English한국어
South Korea flag

South Korea

South Korea Data Privacy Laws: PIPA Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202623 min read
South Korea Data Privacy Laws: PIPA Compliance Guide (2026)

Frequently Asked Questions

Does PIPA apply to foreign companies that are not based in South Korea?

Yes. PIPA applies to any entity that processes personal information of individuals located in South Korea, regardless of where the company is headquartered. Foreign businesses must appoint a domestic representative in Korea by October 2, 2025, to handle privacy matters and regulatory communications. The PIPC has fined both US and Chinese companies for PIPA violations.

What is the maximum fine under PIPA after the March 2026 amendment?

The March 2026 amendment, which takes effect on September 11, 2026, will authorize administrative fines of up to 10% of a company's total revenue for high-severity violations. This applies where a company intentionally or with gross negligence repeats a violation within three years, affects 10 million or more individuals under those conditions, or fails to comply with a PIPC corrective order and a breach results. Standard violations can still result in fines up to 3% of related revenue. Criminal penalties of up to 5 years imprisonment also remain in effect for the most serious violations.

How does the EU-Korea mutual adequacy arrangement affect data transfers?

The arrangement works in both directions. Since December 17, 2021, personal data can flow freely from the EU and EEA to South Korea without additional safeguards like standard contractual clauses. On September 16, 2025, South Korea completed the reverse: Korean controllers may now transfer personal data to the 27 EU Member States and 3 EEA countries without separate consent. Both recognitions have exclusions -- personal credit data, religious organizations, and political parties on the EU side; resident registration numbers and personal credit information on the Korean side. The mutual arrangement expires December 15, 2028 absent renewal.

What makes PIPA's consent requirements stricter than GDPR?

PIPA requires separate, explicit consent for each distinct processing purpose: collection, third-party sharing, sensitive data processing, marketing, and cross-border transfers. Unlike the GDPR, PIPA does not provide a broad legitimate interest basis that allows processing without consent for general commercial purposes. The 2024 anti-bundling rule further prohibits making service access conditional on consent for data that is not strictly necessary for the service.

Are there data localization requirements in South Korea?

PIPA itself does not mandate blanket data localization, but sector-specific laws do. The Electronic Financial Transactions Act requires personal credit information processed via cloud computing to remain on servers in South Korea. The Medical Services Act prohibits storing electronic medical records overseas. Public sector cloud services must maintain physically separate networks with data stored domestically. General commercial data can be transferred abroad with proper consent or other lawful mechanisms.

What CEO accountability obligations does the March 2026 PIPA amendment introduce?

The March 2026 amendment designates the CEO or representative director as the ultimate responsible person for data protection compliance. For organizations above thresholds to be set by enforcement decree, appointing, reassigning, or removing the Chief Privacy Officer must be approved by a formal board resolution and reported to the PIPC. The CPO must report directly to the CEO and the board and must manage dedicated privacy personnel and budget. Personal supervisory liability attaches to the CEO for systemic compliance failures.

Updates

Enforcement update: added the PIPC's June 11, 2026 fine of approximately KRW 624.7 billion (approximately USD 409 million) against Coupang and Coupang Fulfillment Services, the largest data-privacy fine in Korean history, surpassing the August 2025 SK Telecom record. Clarified that the March 2026 amendment's 10% total-revenue fine ceiling is passed but not yet in force; the operative ceiling remains 3% until the amendment takes effect September 11, 2026.

Major expansion: added the March 2026 PIPA amendment (10% turnover penalty ceiling, CEO accountability, breach notification expansion, ISMS-P certification); September 2025 mutual adequacy recognition; SK Telecom KRW 134.7 billion record fine; LVMH luxury brand fines; AI Framework Act and PIPC AI guidelines; data portability (March 2025); updated enforcement record through May 2026.

Initial publication covering PIPA framework, PIPC, 2020 data 3 laws reform, 2023 amendment, consent rules, data subject rights, cross-border transfers, EU adequacy, and penalties.

Sources and References

  1. Personal Information Protection Act (PIPA) -- Full English Text (Korea Legislation Research Institute)(elaw.klri.re.kr).gov
  2. Personal Information Protection Commission (PIPC) -- Official English Portal(pipc.go.kr).gov
  3. PIPC -- Laws and Regulations (Official Page)(pipc.go.kr).gov
  4. European Commission -- Adequacy Decision for the Republic of Korea (December 2021)(eucrim.eu)
  5. European Commission -- Joint Statement on EU-Korea Mutual Adequacy Entry into Force (September 2025)(commission.europa.eu).gov
  6. EDPB -- Opinion on Draft South Korea Adequacy Decision(edpb.europa.eu).gov
  7. IAPP -- South Korea Overhauls PIPA and Ties Fines to CEO Accountability (March 2026)(iapp.org)
  8. Hunton Andrews Kurth -- South Korea Amends Privacy Law to Authorize Fines of Up to 10% of Total Revenue(hunton.com)
  9. IAPP -- South Korea PIPC Flexes Its Muscles: AI Model Deletion, Cross-Border Transfers and More(iapp.org)
  10. Chambers and Partners -- Data Protection and Privacy 2026: South Korea Trends and Developments(practiceguides.chambers.com)
  11. Baker McKenzie -- Regulators, Enforcement Priorities and Penalties: South Korea(resourcehub.bakermckenzie.com)
  12. Baker McKenzie -- International Data Transfer Rules: South Korea(resourcehub.bakermckenzie.com)
  13. Korea Herald -- SK Telecom Hit with Record Privacy Fine After Massive Data Leak(koreaherald.com)
  14. SecurityWeek -- Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches(securityweek.com)
  15. Baker McKenzie -- South Korea Sets AI Standard: PIPC Guidelines for Generative AI(connectontech.bakermckenzie.com)
  16. DLA Piper -- Data Protection Laws of the World: South Korea(dlapiperdataprotection.com)
  17. GRC Report -- South Korea Tightens Privacy Rules with Tougher Penalties and New Executive Accountability(grcreport.com)
  18. PIPC (English) -- enforcement decision against Coupang and Coupang Fulfillment Services (release #210, June 11, 2026)(pipc.go.kr).gov
Share: