, increased spam, or emotional distress), even if the exact quantum is difficult to measure. A controller may therefore defeat a statutory-damages claim by proving affirmatively that the leaked data was encrypted and the encryption key was not compromised, that no third party accessed the data, or that the data subject took no remedial action and suffered no identifiable harm. This holding has been criticized by privacy advocates as undermining the deterrent purpose of statutory damages, but it reflects the Court's textualist interpretation of Article 39-2's requirement that "damages" (損害) must have occurred.
Article 39-3 — punitive damages up to five times actual damages
Article 39-3 PIPA, as amended effective 15 September 2023 (Act No. 19234, 14 March 2023), authorizes courts to award punitive damages of up to five times the amount of actual damages (property damage plus non-pecuniary harm under Article 39(1)) when the controller violated PIPA intentionally or with gross negligence and the violation caused harm to the data subject. Prior to the 2023 amendments, Article 39-3 authorized punitive damages of up to three times actual damages; the September 2023 reform raised the multiplier to five to align South Korea's punitive-damages regime with the deterrent reach of the EU GDPR's administrative fines and the U.S. state statutory-damages frameworks.
Triggering standard — intent or gross negligence
Punitive damages under Article 39-3 require proof that the controller acted with intent (고의, deliberately violated PIPA knowing the conduct was unlawful) or gross negligence (중대한 과실, reckless disregard for PIPA obligations). Ordinary negligence—failure to comply with PIPA despite a reasonable effort—does not support punitive damages. Korean courts have defined gross negligence in the data-protection context as a failure to implement baseline security measures required under Article 29 PIPA and the Security Safeguard Standards when the controller knew or should have known that personal information was at significant risk of leakage or misuse. Examples from PIPC enforcement actions that would likely satisfy the gross-negligence standard include storing unencrypted resident registration numbers in plaintext databases accessible via the internet, failing to patch known critical vulnerabilities for months after vendor disclosure, or processing special-category personal information (health, biometric, or financial data) without access controls or audit logging.
Punitive damages are calculated as a multiple of actual damages
Article 39-3 punitive damages are calculated as a multiple of the actual damages awarded under Article 39(1)—both pecuniary and non-pecuniary harm. If a court awards KRW 1 million in actual damages for identity-theft remediation costs and emotional distress, the court may award up to an additional KRW 5 million in punitive damages (5× KRW 1 million) for a total recovery of KRW 6 million. However, if the court finds that the data subject suffered no actual damages—or awards only nominal damages—the punitive-damages multiplier applies to that nominal base, resulting in a de minimis punitive award.
This structure has limited the deterrent reach of Article 39-3 in practice. The Incheon District Court, in a 2021 decision (2021Na74344), held that Article 39-3 punitive damages should be calculated only on objectively quantifiable pecuniary harm (property damage), not on non-pecuniary mental distress, because mental distress is inherently subjective and difficult to prove with precision. The Court reasoned that allowing punitive damages to be multiplied against non-pecuniary awards would introduce excessive uncertainty and expose controllers to unpredictable liability. This interpretation remains contested—other district courts have applied the multiplier to total damages including mental distress—but it reflects a conservative judicial posture that limits punitive damages to cases where the data subject can prove concrete financial loss.
Interplay with statutory damages under Article 39-2
Article 39-3 punitive damages are awarded in addition to compensatory damages under Article 39(1), but Korean courts have not yet definitively ruled on whether punitive damages may be stacked on top of statutory damages under Article 39-2. The statutory text is ambiguous: Article 39-3 refers to "the amount of damages prescribed in paragraph (1)," which is the general compensatory-damages provision, not the statutory-damages provision in Article 39-2. The more restrictive reading—adopted by several district courts—holds that a data subject who elects statutory damages under Article 39-2 (because actual damages are difficult to prove) forfeits the right to punitive damages under Article 39-3, because there is no proven "actual damages" base to multiply. The more plaintiff-friendly reading holds that statutory damages are a legislatively defined proxy for actual damages when proof is difficult, and courts should therefore apply the punitive multiplier to the statutory award (for example, 5× KRW 3 million = KRW 15 million total). As of June 2026, no appellate court has resolved this split, and practitioners advising data subjects should plead both theories in the alternative.
No punitive damages have been awarded in published data-breach cases as of June 2026
Despite the availability of punitive damages under Article 39-3 since the 2014 introduction of the provision (and the 2023 expansion to a 5× multiplier), no reported Korean appellate decision has affirmed a punitive-damages award in a personal-information breach case. District courts have repeatedly declined to award punitive damages on the grounds that the data subject failed to prove objectively quantifiable actual damages (pecuniary loss) or that the controller's conduct, while negligent, did not rise to the level of gross negligence or intent. The ongoing Coupang class-action litigation (filed in 2025 following a December 2024 breach affecting millions of delivery addresses and phone numbers) is widely viewed as a test case for whether Korean courts will begin awarding meaningful punitive damages under the expanded Article 39-3 framework, but as of mid-2026 no judgment has been entered.
