🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
KR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing21 sources retrieved model claude-sonnet-5 · 2026-08-03

South Korea

KR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 43 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 1 September 2026.

Lead Signal

South Korea's 2026 Personal Information Protection Act overhaul is the cycle's dominant development, and it is confirmed with high confidence. Passed by the National Assembly on 12 February 2026 and promulgated 10 March 2026, effective 11 September 2026, the amendment raises the maximum administrative fine from 3% to 10% of total revenue in specified high-severity cases and makes the CEO or representative director the ultimate responsible person for organisational data-protection compliance, with chief privacy officer appointment and removal at qualifying scale now requiring board resolution and notification to the Personal Information Protection Commission. This is the most consequential PIPA rewrite since the 2023 overhaul, and it was catalysed directly by Coupang's disclosure, on 30 November 2025, of a breach affecting approximately 33.7 million customer records.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator, statutory basis, and material scope are Confirmed via T1/T2 sources; only territorial scope carries residual definitional ambiguity noted by secondary legal commentary.

Primary frameworkPersonal Information Protection Act (PIPA), as amended (2011, 2020 'Data 3 Act', 2023, 2025, 2026)
Traffic-light rationale — GreenCore regulator, statutory basis, and material scope are Confirmed via T1/T2 sources; only territorial scope carries residual definitional ambiguity noted by secondary legal commentary.

Sub-modules (5)

Regulator And AuthorityGreen

PIPC is the statutory enforcement authority for PIPA and its Enforcement Decree.

Claims (1):

  • The Personal Information Protection Commission (PIPC) is responsible for enforcing PIPA and the PIPA Enforcement Decree.

Act And InstrumentsGreen

PIPA, enacted September 30, 2011, is a comprehensive statute applying broadly, including to government entities.

Claims (1):

  • South Korea's comprehensive Personal Information Protection Act was enacted September 30, 2011 and is considered one of the world's strictest privacy regimes, enforced with criminal and regulatory penalties.

Material ScopeGreen

PIPA applies to most organisations, public and private, processing personal information.

Claims (1):

  • PIPA protects privacy rights from the data subject's perspective and applies broadly to most organizations, including government entities.

Territorial ScopeAmber

PIPA does not explicitly codify territorial/extraterritorial scope; application to foreign entities is assessed on factors such as Korea-targeted services.

Claims (1):

  • PIPA does not explicitly specify its territorial or extraterritorial scope; in practice, applicability to foreign entities is determined by factors such as whether services are targeted at Koreans.

Regulator Registration And FilingGreen

Foreign business operators meeting statutory criteria must establish a domestic corporation and designate/supervise a local representative, in force since October 2, 2025.

Claims (1):

  • Foreign business operators processing personal information who meet statutory criteria must establish a domestic corporation and designate a local representative, with the overseas headquarters required to manage and supervise that representative; the amendment was signed April 1, 2025 and took effect October 2, 2025.
Category narrative86 words

South Korea's Personal Information Protection Act (PIPA), enacted 2011 and substantially rewritten since, is enforced by the Personal Information Protection Commission (PIPC), which received EU-adequacy-driving independence and enforcement powers through the 2020 'Data 3 Act' reform. PIPA is comprehensive, applying to public and private controllers, and was further amended in March 2025 (foreign representative/domestic-corporation requirements, effective Oct 2, 2025) and March 2026 (CEO liability, 10% turnover penalty ceiling, effective Sept 11, 2026). PIPA's territorial/extraterritorial scope is not explicitly codified in the statute text, requiring case-by-case analysis.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedDataGuidance — The Personal Information Protection Commission (PIPC) is responsible for enforcing PIPA and the PIPA Enforcement Decree.observed
  2. ConfirmedIAPP — South Korea's comprehensive Personal Information Protection Act was enacted September 30, 2011 and is considered one of the world's strictest privacy regimes, enforced with criminal and regulatory penalties.observed
  3. ConfirmedIAPP — PIPA protects privacy rights from the data subject's perspective and applies broadly to most organizations, including government entities.observed
  4. ProbableDataGuidance / Lee & Ko — PIPA does not explicitly specify its territorial or extraterritorial scope; in practice, applicability to foreign entities is determined by factors such as whether services are targeted at Koreans.observed
  5. ConfirmedDataGuidance — Foreign business operators processing personal information who meet statutory criteria must establish a domestic corporation and designate a local representative, with the overseas headquarters required to manage and supervise that representative; the amendment was signed April 1, 2025 and took effect October 2, 2025.observed

#

Special-category and pseudonymisation rules are Confirmed, but the absence of a statutory consent definition and comparative uncertainty flagged by secondary legal sources keep the lawful-bases sub-module at Probable confidence.

