News

South Korea's Amended Privacy Law Lets the Regulator Fine Serious Breaches up to 10% of Total Revenue

Moca Network
September 16, 2026

Since 11 September 2026, South Korea's Personal Information Protection Commission (PIPC) can impose an administrative surcharge of up to 10% of a company's total revenue for repeated, large-scale or order-defying personal data breaches, up from the general ceiling of 3%. The same amendment names the CEO as the person ultimately responsible for personal data protection, requires notice to people within 72 hours when a leak is likely but not yet confirmed, and gives companies a reduction of up to 40% in the base fine for proven investment in prevention.

The changes come from the amendment to the Personal Information Protection Act (PIPA), promulgated as Act No. 21445 on 10 March 2026, and a revised Enforcement Decree and PIPC notices that set out the detail. The PIPC announced the start date on 10 September, citing a run of large breaches in everyday services. This post is not legal advice.

Key takeaways

  • 10% of total revenue is the new ceiling for three kinds of serious violation. The general ceiling stays at 3%.
  • Up to 40% can come off the base fine for preventive investment in budget, staff, facilities and equipment.
  • The CEO is named as ultimately responsible. Larger controllers need a board resolution to appoint, change or dismiss a Chief Privacy Officer.
  • 72 hours is the deadline to notify people when a leak is likely but the affected individuals cannot yet be identified, or when part of a dataset is found for sale.
  • Forgery, alteration and damage, including ransomware, now count as incidents that must be reported and notified.
  • ISMS-P certification becomes mandatory for major public and private controllers from 1 July 2027. CPO-related administrative fines will not be imposed during a guidance period to 31 December 2027.

What the PIPC changed on 11 September 2026

According to the PIPC's release, republished in full by Seoul Focus, the reform has three aims: respond firmly to breaches, encourage investment in prevention before an incident, and give data subjects faster warning and clearer routes to redress.

As Yulchon explains, the Enforcement Decree also redefines "total revenue" for the 3% ceiling as the greater of the average annual revenue over the past three fiscal years or the revenue of the immediately preceding year, and allows reductions to be denied in full or in part for "very serious violations".

Our overview of identity data regulations in 2026 shows the same direction elsewhere: larger penalties, named accountability, faster notice.

The requirements at a glance

AreaWhat the amended law and decree require
Surcharge ceilingUp to 10% of total revenue where (i) a controller already sanctioned for intent or gross negligence repeats the violation within three years, (ii) a violation by intent or gross negligence affects 10 million or more data subjects, or (iii) a breach follows failure to comply with a PIPC corrective order (PIPA Article 64-2(2))
Preventive investment reductionBase amount reduced by up to 40%, considering the size, share, continuity and growth of investment in budget, staff, facilities and equipment, the CEO, CPO and specialist governance in place, and safety measures beyond legal minimums
Response reduction and aggravationUp to 40% off for fast detection, prompt reporting and containment; up to 30% added where reporting and notification deadlines are missed and no steps are taken to stop harm spreading; higher aggravation for repeat violations
CEO and CPOBusiness owner or CEO named as ultimately responsible; CPO gains authority over specialist staff and budget and must report to the board; qualifying controllers need a board resolution for CPO appointment, change or dismissal and must report to the PIPC within six months
Notice of possible leakNotify data subjects within 72 hours of becoming aware when unlawful access makes a leak likely but individuals cannot be identified, or when a confirmed partial leak, such as data traded illegally, means others may be affected
Scope of incidentsForgery, alteration and damage of personal information, including ransomware, added to reportable and notifiable incidents
Notice contentNotices must also explain how to apply for dispute mediation and how to claim damages
ISMS-PCertification mandatory for major public and private controllers from 1 July 2027
TransitionGuidance period to 31 December 2027, during which no administrative fines apply for CPO non-designation, missing qualifications, missing board resolutions or late reporting

Why exposure now sets the price

First, the ceiling now tracks exposure. Where intent or gross negligence is found, a violation affecting 10 million or more people can move the maximum from 3% to 10% of total revenue, so record count, including dormant and former users' accounts, becomes a direct input to the penalty. We looked at how the Tving breach exposed connecting information, an identifier people cannot change, which shows how large a single platform's exposure can be.

Second, the law puts a number on prevention. In the release, PIPC Chairperson Song Kyung-hee said the Commission expects companies to stop seeing protection spending as a "cost" and start treating it as a pre-emptive investment in customer trust. The 40% investment reduction and the new CEO accountability put that view into the fine calculation and into the boardroom.

We welcome both moves. Tying penalties to the scale of harm, and rewarding controllers who invest before an incident, gives boards a clear reason to fund security properly. Controls are also not a one-off project: as technology and fraud risks evolve, safeguards, retention rules and incident plans need to be reviewed and recalibrated continually.

For boards, the question becomes how much personal data the business holds and whether each record is still needed. We covered that in our analysis of identity verification data storage risk.