Article 39-11 — liability-guarantee measures for large controllers
Article 39-11 PIPA, added by the September 2023 amendments, requires personal-information controllers who meet revenue and data-volume thresholds specified in the Enforcement Decree to take necessary measures to guarantee their ability to compensate for damages, including purchasing liability insurance, joining mutual-aid associations, or accumulating reserves. The detailed thresholds are set forth in Article 48-8 of the Enforcement Decree (Presidential Decree No. 34421, as amended September 2023): controllers with annual revenue exceeding KRW 10 billion (approximately USD 7 million) and processing personal information of more than 1 million data subjects must establish a liability-guarantee mechanism. The PIPC may exempt controllers who demonstrate that their financial condition is sufficient to cover expected liabilities without insurance or reserves.
Failure to comply with Article 39-11 is subject to an administrative fine of up to KRW 30 million under Article 75(2)(14) PIPA, but does not create an independent cause of action for data subjects. The liability-guarantee requirement is intended to ensure that large controllers have sufficient assets to satisfy judgments in mass data-breach cases, addressing a concern that emerged after several early PIPA class actions were settled for de minimis amounts because the defendant controllers lacked insurance coverage or liquid assets.
Class actions and representative litigation under the Securities-Related Class Action Act
South Korea does not have a general class-action statute for consumer or privacy claims. Data subjects injured by the same PIPA violation may file individual lawsuits or may consolidate their claims through joint litigation (共同訴訟) under Article 65 of the Korean Civil Procedure Act, in which multiple plaintiffs join as co-parties in a single action. Joint litigation does not bind absent class members and does not provide for opt-out or settlement-approval procedures analogous to U.S. Federal Rule of Civil Procedure 23.
However, the Securities-Related Class Action Act (Act No. 6012, enacted 2001) permits representative class actions for certain securities-fraud claims, and Korean courts have occasionally allowed representative actions in non-securities consumer cases by analogical application when the claims involve a large number of similarly situated plaintiffs and common questions of law and fact. The Coupang data-breach litigation filed in 2025 is structured as a joint action by approximately 10,000 named plaintiffs represented by a consumer-rights organization, but the court has not certified it as a formal class action. Settlement of joint actions requires individual consent from each plaintiff, which poses practical challenges when the plaintiff group is large.
Data subjects who lack the resources to file individual lawsuits may file a complaint with the PIPC under Article 62 PIPA (via the Korea Internet & Security Agency's toll-free hotline at 118 or online at www.pipc.go.kr), but the PIPC's administrative investigation and corrective order do not create a civil judgment or award damages. Data subjects must file a separate civil action in district court to recover compensation under Articles 39–39-3.
Source: Personal Information Protection Act (PIPA) — Act No. 19234, effective 15 September 2023, Articles 39, 39-2, 39-3, 39-11 Source: PIPC — Laws & Regulations
Administrative fines under Article 75 PIPA — fixed-sum monetary sanctions and forthcoming 10% revenue-based surcharges
Administrative fines (과태료, gwataeryo) under Article 75 of South Korea’s Personal Information Protection Act (PIPA) constitute a core civil penalty mechanism—distinct from administrative penalty surcharges (과징금) under Article 34-2 (up to 3% of revenue, rising to 10% for severe violations in September 2026) and criminal penalties under Articles 70–73.
Current statutory framework (March 2024–September 2026): As amended and effective as of 15 March 2024 (Act No. 19234, as consolidated through early 2024), Article 75 imposes fixed-sum administrative fines:
- Up to KRW 50 million for the most serious administrative violations under Article 75(1).
- Up to KRW 30 million for specified procedural and governance failures under Article 75(2).
These fines are imposed directly by the Personal Information Protection Commission (PIPC) through administrative adjudication, and are enforceable as national tax debts if unpaid. The amount is determined based on seriousness, harm, prior compliance, and the aggravating/mitigating factors detailed in Appendix 2 of the Enforcement Decree (Presidential Decree No. 34421, as amended September 2023 and March 2024).
Material changes: Enhanced enforcement regime from September 2026 and July 2027: A major revision to PIPA promulgated 10 March 2026 and taking effect on 11 September 2026 (Act No. 20509) significantly increases penalty exposure:
- For repeated or aggravated violations (including: repeated breaches after a prior order, breaches affecting >10 million data subjects, or failure to comply with a corrective order followed by a breach), the PIPC may impose surcharges up to 10% of the controller’s total revenue, or up to KRW 5 billion if the revenue calculation is unavailable (Article 34-2(5), incorporated by reference into Article 75 application by the Enforcement Decree).