Primary frameworkPersonal Information Protection Act (PIPA)
Traffic-light rationale — AmberSpecial-category and pseudonymisation rules are Confirmed, but the absence of a statutory consent definition and comparative uncertainty flagged by secondary legal sources keep the lawful-bases sub-module at Probable confidence.

Sub-modules (4)

Lawful BasesAmber

PIPA recognises consent as a legal basis for processing but does not define 'consent'; Korean Supreme Court case law has filled interpretive gaps.

Claims (1):

  • PIPA does not statutorily define 'consent,' unlike more prescriptive comparator regimes, creating interpretive reliance on case law and PIPC guidance.

Special CategoriesGreen

Biometric data used to uniquely identify a person is classified as sensitive/special-category information requiring separate consent.

Claims (1):

  • PIPA classifies biometric data collected for the purpose of uniquely identifying a person as a special class of sensitive information, necessitating separate consent for its collection and processing.

Pseudonymisation And AnonymisationGreen

PIPA Article 2(1-2) defines pseudonymous processing as partial deletion or replacement of data such that an individual cannot be identified without additional information.

Claims (1):

  • Under PIPA, 'pseudonymous processing' is processing by methods such as partially deleting or partially/entirely replacing personal data such that no specific individual can be recognised without additional information (Article 2(1-2) PIPA).
Category narrative56 words

PIPA recognises consent alongside other legal bases for processing, but the statute does not itself define 'consent,' leaving interpretive gaps filled by Supreme Court rulings and PIPC guidance. Biometric data used for unique identification is treated as a special/sensitive category requiring separate consent. Pseudonymisation is statutorily defined (Art 2(1-2)) and forms the basis for research/statistics safe-harbours.

Sources and claims (4)
  1. ProbableDataGuidance / Lee & Ko — PIPA does not statutorily define 'consent,' unlike more prescriptive comparator regimes, creating interpretive reliance on case law and PIPC guidance.observed
  2. ProbableDataGuidance / Lee & Ko — To obtain valid consent, a data handler must present the consent request to the data subject in a clearly recognisable manner with each matter requiring consent distinctly presented.observed
  3. ConfirmedarXiv — PIPA classifies biometric data collected for the purpose of uniquely identifying a person as a special class of sensitive information, necessitating separate consent for its collection and processing.observed
  4. ConfirmedEUR-Lex / European Union — Under PIPA, 'pseudonymous processing' is processing by methods such as partially deleting or partially/entirely replacing personal data such that no specific individual can be recognised without additional information (Article 2(1-2) PIPA).observed

#

Core access/rectification/erasure and suspension rights are Confirmed via a T1 EU adequacy instrument and T2/T3 secondary sources; portability (MyData) expansion is Probable as a policy-plan item rather than a fully generalized statutory right at this time.

Primary frameworkPersonal Information Protection Act (PIPA)
Traffic-light rationale — GreenCore access/rectification/erasure and suspension rights are Confirmed via a T1 EU adequacy instrument and T2/T3 secondary sources; portability (MyData) expansion is Probable as a policy-plan item rather than a fully generalized statutory right at this time.

Sub-modules (5)

Access RightGreen

PIPA grants individuals the right to be informed of, and to access, their personal information held by controllers.

Claims (1):

  • PIPA grants individuals significant rights over their personal information, including the right to be informed of and to access data held about them.

Rectification And ErasureGreen

PIPA grants rights to rectify and erase personal information.

Claims (1):

  • PIPA grants individuals the right to rectify and erase their personal information held by controllers.