Where verifiable credentials fit

Verifiable credentials do not replace any obligation in the amended PIPA. Identity checks, security controls, certification, governance and breach response all stay with the controller and its regulated providers. A credential layer is additive: it lets a business answer a specific question about a person without collecting more raw identity data than the decision needs.

AIR Identity, built by Moca Network, works from both sides. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run: passed KYC, residency, membership tier or account tenure. Businesses that need to know one of those facts request a proof of just that fact and receive a yes or no answer through zero-knowledge proofs, with the user's consent and minimal data custody. In Korea, SK Planet's OKI Club is built with AIR Kit.

For growth teams, the same model means reaching users who already hold the credentials a service requires, and paying only upon receipt of verification, rather than collecting fresh identity files from every sign-up. Each business remains responsible for deciding whether a credential meets its own legal requirements.

RequirementWhat stays with existing controlsWhat a credential layer can add
10% ceiling for breaches affecting 10 million+ peopleSecurity controls, encryption, access management and monitoring across all systemsFewer raw identity records collected for checks that only need a yes or no, so less data sits in scope
40% preventive investment reductionBudgets, staff, facilities and equipment assessed by the PIPC under its guideAn architecture choice that limits new identity data at the point of collection, alongside those investments
CEO final responsibility and CPO board reportingGovernance, board resolutions, PIPC reporting and CPO authorityA clear record of which facts were requested and consented to, which helps a CPO report on data flows
72-hour notice of possible leakDetection, investigation and notification processesWhere a check used a proof rather than a stored document, there is less underlying identity data to assess
Forgery, alteration and damage as incidentsBackups, ransomware defences and integrity controlsCredentials signed by the issuer, so tampering with a presented proof can be detected
ISMS-P certification from 1 July 2027Certification scope, audits and remediationNothing replaced; certification remains a separate obligation

Whether any design counts toward the investment reduction is for the PIPC to assess case by case.

Practical steps for controllers with Korean data

  1. Count data subjects, including dormant ones. Compare the total against the 10 million threshold.
  2. Document preventive investment by year. The reduction weighs the size, continuity and growth of spending.
  3. Check whether your CPO needs board approval. Controllers already required to appoint a specialist CPO fall in scope, and existing CPOs must be reported within six months of 11 September 2026.
  4. Rehearse the 72-hour notice. Update incident plans for leaks that are likely but unconfirmed, and add dispute mediation and damages information to notice templates.
  5. Treat ransomware as a notifiable incident. Forgery, alteration and damage now trigger reporting and notification, not only loss or theft.
  6. Ask for facts, not documents. Where a decision depends on one attribute, such as KYC status or residency, consider requesting a credential proof of that fact rather than another copy of the underlying ID, with regulated checks unchanged.

Our read

The PIPC now treats personal data as a board-level exposure with a price attached. The 10% ceiling is reserved for serious cases, the investment reduction rewards early action, and the guidance period gives realistic time to adjust. We welcome it. The durable response is to invest in the controls the law describes and, where a decision only needs a fact, to collect only that fact.

Frequently asked questions

What changed in South Korea's Personal Information Protection Act in September 2026?

From 11 September 2026, the amended PIPA (Act No. 21445) allows surcharges of up to 10% of total revenue for three kinds of serious violation, names the CEO as ultimately responsible, requires board approval of CPO appointments at qualifying controllers, and introduces 72-hour notice of likely leaks.

How much can Korea fine a company for a personal data breach?

The general ceiling is 3% of total revenue. It rises to 10% of total revenue where a controller repeats a violation within three years after a sanction for intent or gross negligence, where a violation by intent or gross negligence affects 10 million or more people, or where a breach follows failure to comply with a PIPC corrective order.

What are Korea's data breach notification rules in 2026?

Controllers must notify data subjects within 72 hours of becoming aware that a leak is likely, even before it is confirmed, where unlawful access occurred but individuals cannot be identified or where a partial leak suggests others are affected. Notices must also explain dispute mediation and damages claims.

How can a company reduce a PIPC fine?

The base amount can be reduced by up to 40% for preventive investment and by up to 40% for fast detection, reporting and containment. Missing notification deadlines without containing harm can add up to 30%.

When does ISMS-P certification become mandatory in Korea?

From 1 July 2027, for major public and private controllers. The PIPC delayed it so organisations can budget for certification.

Holding less identity data starts with asking for less. See how AIR Identity works, or partner with us to grow your business.

Sources

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Three Turkish Regulators Now Put the NFC Chip at the Centre of Remote Onboarding
MASAK, the CMB and the CBRT now anchor remote onboarding in Türkiye to NFC chip reading, and open it to foreign nationals holding ICAO 9303 passports.
News
US Regulators Confirm Banks Can Accept Mobile Driver's Licences When Opening Accounts
FinCEN and four US banking agencies say a government-issued mobile driver's licence can serve as documentary ID under the CIP Rule. What the 2026 FAQs require.
News
The EU KIDS Act Proposes 15 as the Minimum Age for Independent Social Media Accounts
The EU KIDS Act proposal sets 15 as the minimum age for independent social media accounts, adds supervised accounts from 13 and requires certified age checks.