- These surcharges coexist with (and may, in some instances, supersede) fixed-sum fines. Appendix 2 of the Enforcement Decree is amended to govern the calculation and procedural interplay between surcharges and fines as of September 2026.
Additional procedural fines — July 2027: Per Article 75(2), newly added paragraphs 14‑2 through 14‑4 (effective July 1, 2027) authorize fines of up to KRW 30 million for failures related to CPO governance and reporting, as required by the 2026 amendments (e.g., Board approval, notification to PIPC, and public announcement of CPO appointments for large controllers).
Key cross-over and limitations:
- Article 75(6) continues to prohibit double-penalization: no administrative fine under Article 75 may be imposed for acts prosecuted criminally under Articles 70–73.
- Enforcement action may combine Article 75 fines with Article 34-2 surcharges for different aspects of a given violation.
Summary table:
- March 2024–September 2026: Fixed-sum fines: Up to KRW 50M (serious), 30M (governance)
- September 2026 onward: Surcharge of up to 10% revenue or KRW 5B for severe/repeat violations; procedural fines expanded for CPO duties (from July 2027)
Practitioners must reference the exact violation date and the relevant Enforcement Decree for penalty determination. The statutory structure is subject to ongoing amendment and annual PIPC guidance.
Source: Personal Information Protection Act (PIPA), Article 75, as amended and enforced Mar 2024 and Mar/Sep 2026 Source: PIPA, Act No. 20509, amendments promulgated Mar 10, 2026, effective Sep 11, 2026, July 1, 2027
Judicial review and appeals of PIPC enforcement actions — Article 20 Administrative Litigation Act
Any controller, processor, or data subject aggrieved by a final enforcement decision of the Personal Information Protection Commission (PIPC) — including administrative fines (Article 75 PIPA), administrative penalty surcharges (Article 34-2 PIPA), or corrective orders (Article 64 PIPA) — has the right to seek judicial review before the South Korean administrative courts. The governing statute is the Administrative Litigation Act (행정소송법), with details set out in Article 20 and relevant provisions of the Personal Information Protection Act (PIPA).
Right of appeal — 60-day deadline, Seoul Administrative Court jurisdiction Article 20 of the Administrative Litigation Act provides that a person wishing to challenge a PIPC administrative act must file a written petition within 60 days of receiving notice of the contested disposition, and within 1 year of the occurrence of the act, unless good cause is shown for delay. For PIPC administrative penalties (including fines and surcharges), the competent court is ordinarily the Seoul Administrative Court (서울행정법원), which exercises exclusive jurisdiction over regulatory appeals challenging central government agency actions. The court’s review covers both legal and factual issues, including claims that the PIPC misapplied PIPA articles, breached due process, or imposed disproportionate sanctions.
Standard of review and remedies The administrative court has authority to annul, amend, or suspend the enforcement of a PIPC penalty or order. The standard is generally one of full judicial review, not mere procedural regularity; the court will examine whether the PIPC correctly interpreted and applied PIPA and whether the penalty was proportionate to the violation. For record-heavy cases, the court may order production of the full PIPC investigation file and, where factual disputes exist, take evidence from expert witnesses or order additional administrative fact-finding. The court may stay enforcement of the sanction pending judgment if the appellant shows irreparable harm or a likelihood of success on the merits (Administrative Litigation Act, Article 23-2).
Effect of appeal — payment and enforcement Filing an appeal does not by itself suspend payment or enforcement of the penalty; a separate stay order must be requested and granted. If the court annuls or reduces the penalty, the PIPC must refund any amount already paid. The deadlines and available remedies are strictly construed, and missed deadlines generally preclude later judicial review, making prompt action critical for practitioners.
Recent appellate practice Since the post-2020 centralization of PIPC penalty powers, most large-scale data-protection penalties have been contested at the Seoul Administrative Court. As of June 2026, judgments reflect searching judicial review of both the substantive proportionality of surcharges and fines and the evidentiary adequacy of PIPC findings. Notably, in mid-2025 the Seoul Administrative Court annulled PIPC penalty surcharges against an e-commerce platform on the grounds of insufficient documentary proof of actual harm and held that the PIPC must provide a detailed rationale for penalty calculations under the Enforcement Decree.