Restriction And ObjectionGreen

In lieu of a general consent-withdrawal right, PIPA (Art 37) provides a right to suspension of processing, which can also be invoked where processing rests on consent, leading to termination and deletion.

Claims (1):

  • PIPA does not provide a general right to withdraw consent; instead, Article 37 grants a general right to suspension of processing, which can also be invoked where data is processed on the basis of consent, terminating processing and triggering deletion.

Data PortabilityAmber

The PIPC's 2024-2026 basic plan aims to activate 'MyData' (the right to request transmission of personal information) across all fields, building on its existing financial-sector implementation.

Claims (1):

  • The PIPC's 2024-2026 basic plan aims to activate 'MyData' (the right to request transmission of personal information) in all fields as part of South Korea's data-driven society transition.

Deadlines And Response WindowsGreen

Requests for access to personal information held by public institutions may be made directly or indirectly via the PIPC, which must transmit the request without delay (Art 35(2) PIPA; Art 41(3) Enforcement Decree).

Claims (1):

  • Access to personal information processed by a public institution may be obtained directly or, indirectly, by lodging a request with the PIPC, which must transmit the request without delay.
Category narrative69 words

PIPA grants individuals rights to be informed, access, rectify, and erase personal data. Rather than a general right of consent withdrawal, PIPA provides a right to obtain suspension of processing (Art 37), which terminates processing and triggers deletion. The PIPC's 2024-2026 basic plan aims to expand 'MyData' (the right to request transmission of personal information) across all sectors. Public-institution access requests must be transmitted by the PIPC without delay.

Sources and claims (5)
  1. ConfirmedarXiv — PIPA grants individuals significant rights over their personal information, including the right to be informed of and to access data held about them.observed
  2. ConfirmedarXiv — PIPA grants individuals the right to rectify and erase their personal information held by controllers.observed
  3. ConfirmedEDPB — PIPA does not provide a general right to withdraw consent; instead, Article 37 grants a general right to suspension of processing, which can also be invoked where data is processed on the basis of consent, terminating processing and triggering deletion.observed
  4. ProbableDataGuidance — The PIPC's 2024-2026 basic plan aims to activate 'MyData' (the right to request transmission of personal information) in all fields as part of South Korea's data-driven society transition.observed
  5. ConfirmedEUR-Lex / European Union — Access to personal information processed by a public institution may be obtained directly or, indirectly, by lodging a request with the PIPC, which must transmit the request without delay.observed

#

Core breach-notification and DPIA rules are Confirmed and in force, but the most consequential governance/penalty provisions (CEO liability, 10% turnover ceiling, CPO/ISMS-P thresholds) are either enacted-not-yet-effective or still in draft/proposed stage.

Primary frameworkPersonal Information Protection Act (PIPA) and PIPA Enforcement Decree
Traffic-light rationale — AmberCore breach-notification and DPIA rules are Confirmed and in force, but the most consequential governance/penalty provisions (CEO liability, 10% turnover ceiling, CPO/ISMS-P thresholds) are either enacted-not-yet-effective or still in draft/proposed stage.

Sub-modules (7)

Accountability And DpiaAmber

PIPA currently only requires public organisations to conduct a Data Protection Impact Assessment (DPIA); no general private-sector DPIA mandate exists.

Claims (1):

  • PIPA only requires public organisations to conduct a Data Protection Impact Assessment (DPIA).

Dpo RequirementsAmber

A June 2026 draft Enforcement Decree amendment would require organisations meeting revenue/data-volume thresholds to obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer (CPO).

Claims (1):

  • A draft amendment to the PIPA Enforcement Decree (announced June 2, 2026) would require organisations with annual revenue of at least KRW 180 billion processing sensitive data of 50,000+ people or personal data of 1 million+ people, universities with 20,000+ students, large general hospitals, and public information-system operators to obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer.

Ropa RequirementsRed

No dedicated Records-of-Processing-Activities (ROPA) provision distinct from PIPA's general processing-policy disclosure obligations was located in this research pass.

Absence provenance: No claim populated; recommend targeted primary-source review of PIPA Art. 30-32 processing-policy provisions.. Searched: PIPA records of processing activities requirement, PIPA processing policy disclosure obligation.

Joint Controller ArrangementsAmber

PIPA distinguishes between 'provision' of personal information (analogous to controller-to-controller transfer) and 'outsourcing' of processing (analogous to controller-processor arrangements), each carrying distinct obligations.

Claims (1):

  • PIPA distinguishes between the 'provision' of personal information, akin to a controller-to-controller data transfer, and 'outsourcing' of processing, akin to a controller-processor arrangement under the GDPR.

Security MeasuresAmber

ICSPs and third parties receiving user data are subject to specified security obligations (internal management plans, access control, encryption, malware detection); a draft amendment would mandate ISMS-P certification for certain entities by December 31, 2028.

Claims (1):

  • A June 2026 draft PIPA Enforcement Decree amendment would mandate ISMS-P certification for certain entities by December 31, 2028.

Breach NotificationGreen

ICSPs must notify affected users and the PIPC within 24 hours of becoming aware that personal information was lost, stolen, or leaked (Art 39-4(1) PIPA); a June 2026 draft amendment would extend a 72-hour data-subject notification standard more broadly.

Claims (2):

  • Information and communication service providers are required to notify the data subject and the PIPC within 24 hours after becoming aware that personal information has been lost, stolen, or leaked (Article 39-4(1) PIPA).
  • A June 2026 draft amendment to the PIPA Enforcement Decree would require organisations to notify data subjects within 72 hours of discovering unauthorized access or illegal distribution of personal data.

Retention And DisposalRed

No retention-limit/disposal-specific claim was populated in this research pass beyond general breach/pseudonymisation provisions.

Absence provenance: Explicit retention-period statutory text not retrieved in this pass; recommend primary-source follow-up on PIPA Art. 21 destruction obligations.. Searched: PIPA data retention limit disposal obligation.

Category narrative91 words

PIPA currently mandates DPIAs only for public organisations. A June 2026 draft Enforcement Decree amendment would require board-approved CPO appointment/removal notifications for large processors, mandatory ISMS-P certification for certain entities by December 31, 2028, and a 72-hour data-subject breach notification standard; these remain proposed as of this research pass. Information-and-communication service providers (ICSPs) are already bound by a stricter 24-hour breach notification rule under Article 39-4(1) PIPA. The March 2026 PIPA amendment (effective September 11, 2026) introduces personal CEO supervisory liability and raises the penalty ceiling to 10% of total turnover.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedDataGuidance / Lee & Ko — PIPA only requires public organisations to conduct a Data Protection Impact Assessment (DPIA).observed
  2. ProbableDataGuidance — A draft amendment to the PIPA Enforcement Decree (announced June 2, 2026) would require organisations with annual revenue of at least KRW 180 billion processing sensitive data of 50,000+ people or personal data of 1 million+ people, universities with 20,000+ students, large general hospitals, and public information-system operators to obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer.observed
  3. ProbableDataGuidance / Lee & Ko — PIPA distinguishes between the 'provision' of personal information, akin to a controller-to-controller data transfer, and 'outsourcing' of processing, akin to a controller-processor arrangement under the GDPR.observed
  4. ProbableDataGuidance — A June 2026 draft PIPA Enforcement Decree amendment would mandate ISMS-P certification for certain entities by December 31, 2028.observed
  5. ConfirmedEUR-Lex / European Union — Information and communication service providers are required to notify the data subject and the PIPC within 24 hours after becoming aware that personal information has been lost, stolen, or leaked (Article 39-4(1) PIPA).observed
  6. ProbableDataGuidance — A June 2026 draft amendment to the PIPA Enforcement Decree would require organisations to notify data subjects within 72 hours of discovering unauthorized access or illegal distribution of personal data.observed
  7. ConfirmedIAPP — A March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.observed

#

Adequacy-received status and general transfer-mechanism rules are Confirmed via a T1 EU legal instrument and T1 EDPB opinion; however, SCC/BCR-equivalent instruments, transfer-impact-assessment practice, and data-localisation specifics were not evidenced in this pass.

Primary frameworkPersonal Information Protection Act (PIPA); EU Commission Implementing Decision (EU) 2022/254 (adequacy)
Traffic-light rationale — AmberAdequacy-received status and general transfer-mechanism rules are Confirmed via a T1 EU legal instrument and T1 EDPB opinion; however, SCC/BCR-equivalent instruments, transfer-impact-assessment practice, and data-localisation specifics were not evidenced in this pass.

Sub-modules (6)

Transfer MechanismsGreen

PIPA recognises consent, international agreements, and other legal bases as grounds for cross-border transfer, and grants the PIPC power to suspend or cease transfers in certain cases. South Korea is also a member of the APEC CBPR system.

Claims (2):

  • PIPA recognises consent, international agreements, and other legal bases as valid grounds for cross-border transfers, and grants the PIPC power to cease cross-border transfers in certain cases.
  • South Korea became the fifth member of the APEC Cross-Border Privacy Rules (CBPR) system, joining the U.S., Japan, Canada, and Mexico.

Adequacy ReceivedGreen

The European Commission's adequacy decision for South Korea concludes PIPA and PIPC-issued notifications offer protection essentially equivalent to the GDPR; the decision is subject to periodic review at least every four years, with the first review period shortened to three years.

Claims (2):

  • The European Commission concludes that, for each relevant component including rights of individuals and redress mechanisms, South Korean law under PIPA offers a level of protection essentially equivalent to the GDPR, and that the PIPC meets the independence test required under the GDPR.
  • The South Korea adequacy decision is subject to periodic review at least every four years under GDPR Article 45(3), with the first revision period for Korea shortened to three years.

Adequacy GrantedRed

No evidence located in this pass of South Korea granting outbound adequacy-equivalent recognition to other jurisdictions.

Absence provenance: No claim populated; PIPA's outbound-adequacy-granting mechanism (if any) requires further primary-source review.. Searched: South Korea PIPA adequacy decision EU GDPR cross-border transfer mechanism.

Sccs And BcrsRed

No PIPA-specific SCC/BCR-equivalent instrument text was retrieved in this research pass.

Absence provenance: PIPA's contractual-clause equivalent (if formalized) not confirmed in retrieved sources.. Searched: South Korea PIPA adequacy decision EU GDPR cross-border transfer mechanism.

Transfer Impact AssessmentRed

No PIPA-specific transfer-impact-assessment requirement was retrieved in this research pass.

Absence provenance: No claim populated; recommend dedicated search on PIPC transfer risk-assessment guidance.. Searched: South Korea PIPA adequacy decision EU GDPR cross-border transfer mechanism.

Data LocalisationAmber

The adequacy decision excludes personal credit information governed by the Credit Information Act, which remains under FSC oversight; no general data-localisation mandate was otherwise evidenced.

Claims (1):

  • The EU adequacy decision for South Korea excludes the processing of personal credit information pursuant to the Credit Information Act (CIA) by controllers subject to FSC oversight, since such processing falls outside the Decision's scope.
Category narrative90 words

The European Commission adopted an adequacy decision for South Korea (Commission Implementing Decision (EU) 2022/254), concluding that PIPA offers protection essentially equivalent to the GDPR, including on redress and independence of the PIPC. The decision excludes processing of personal credit information under the Credit Information Act (CIA), which remains under Financial Services Commission (FSC) oversight outside PIPC's adequacy-relevant scope. PIPA itself recognises consent, international agreements, and other bases for cross-border transfers, and empowers the PIPC to suspend transfers. South Korea also participates in the APEC Cross-Border Privacy Rules (CBPR) system.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedDataGuidance / Lee & Ko — PIPA recognises consent, international agreements, and other legal bases as valid grounds for cross-border transfers, and grants the PIPC power to cease cross-border transfers in certain cases.observed
  2. ConfirmedIAPP — South Korea became the fifth member of the APEC Cross-Border Privacy Rules (CBPR) system, joining the U.S., Japan, Canada, and Mexico.observed
  3. ConfirmedIAPP — The European Commission concludes that, for each relevant component including rights of individuals and redress mechanisms, South Korean law under PIPA offers a level of protection essentially equivalent to the GDPR, and that the PIPC meets the independence test required under the GDPR.observed
  4. ConfirmedIAPP — The South Korea adequacy decision is subject to periodic review at least every four years under GDPR Article 45(3), with the first revision period for Korea shortened to three years.observed
  5. ConfirmedEUR-Lex / European Union — The EU adequacy decision for South Korea excludes the processing of personal credit information pursuant to the Credit Information Act (CIA) by controllers subject to FSC oversight, since such processing falls outside the Decision's scope.observed

#

Financial and telecoms overlays are Confirmed via T1/T2 sources; health, education, employment, and insurance overlays carry no populated claims in this pass.

