South Korea's Amended Privacy Law Lets the Regulator Fine Serious Breaches up to 10% of Total Revenue
Since 11 September 2026, South Korea's Personal Information Protection Commission (PIPC) can impose an administrative surcharge of up to 10% of a company's total revenue for repeated, large-scale or order-defying personal data breaches, up from the general ceiling of 3%. The same amendment names the CEO as the person ultimately responsible for personal data protection, requires notice to people within 72 hours when a leak is likely but not yet confirmed, and gives companies a reduction of up to 40% in the base fine for proven investment in prevention.
The changes come from the amendment to the Personal Information Protection Act (PIPA), promulgated as Act No. 21445 on 10 March 2026, and a revised Enforcement Decree and PIPC notices that set out the detail. The PIPC announced the start date on 10 September, citing a run of large breaches in everyday services. This post is not legal advice.
Key takeaways
- 10% of total revenue is the new ceiling for three kinds of serious violation. The general ceiling stays at 3%.
- Up to 40% can come off the base fine for preventive investment in budget, staff, facilities and equipment.
- The CEO is named as ultimately responsible. Larger controllers need a board resolution to appoint, change or dismiss a Chief Privacy Officer.
- 72 hours is the deadline to notify people when a leak is likely but the affected individuals cannot yet be identified, or when part of a dataset is found for sale.
- Forgery, alteration and damage, including ransomware, now count as incidents that must be reported and notified.
- ISMS-P certification becomes mandatory for major public and private controllers from 1 July 2027. CPO-related administrative fines will not be imposed during a guidance period to 31 December 2027.
What the PIPC changed on 11 September 2026
According to the PIPC's release, republished in full by Seoul Focus, the reform has three aims: respond firmly to breaches, encourage investment in prevention before an incident, and give data subjects faster warning and clearer routes to redress.
As Yulchon explains, the Enforcement Decree also redefines "total revenue" for the 3% ceiling as the greater of the average annual revenue over the past three fiscal years or the revenue of the immediately preceding year, and allows reductions to be denied in full or in part for "very serious violations".
Our overview of identity data regulations in 2026 shows the same direction elsewhere: larger penalties, named accountability, faster notice.
The requirements at a glance
| Area | What the amended law and decree require |
|---|---|
| Surcharge ceiling | Up to 10% of total revenue where (i) a controller already sanctioned for intent or gross negligence repeats the violation within three years, (ii) a violation by intent or gross negligence affects 10 million or more data subjects, or (iii) a breach follows failure to comply with a PIPC corrective order (PIPA Article 64-2(2)) |
| Preventive investment reduction | Base amount reduced by up to 40%, considering the size, share, continuity and growth of investment in budget, staff, facilities and equipment, the CEO, CPO and specialist governance in place, and safety measures beyond legal minimums |
| Response reduction and aggravation | Up to 40% off for fast detection, prompt reporting and containment; up to 30% added where reporting and notification deadlines are missed and no steps are taken to stop harm spreading; higher aggravation for repeat violations |
| CEO and CPO | Business owner or CEO named as ultimately responsible; CPO gains authority over specialist staff and budget and must report to the board; qualifying controllers need a board resolution for CPO appointment, change or dismissal and must report to the PIPC within six months |
| Notice of possible leak | Notify data subjects within 72 hours of becoming aware when unlawful access makes a leak likely but individuals cannot be identified, or when a confirmed partial leak, such as data traded illegally, means others may be affected |
| Scope of incidents | Forgery, alteration and damage of personal information, including ransomware, added to reportable and notifiable incidents |
| Notice content | Notices must also explain how to apply for dispute mediation and how to claim damages |
| ISMS-P | Certification mandatory for major public and private controllers from 1 July 2027 |
| Transition | Guidance period to 31 December 2027, during which no administrative fines apply for CPO non-designation, missing qualifications, missing board resolutions or late reporting |
Why exposure now sets the price
First, the ceiling now tracks exposure. Where intent or gross negligence is found, a violation affecting 10 million or more people can move the maximum from 3% to 10% of total revenue, so record count, including dormant and former users' accounts, becomes a direct input to the penalty. We looked at how the Tving breach exposed connecting information, an identifier people cannot change, which shows how large a single platform's exposure can be.
Second, the law puts a number on prevention. In the release, PIPC Chairperson Song Kyung-hee said the Commission expects companies to stop seeing protection spending as a "cost" and start treating it as a pre-emptive investment in customer trust. The 40% investment reduction and the new CEO accountability put that view into the fine calculation and into the boardroom.
We welcome both moves. Tying penalties to the scale of harm, and rewarding controllers who invest before an incident, gives boards a clear reason to fund security properly. Controls are also not a one-off project: as technology and fraud risks evolve, safeguards, retention rules and incident plans need to be reviewed and recalibrated continually.
For boards, the question becomes how much personal data the business holds and whether each record is still needed. We covered that in our analysis of identity verification data storage risk.
Where verifiable credentials fit
Verifiable credentials do not replace any obligation in the amended PIPA. Identity checks, security controls, certification, governance and breach response all stay with the controller and its regulated providers. A credential layer is additive: it lets a business answer a specific question about a person without collecting more raw identity data than the decision needs.
AIR Identity, built by Moca Network, works from both sides. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run: passed KYC, residency, membership tier or account tenure. Businesses that need to know one of those facts request a proof of just that fact and receive a yes or no answer through zero-knowledge proofs, with the user's consent and minimal data custody. In Korea, SK Planet's OKI Club is built with AIR Kit.
For growth teams, the same model means reaching users who already hold the credentials a service requires, and paying only upon receipt of verification, rather than collecting fresh identity files from every sign-up. Each business remains responsible for deciding whether a credential meets its own legal requirements.
| Requirement | What stays with existing controls | What a credential layer can add |
|---|---|---|
| 10% ceiling for breaches affecting 10 million+ people | Security controls, encryption, access management and monitoring across all systems | Fewer raw identity records collected for checks that only need a yes or no, so less data sits in scope |
| 40% preventive investment reduction | Budgets, staff, facilities and equipment assessed by the PIPC under its guide | An architecture choice that limits new identity data at the point of collection, alongside those investments |
| CEO final responsibility and CPO board reporting | Governance, board resolutions, PIPC reporting and CPO authority | A clear record of which facts were requested and consented to, which helps a CPO report on data flows |
| 72-hour notice of possible leak | Detection, investigation and notification processes | Where a check used a proof rather than a stored document, there is less underlying identity data to assess |
| Forgery, alteration and damage as incidents | Backups, ransomware defences and integrity controls | Credentials signed by the issuer, so tampering with a presented proof can be detected |
| ISMS-P certification from 1 July 2027 | Certification scope, audits and remediation | Nothing replaced; certification remains a separate obligation |
Whether any design counts toward the investment reduction is for the PIPC to assess case by case.
Practical steps for controllers with Korean data
- Count data subjects, including dormant ones. Compare the total against the 10 million threshold.
- Document preventive investment by year. The reduction weighs the size, continuity and growth of spending.
- Check whether your CPO needs board approval. Controllers already required to appoint a specialist CPO fall in scope, and existing CPOs must be reported within six months of 11 September 2026.
- Rehearse the 72-hour notice. Update incident plans for leaks that are likely but unconfirmed, and add dispute mediation and damages information to notice templates.
- Treat ransomware as a notifiable incident. Forgery, alteration and damage now trigger reporting and notification, not only loss or theft.
- Ask for facts, not documents. Where a decision depends on one attribute, such as KYC status or residency, consider requesting a credential proof of that fact rather than another copy of the underlying ID, with regulated checks unchanged.
Our read
The PIPC now treats personal data as a board-level exposure with a price attached. The 10% ceiling is reserved for serious cases, the investment reduction rewards early action, and the guidance period gives realistic time to adjust. We welcome it. The durable response is to invest in the controls the law describes and, where a decision only needs a fact, to collect only that fact.
Frequently asked questions
What changed in South Korea's Personal Information Protection Act in September 2026?
From 11 September 2026, the amended PIPA (Act No. 21445) allows surcharges of up to 10% of total revenue for three kinds of serious violation, names the CEO as ultimately responsible, requires board approval of CPO appointments at qualifying controllers, and introduces 72-hour notice of likely leaks.
How much can Korea fine a company for a personal data breach?
The general ceiling is 3% of total revenue. It rises to 10% of total revenue where a controller repeats a violation within three years after a sanction for intent or gross negligence, where a violation by intent or gross negligence affects 10 million or more people, or where a breach follows failure to comply with a PIPC corrective order.
What are Korea's data breach notification rules in 2026?
Controllers must notify data subjects within 72 hours of becoming aware that a leak is likely, even before it is confirmed, where unlawful access occurred but individuals cannot be identified or where a partial leak suggests others are affected. Notices must also explain dispute mediation and damages claims.
How can a company reduce a PIPC fine?
The base amount can be reduced by up to 40% for preventive investment and by up to 40% for fast detection, reporting and containment. Missing notification deadlines without containing harm can add up to 30%.
When does ISMS-P certification become mandatory in Korea?
From 1 July 2027, for major public and private controllers. The PIPC delayed it so organisations can budget for certification.
Holding less identity data starts with asking for less. See how AIR Identity works, or partner with us to grow your business.
Sources
- PIPC release on the amended PIPA, Enforcement Decree and notices taking effect on 11 September 2026, as republished by Seoul Focus (Korean)
- Yulchon: Amendments to the Personal Information Protection Act, Its Enforcement Decree, and the Network Act (April 2026)
- DLA Piper: Data protection laws in South Korea
Partner with AIR
AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.
Partner with us to grow your business.
AIR is built by Moca Network, the identity network of Animoca Brands.

.png)