Source: Administrative Litigation Act (English translation), Article 20
Penalty calculation — aggravating and mitigating factors under Enforcement Decree Appendix 2
Appendix 2 of the Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 34421, effective as amended September 2023) prescribes the criteria for calculating administrative penalty surcharges (Article 34-2 PIPA) and administrative fines (Article 75 PIPA). The Personal Information Protection Commission (PIPC) must apply these aggravating and mitigating factors in setting the final sanction for personal-information violations.
Mitigating factors under Appendix 2 The Decree lists the following circumstances as grounds to reduce the penalty:
- The violator voluntarily reported the infraction to the PIPC before discovery by the authority.
- The violator took corrective action to remedy or minimize the violation’s impact immediately after its occurrence.
- There was no material damage to data subjects, as when personal information was encrypted or swiftly recovered so as to prevent use or leakage.
- The violator sincerely cooperated with the PIPC’s investigation (e.g., rapid submission of required documents, unfettered access for on-site inspections).
- Other comparable circumstances considered by the PIPC to justify mitigation (Appendix 2, Para. 3(5)).
Aggravating factors under Appendix 2 Aggravation applies when:
- The violation was repeated within three years for the same or similar obligation.
- The conduct was willful or grossly negligent rather than inadvertent.
- The violator obstructed or interfered with the PIPC’s investigation (including refusal to submit materials, denying on-site access, or providing false explanations).
- The violation concerned a large number of data subjects or highly sensitive types of personal information (e.g., resident registration numbers, financial, biometric, or health data).
- There was significant and widespread damage, or considerable risk of such, to data subjects due to the violation.
Penalty adjustment process Appendix 2 describes a formal, multi-step process: the PIPC determines a base amount for the sanction, then applies percentage-based increases or reductions according to the presence, severity, and number of the above factors. The total must not exceed the statutory cap (3% of total revenue for penalty surcharges; stated maximums for fines). The Decree gives formulaic weight to each factor and requires the PIPC to record its penalty calculation systematically. The English translation of Appendix 2 contains the governing language and adjustment tables.
Mitigating or aggravating factors must be substantiated by documentation or facts established during the investigation.
Cross-border enforcement of PIPA penalties against foreign controllers — domestic-representative obligations and recovery limits
South Korea’s Personal Information Protection Act (PIPA) applies extraterritorially to foreign controllers processing the personal information of Korean data subjects (Article 2(2) PIPA). The practical enforceability of administrative surcharges or fines, however, remains sharply limited for foreign entities lacking assets or presence in South Korea.
Obligation to designate a domestic representative — key amendments effective September 2026: Foreign controllers that exceed KRW 1 trillion annual revenue, process personal data of more than one million Korean subjects per day (averaged over three months), or are otherwise designated by the PIPC are required to appoint a domestic representative in South Korea (Article 39-12 PIPA; new designation rules effective 2 April 2026 require the representative to be a Korean legal entity). Effective from September 11, 2026, the law expands both the categories of controllers subject to this requirement and the enforcement reach to CEOs or primary business operators, consistent with the amendments adopted by Act No. 20509 (February 2026). Failing to appoint a domestic representative or provide registration carries a maximum administrative fine of KRW 20 million (Article 75(5)(3)), but does not enable direct attachment of foreign assets or substituted service for higher-tier sanctions against entities with no Korean presence.
Material enhancement of PIPA administrative penalty surcharges (2026):
- Prior to September 2026, the maximum administrative penalty surcharge imposed by the PIPC was capped at 3% of total worldwide revenue, applicable even to foreign controllers (Article 64-2(2) PIPA).
- Effective September 11, 2026, for aggravated or repeated violations (including repeat offenses, breaches affecting more than 10 million data subjects, or non-compliance with corrective orders), the penalty cap rises to 10% of total revenue, or KRW 5 billion if the revenue base cannot be established. The PIPC must consider aggravation and mitigation factors set out in the Enforcement Decree (see the relevant section of this guide for penalty calculation detail).
- Despite these caps, in practice, the PIPC remains able to enforce monetary penalties only to the extent the foreign controller (or its designated Korean representative) holds assets or maintains accounts within Korea. There is no cross-border administrative enforcement treaty for privacy fines, and the OECD or other international mutual assistance conventions do not extend to privacy surcharges as of June 2026.
Recent PIPC enforcement and reputational sanctions: Penalty surcharges against high-profile foreign entities (e.g., major international e-commerce services) are enforceable only where a local agent, subsidiary, or asset is present. Failure to pay or respond leads to publicization of the non-compliance (see PIPA Article 64-2) and reputational consequences in the Korean market, but has not resulted in enforced recovery against assets held outside South Korea. There are no publicly reported cases of successful administrative fine collection abroad based solely on a Korean order.
Bonding and insurance obligations for large entities: Article 39-11 PIPA requires controllers meeting certain thresholds to maintain liability-guarantee measures (insurance, reserves, or mutual-aid association participation); however, these liability guarantees are enforceable only in respect of domestic (Korean) judgments relating to damages, not for PIPC-imposed administrative fines or surcharges. Foreign controllers without such arrangements remain exposed only to the limited reach described above.
Summary: South Korea’s PIPA regime for foreign controllers features strong formal penalty authority, but actual cross-border monetary recovery power is functionally limited. Major 2026 amendments increase administrative penalty exposure up to 10% of total revenue and enhance personal accountability, but enforcement outside the jurisdiction is practically available only against domestic representatives or locally held assets. Practitioners must closely track effective dates and penalty structure changes when assessing exposure for non-Korean entities handling Korean data.
Voluntary reporting and self-remediation — leniency and penalty mitigation under PIPA and Enforcement Decree Appendix 2
South Korea’s Personal Information Protection Act (PIPA) incentivizes controllers and processors to self-report violations and promptly remediate breaches by treating voluntary notification and corrective action as explicit mitigating factors when calculating administrative sanctions. The statutory authority for leniency is grounded in the detailed penalty criteria set forth in Appendix 2 of the Enforcement Decree of PIPA (Presidential Decree No. 34421, as amended September 2023). The Personal Information Protection Commission (PIPC) must consider these circumstances in both administrative penalty surcharge (Article 34-2) and fixed-amount fines (Article 75) determinations.
Statutory basis for mitigation — voluntary reporting and corrective action
Appendix 2 lists the following circumstances as grounds for mitigation:
- The violator voluntarily reported the violation or breach to the PIPC before it was discovered by the authority (Appendix 2, Para. 3(1)).
- The violator took prompt corrective measures to remedy or minimize the impact of the breach immediately after its occurrence (Appendix 2, Para. 3(2)).
- Additional mitigating factors include sincere cooperation with the investigation (rapid submission of information, transparency in on-site inspection), and demonstration that no material harm occurred (e.g., robust encryption prevented real-world exposure, Para. 3(3)-(4)).
These factors must be weighed in the final penalty decision. The PIPC issues detailed internal guidelines that reinforce these standards: for example, the official “Guideline on the Handling and Disclosure of Personal Information Incidents” (last updated September 2023) emphasizes that self-reporting—using the online reporting portal or dedicated telephone hotline—before investigation or discovery typically results in substantial penalty reduction, except where the violation was intentional or involved significant, widespread harm.
Practical impact — scope and limits of leniency
Self-reporting and prompt mitigation do not create a full safe-harbor and do not preclude enforcement entirely. Rather, they permit significant downward adjustments from the statutory maximum or base amount. For example, if the base penalty for a cross-border transfer violation is set at 50% of the maximum surcharge, voluntary notification and good-faith cooperation may reduce the penalty to 10–30% of the cap, depending on other circumstances. The final sanction cannot be reduced below zero or outside the range established by Appendix 2 and is still subject to aggravating factors (such as repeated offenses or harm to sensitive/personal-identifiable information subclasses).
In practice, the PIPC publicly reports that a substantial portion of penalty reductions in major breach cases results from prompt voluntary notice, rapid remediation, and transparent cooperation during investigation (see 2024 penalty statistics). However, cases involving intentional concealment, repeated violations, or willful obstruction do not receive meaningful mitigation regardless of subsequent self-reporting.
Comparison to EU/US safe-harbor and penalty-mitigation models
This regime closely tracks (but does not duplicate) the GDPR’s Article 83(2) mitigation factors and the typical credit given by EU supervisory authorities. The practical result is that controllers operating in South Korea should implement internal escalation and rapid-notice protocols not only to comply with statutory breach-notification timelines under PIPA (see South Korea — Breach Notification guide) but also to preserve eligibility for penalty reductions if a violation does occur. Controllers with compliance programs aligning with this risk-based, transparent, and rapid-notice regime are best positioned as of June 2026 to minimize enforcement exposure.
Corrective orders and remedial measures — Article 64 PIPA authority and procedure
The Personal Information Protection Commission (PIPC) may issue corrective orders under Article 64 of the Personal Information Protection Act (PIPA) as a central tool to remedy or prevent personal-information violations in South Korea. A corrective order (시정명령) is a legally binding mandate—separate from monetary penalties—requiring a controller, processor, or consignee to take, suspend, or reverse specific actions to address a breach of the PIPA or to avert serious harm to data subjects.