Primary frameworkPIPA; Credit Information Use and Protection Act; Network Act (ICNA); Act on Real Name Financial Transactions and Guarantee of Secrecy
Traffic-light rationale — AmberFinancial and telecoms overlays are Confirmed via T1/T2 sources; health, education, employment, and insurance overlays carry no populated claims in this pass.

Sub-modules (7)

Financial Sector OverlayGreen

The Credit Information Use and Protection Act governs personal credit information and is enforced by the FSC; the FSC also operates a 'MyData' licence mechanism for financial companies/FinTechs; the Act on Real Name Financial Transactions applies separately to financial institutions.

Claims (3):

  • The Use and Protection of Credit Information Act applies to credit information used in credit ratings, and the Financial Services Commission is Korea's supervisory authority for the financial sector in that capacity.
  • The FSC published a manual and licence mechanism (July 2020) for financial companies and FinTechs to access and use the credit-information management platform 'MyData,' covering data security, outsourcing, and collection/use checklists.
  • The Act on Real Name Financial Transactions and Guarantee of Secrecy applies separately to financial or financial-services institutions, distinct from PIPA's general regime.

Health Sector OverlayRed

No health-sector-specific data-protection overlay was evidenced in this research pass.

Absence provenance: No dedicated health-sector statute/claim retrieved; recommend targeted search on Korea's Bioethics and Safety Act or medical-data provisions.. Searched: PIPC Korea AI guidelines biometric data facial recognition 2025 2026.

Telecoms And EprivacyGreen

The Network Act (ICNA) imposes additional, stricter consent and security obligations on information-and-communication service providers (ICSPs).

Claims (1):

  • Information-and-communication service providers face additional consent obligations under Article 39-3(1) PIPA and further security obligations under Article 48-2 of the PIPA Enforcement Decree, including internal management plans, access control, and encryption.

Employment DataRed

No employment-sector-specific data-protection overlay was evidenced in this research pass.

Absence provenance: No employment-specific statute/claim retrieved in this pass.. Searched: South Korea Credit Information Act financial sector data protection overlay PIPC FSC.

Credit And ScoringGreen

The Credit Information Use and Protection Act governs personal credit information used in credit ratings, under FSC enforcement.

Claims (1):

  • The Use and Protection of Credit Information Act applies to credit information used in credit ratings, and the Financial Services Commission is Korea's supervisory authority for the financial sector in that capacity.

EducationRed

No education-sector-specific data-protection overlay was evidenced in this research pass.

Absence provenance: No education-specific statute/claim retrieved in this pass.. Searched: South Korea Credit Information Act financial sector data protection overlay PIPC FSC.

InsuranceRed

No insurance-sector-specific data-protection overlay was evidenced in this research pass.

Absence provenance: No insurance-specific statute/claim retrieved in this pass.. Searched: South Korea Credit Information Act financial sector data protection overlay PIPC FSC.