Legal authority and triggers — Article 64(1) PIPA Article 64(1) authorizes the PIPC to issue a corrective order if it finds that a personal information controller, processor, or consignee has violated the PIPA or its Enforcement Decree, or is processing personal information in a manner likely to seriously infringe data subjects' rights and interests. The PIPC may act on its own initiative or following an investigation prompted by a complaint or notification under Article 62. The law specifically states that the PIPC may order the violator to correct or stop the relevant processing activities as necessary.
Range of measures available The scope of a corrective order under Article 64(1) includes:
- Suspending or terminating unlawful personal information processing;
- Taking necessary actions to remedy the violation and prevent recurrence;
- Destroying or anonymizing unlawfully collected or processed personal data;
- Suspending or limiting transfer of personal information to third parties or across borders where required.
Other forms of remedial action may also be included if necessary to comply with the PIPA. The exact action required will be set out in the corrective order according to the circumstances of the violation.
Compliance requirements and consequences Article 64(2)–(3) provides that the order will specify a period for corrective action, after which the violator must submit evidence of compliance. Failure or refusal to comply with a corrective order is itself a separate breach—subject to a fixed-sum administrative fine up to KRW 100 million under Article 75(2)(1) PIPA. Article 64 does not specify further enforcement mechanisms or appeal procedures within the PIPA, but general rights of judicial review are addressed in separate law (see /guides/south-korea/enforcement-and-penalties#judicial-review-and-appeals-article-20 for details).
Statutory language above practice The scope and operation of corrective orders are determined directly by Article 64 and its implementing Decree. As of June 2026, further practical enforcement guidance (such as the use of system logs or audit reports to evidence compliance, or reference to particular enforcement statistics or prominent cases) is not expressly stated in Article 64 or the official English translation linked below. Practitioners should consult the latest PIPC-issued guidelines or enforcement reports for operational updates beyond the statute.
Source: Personal Information Protection Act (PIPA), Article 64, Act No. 19234, effective 15 September 2023
Publication of Enforcement Actions — PIPC Public Disclosure of Penalties and Corrective Orders (Article 64-2 PIPA)
Statutory authority and scope of public disclosure South Korea’s Personal Information Protection Act (PIPA), as amended, expressly empowers the Personal Information Protection Commission (PIPC) to publicly disclose the identities, violations, and penalties or corrective measures imposed on controllers, processors, or their representatives who breach PIPA obligations. The primary authority is Article 64-2 PIPA, titled “Publication of the Status of Dispositions, etc.”
Publication regime under Article 64-2(1)–(3) (September 2023–) Under Article 64-2(1), when the PIPC imposes a disposition (penalty surcharge, administrative fine, or corrective order) for material violations—especially those causing significant or repeated harm—it may disclose:
- The name of the individual or corporation (including principal representatives)
- The nature/content of the violation
- Details of the disposition imposed (fine/penalty/corrective measures)
Publication is discretionary but widely utilized, especially for large-scale infractions. Article 64-2(2)–(3) requires that controllers subject to disclosure receive advance notice, with opportunity to comment, object, or request redaction (especially for trade secrets or sensitive data). PIPC must consider substantive objections and may redact identifying/business information to protect justifiable interests.
2026 amendments — expanded penalty publication and mitigation regime A material amendment to Article 64-2, promulgated 12 February 2026 (Act No. 20509, effective 11 September 2026), introduces several changes:
- New penalty ceiling for aggravated violations: Article 64-2(2) adds authority for the PIPC to publish decisions imposing administrative penalties of up to 10% of total turnover (or KRW 5 billion if turnover is unavailable) for particularly severe or repeated violations. Triggers include:
- Repeated violations after a prior order
- Breaches affecting over 10 million data subjects
- Failure to comply with a corrective order followed by a breach
This marks a significant increase from the previous maximum of 3% of turnover, in line with enhanced enforcement priorities.
- Publication of aggravated penalties: PIPC must publish the outcomes of such high-severity decisions.
- Mitigation and adjustment for bona fide compliance efforts: The new Article 64-2(6) empowers PIPC to reduce penalties for controllers that demonstrate substantial investment in protection measures (such as technical security, staff training, or audit systems), unless the case involves intent or gross negligence.
Retention and business impact Sanctions, names, and summaries are published on the PIPC’s website, generally for 3–5 years or until the risk from ongoing publication outweighs public interest. The reputational impact of disclosure frequently exceeds the financial value of the penalty itself for large organizations, incentivizing preventative compliance programs.
Controllers should anticipate expanded publication and higher penalty threats for severe or recurring breaches from September 2026 onward and promptly engage during the comment/redaction process to minimize reputational harm.