Category narrative97 words

Beyond PIPA, South Korea maintains sector-specific overlays: the Credit Information Use and Protection Act (Credit Act) governs personal credit information used in credit ratings and is enforced by the Financial Services Commission (FSC); the Act on Real Name Financial Transactions and Guarantee of Secrecy applies separately to financial institutions; and the Act on Promotion of Information and Communications Network Utilization and Information Protection (Network Act/ICNA) imposes stricter obligations on information-and-communication service providers. The FSC's 'MyData' credit-information platform operates under its own manual/licence mechanism. Health, education, employment, and insurance sector-specific overlays were not evidenced in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedEUR-Lex / European Union — The Use and Protection of Credit Information Act applies to credit information used in credit ratings, and the Financial Services Commission is Korea's supervisory authority for the financial sector in that capacity.observed
  2. ConfirmedDataGuidance — The FSC published a manual and licence mechanism (July 2020) for financial companies and FinTechs to access and use the credit-information management platform 'MyData,' covering data security, outsourcing, and collection/use checklists.observed
  3. ConfirmedIAPP — The Act on Real Name Financial Transactions and Guarantee of Secrecy applies separately to financial or financial-services institutions, distinct from PIPA's general regime.observed
  4. ConfirmedEUR-Lex / European Union — Information-and-communication service providers face additional consent obligations under Article 39-3(1) PIPA and further security obligations under Article 48-2 of the PIPA Enforcement Decree, including internal management plans, access control, and encryption.observed

#

Only the direct_marketing sub-module has Confirmed claims; five of six declared sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) carry no populated claims and are flagged with explicit absent_field_provenance.

Primary frameworkAct on Promotion of Information and Communications Network Utilization and Information Protection (Network Act/ICNA); PIPA
Traffic-light rationale — RedOnly the direct_marketing sub-module has Confirmed claims; five of six declared sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) carry no populated claims and are flagged with explicit absent_field_provenance.

Sub-modules (6)

Cookies And TrackersRed

No PIPA/Network-Act-specific cookie-consent statutory text was retrieved in this research pass beyond the general ICSP consent framework.

Absence provenance: Dedicated cookie-consent provisions not retrieved verbatim; DataGuidance 'South Korea - Cookies & Similar Technologies' note exists but content was paywalled in retrieved snippet.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.

Dark PatternsRed

No dark-pattern-specific prohibition text was retrieved in this research pass.

Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.

Opt Out SignalsRed

No Global-Privacy-Control/DAA-equivalent opt-out signal framework was retrieved in this research pass.

Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule was retrieved in this research pass.

Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.

Cross Context AdvertisingRed

No cross-context-advertising-specific ('sale'/'share'-equivalent) provision was retrieved in this research pass.

Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.

Direct MarketingGreen

Senders of advertising messages must clearly indicate that consent relates to 'advertising information' (vague terms disallowed) and must provide simplified refusal mechanisms, per the KISA/KCC revised Network Act anti-spam guide (March 2026).

Claims (2):

  • Senders requesting consent to receive advertising messages must clearly indicate that the consent relates to 'advertising information,' with vague expressions such as 'benefit notifications' disallowed, per KISA's revised guide to the Network Act.
  • Users must be able to refuse advertising communications through simplified means, such as app-notification opt-out, without complex procedures.
Category narrative60 words

Under the Network Act, senders of commercial advertising messages must obtain clear, specific consent to 'advertising information' (vague terms such as 'benefit notifications' are disallowed) and must provide simplified opt-out mechanisms, per a March 2026 KISA/KCC revised anti-spam guide. Cookie/tracker-specific consent rules, dark-pattern prohibitions, opt-out signal (GPC/DAA-equivalent) frameworks, clean-room/data-collaboration rules, and cross-context-advertising-specific provisions were not evidenced in this research pass.

Sources and claims (2)
  1. ConfirmedDataGuidance — Senders requesting consent to receive advertising messages must clearly indicate that the consent relates to 'advertising information,' with vague expressions such as 'benefit notifications' disallowed, per KISA's revised guide to the Network Act.observed
  2. ConfirmedDataGuidance — Users must be able to refuse advertising communications through simplified means, such as app-notification opt-out, without complex procedures.observed

#

Enforcement precedent (model deletion, biometric special-category status, law-enforcement carve-out) is Confirmed via T1/T2 sources, but the Generative AI Guide is non-binding soft guidance and genetic-data-specific rules were not evidenced.

Primary frameworkPersonal Information Protection Act (PIPA); PIPC Guide for Development and Use of Generative AI (non-binding guidance)
Traffic-light rationale — AmberEnforcement precedent (model deletion, biometric special-category status, law-enforcement carve-out) is Confirmed via T1/T2 sources, but the Generative AI Guide is non-binding soft guidance and genetic-data-specific rules were not evidenced.