Business suspension and limitation of operations — Article 76 PIPA non-monetary sanctions
Authority to impose suspension or limitation of business operations – Article 76 PIPA Article 76 of South Korea's Personal Information Protection Act (PIPA), as amended and effective 15 September 2023, authorizes the Personal Information Protection Commission (PIPC) to order the suspension or partial suspension of business operations as a non-monetary sanction against controllers or processors that commit severe or repeated violations of PIPA. This "business suspension" (영업정지 처분) is considered the most severe administrative measure, short of criminal prosecution or license revocation, and is distinct from monetary penalties (penalty surcharges under Article 34-2 or administrative fines under Article 75) or corrective orders (Article 64).
Scope and grounds for suspension Under Article 76(1), the PIPC may, by formal order, suspend all or a portion of a controller's business for up to six months if the controller or its legal representative:
- Has received two or more administrative sanctions (penalty surcharge, administrative fine, or corrective order) for the same type of PIPA violation within three years; or
- Commits a violation likely to cause significant harm to data subjects, or one that is viewed as particularly egregious given the nature of the data or the scale of the infringement.
The statute permits partial suspension (limiting processing to certain data, services, or business segments) where full business closure would be disproportionate to the harm or would unduly affect third parties. The suspension order must explicitly specify its extent, duration (up to six months), and the grounds for imposition.
Procedural requirements and safeguards Article 76(2) requires that the PIPC give written prior notice to the controller, specifying the intended sanction and allowing the controller an opportunity to argue against suspension, submit evidence, or propose mitigating circumstances. The PIPC must consider these submissions before finalizing the order.
Exemptions and limitations Suspension "shall not be imposed where it would cause a serious hindrance to the public interest" (Article 76(3)), such as essential services in financial, healthcare, telecommunications, or infrastructure sectors. Instead, alternative measures—such as targeted restrictions on certain processing activities or periodic reporting obligations—may be imposed.
Enforcement examples and practical guidance While few published cases reflect the imposition of full business suspension as of June 2026, the threat is routinely cited in PIPC investigatory communications in large-scale or repeat-breach cases. The risk is highest when systematic, repeated violations occur (such as neglecting multiple corrective orders or recurring security failures affecting millions of data subjects).
Controllers should treat the possibility of business suspension as a central compliance risk, especially where prior violations exist or sensitive categories of data are involved. Proactive demonstration of remedial steps, strong internal controls, and prompt engagement with the PIPC in the event of an investigation are critical to avert non-monetary sanctions under Article 76.
Source: Personal Information Protection Act (PIPA), Article 76, Act No. 19234, effective 15 September 2023
Evidence preservation and records production during PIPC investigations — Article 63 PIPA
Article 63 of the Personal Information Protection Act (PIPA), as amended and effective 15 September 2023, grants the Personal Information Protection Commission (PIPC) explicit authority to compel personal information controllers and processors to submit materials, documents, and digital records during investigations for potential PIPA violations. This provision—distinct from the ordinary corrective order mechanism in Article 64—serves as the central legal tool for evidence preservation and records production during administrative audits and enforcement actions.
PIPC's powers to request and seize evidence Under Article 63(1), when the PIPC investigates a controller or processor, it may require submission of test data, ledgers, computer files, contracts, privacy policies, logs, and any other materials necessary to verify facts relevant to a suspected violation. The PIPC may also visit the business premises to inspect systems or seize original or copied materials for examination. The agency may designate specific preservation instructions—including suspending destruction or alteration of relevant electronic files or devices—and issue document holds similar to litigation hold orders in common-law jurisdictions.
Obligations on controllers and processors Upon official notice from the PIPC, the controller is required to maintain, preserve, and timely produce all requested records. Failure to comply—through non-production, delay, destruction, falsification, or concealment—constitutes a separate administrative offense under Article 75(2)(2) and is punishable by an administrative fine of up to KRW 100 million per incident. Intentional destruction or alteration may also support referral for criminal prosecution under Article 72 or other criminal statutes.
The Enforcement Decree of PIPA Appendix 2 further identifies “sincere cooperation with the PIPC investigation” and the absence of “obstruction or interference” as key mitigating/aggravating factors in penalty calculation. Voluntarily prompt production, proactive log preservation, notifications to IT and compliance staff to suspend routine data purges, and contemporaneous audit trails materially reduce exposure if a violation is later found.
Practice guidance and risk management As of June 2026, the official English PIPA text and the PIPC website do not set out detailed practical requirements (such as preferred formats for log exports, or binding timetables for digital evidence imaging beyond “without delay” on request). However, published penalty cases and the Enforcement Decree make clear that even ordinary system backup rotation or automated deletion, if not suspended after a PIPC notice, may constitute punishable non-cooperation. Controllers should implement documented internal processes for prompt “legal holds” on electronic records and train IT/compliance teams to escalate all PIPC communications immediately.
Source: Personal Information Protection Act (PIPA), Article 63, Act No. 19234, effective 15 September 2023
Statute of limitations for PIPA criminal and administrative penalties (Articles 77, 77-2)
The Personal Information Protection Act (PIPA) of South Korea sets explicit limitation periods (prescription periods) for the enforcement of both criminal and administrative penalties arising from personal-information violations. Knowing these time bars is essential for compliance assessment and defense planning, especially in large-scale breach cases or historical investigations.
Criminal penalties — five-year statute under Article 77 Article 77 PIPA provides: “The right of the State to impose punishment for offenses prescribed in this Act shall be extinguished by prescription if it is not exercised for five years.” This five-year period applies to prosecution for all criminal offenses defined in PIPA (Articles 70–73). The clock starts when the criminal conduct is completed. After five years have passed without prosecution, criminal liability is extinguished, and prosecutors may not commence proceedings.
Administrative penalties — three-year statute under Article 77-2 Administrative sanctions, including administrative fines and penalty surcharges, are subject to a shorter limitation period. Article 77-2 PIPA (added by amendment in March 2023) provides: “The right of the State to impose an administrative fine or surcharges … shall be extinguished by prescription if it is not exercised for three years from when the offense is committed.” If the Personal Information Protection Commission (PIPC) notifies the controller or processor of an investigation within this period, the limitation period is tolled: the clock is paused until the penalty is imposed or the investigation is closed (see Article 77-2(2)). In cases where the violation is actively concealed, there may be further delay before the limitation period begins, but the text of PIPA itself is silent on detailed rules for concealment; the Enforcement Decree may add specificity.
Note on civil damages claims PIPA does not expressly prescribe a statute of limitations for private lawsuits by data subjects for damages. Korean practice is to apply the general prescriptions of the Korean Civil Act, typically a three-year period from discovery of harm and the responsible party, and an absolute maximum of ten years from the date of the act. However, the PIPA official translation does not itself set out these civil limitation rules: Unable to confirm as of 2026-06-16.
For compliance professionals, prompt analysis is essential: claims for PIPA administrative penalties become time-barred after three years unless timely action or formal investigation tolls the period. Criminal liability expires after five years. Civil claimants are likely held to general limitations under the Civil Act, but statutory backup must be checked case by case.
Source: Personal Information Protection Act (PIPA), Article 77, Article 77-2
PIPC on-site investigations and audits — scope, process, and controller duties under Article 63 PIPA
Article 63 of the Personal Information Protection Act (PIPA) authorizes the Personal Information Protection Commission (PIPC) to conduct on-site investigations and audits of personal information controllers and processors to verify compliance or investigate suspected violations. This Article establishes the PIPC’s statutory right to conduct audits both upon receipt of a complaint or report under Article 62 and on its own initiative (ex officio), including entry into business locations and IT facilities.
Scope of powers Under Article 63(1)–(2), the PIPC or officials it delegates may:
- Enter business premises or related facilities;
- Demand that controllers or processors submit books, documents, or electronic data for inspection;
- Request explanations from officers, employees, or related persons;
- Copy, seize, or preserve evidence that may prove a violation (including digital logs and records);
- Order preservation of relevant materials, suspending destruction or concealment.
Controllers and processors are obliged to cooperate: refusal to submit materials, denial of entry for on-site investigation, or interference with the inspection process is independently punishable by an administrative fine of up to KRW 100 million under Article 75(2).
Procedural requirements and safeguards The PIPC must notify the controller in advance of the investigation or audit—unless there is concern that advance notice could jeopardize the effectiveness of the investigation (e.g., risk of evidence destruction). The law requires PIPC inspectors to prepare a written investigation report or audit record after the inspection. Article 63 text governs these procedures, but the Enforcement Decree sets specific details such as notice contents and timelines; these details must be confirmed in the source Decree.
If evidence of a PIPA violation is discovered during the investigation or audit, PIPC may initiate corrective orders (Article 64), impose administrative penalties (Article 75), or, if warranted, refer the case for criminal prosecution (Articles 70–73).
Statutory limits Article 63 does not cover the publication of audit results, statistical reporting of the PIPC’s audit docket, or the use of audit cooperation as a mitigating factor in penalty calculation. These issues are governed elsewhere in PIPA or its Enforcement Decree, or remain policy practice rather than statutory requirements.
Practical guidance Controllers should maintain up-to-date compliance documentation and evidence logs to ensure readiness in the event of a PIPC investigation. The statute requires full cooperation but does not detail mitigation effects or sector prioritization.
Source: Personal Information Protection Act (PIPA), Article 63, Act No. 19234, effective 15 September 2023