Sub-modules (6)

Profiling RestrictionsAmber

The PIPC's Kakao Pay/Alipay enforcement action addressed unlawful profiling (an 'NSF score' built without notice or consent from transferred user data).

Claims (1):

  • The PIPC's January 2025 Kakao Pay decision found the wallet provider sent 40 million users' data to Alipay, which built 'NSF scores' for Apple Pay without notice or consent, resulting in a KRW 8.3 billion fine and an order to erase the algorithm itself.

Automated Decision Making TransparencyAmber

The same Kakao Pay/Alipay decision required destruction of the AI-derived scoring algorithm, evidencing PIPC's willingness to compel algorithmic transparency/remediation beyond monetary fines.

Claims (1):

  • The PIPC's January 2025 Kakao Pay decision found the wallet provider sent 40 million users' data to Alipay, which built 'NSF scores' for Apple Pay without notice or consent, resulting in a KRW 8.3 billion fine and an order to erase the algorithm itself.

Ai Risk AssessmentsAmber

The PIPC published a Guide for the Development and Use of Generative AI (August 6, 2025), a non-binding reference outlining minimum legal/safety requirements, impact assessments, and Privacy by Design across the AI lifecycle.

Claims (1):

  • The PIPC published a Guide for the Development and Use of Generative AI on August 6, 2025, outlining minimum requirements for legal and safe personal-data processing across the generative-AI lifecycle, including impact assessments and Privacy by Design.

Biometric RegimeGreen

Biometric data collected for unique identification is treated as sensitive/special-category information under PIPA, requiring separate consent.

Claims (1):

  • PIPA classifies biometric data used to uniquely identify an individual as a special category of sensitive information requiring separate consent for collection and processing.

Genetic DataRed

No genetic-data-specific provision was evidenced in this research pass.

Absence provenance: No genetic-data-specific statute/claim retrieved in this pass.. Searched: PIPC Korea AI guidelines biometric data facial recognition 2025 2026.

State Surveillance CarveoutsAmber

The EDPB's adequacy opinion notes that PIPA's provisions apply without limitation in the area of law enforcement, a carve-out subject to continued EU monitoring under the adequacy decision.

Claims (1):

  • PIPA's provisions apply without limitation in the area of law enforcement, per the EDPB's assessment of the Korea adequacy decision, a carve-out the EDPB flagged for continued monitoring.
Category narrative112 words

The PIPC has taken an increasingly assertive posture on algorithmic accountability: its January 2025 Kakao Pay/Alipay decision fined the companies KRW 8.3 billion and ordered destruction of an AI-trained credit-scoring algorithm built on unlawfully transferred user data, following on from the 2021 Scatter Lab precedent confirming PIPA's reach into AI training data. In August 2025 the PIPC published a Guide for the Development and Use of Generative AI, setting minimum legal/safety requirements across the AI lifecycle. Biometric data used for unique identification is a special category requiring separate consent. The EDPB's adequacy assessment notes that PIPA's provisions apply without limitation in the law-enforcement area, a national-security carve-out subject to ongoing EU monitoring.

Sources and claims (4)
  1. ConfirmedIAPP — The PIPC's January 2025 Kakao Pay decision found the wallet provider sent 40 million users' data to Alipay, which built 'NSF scores' for Apple Pay without notice or consent, resulting in a KRW 8.3 billion fine and an order to erase the algorithm itself.observed
  2. ConfirmedDataGuidance — The PIPC published a Guide for the Development and Use of Generative AI on August 6, 2025, outlining minimum requirements for legal and safe personal-data processing across the generative-AI lifecycle, including impact assessments and Privacy by Design.observed
  3. ConfirmedarXiv — PIPA classifies biometric data used to uniquely identify an individual as a special category of sensitive information requiring separate consent for collection and processing.observed
  4. ConfirmedEDPB — PIPA's provisions apply without limitation in the area of law enforcement, per the EDPB's assessment of the Korea adequacy decision, a carve-out the EDPB flagged for continued monitoring.observed

#

Only two of five declared sub-modules carry populated claims, and even those rest on comparative (Probable/Uncertain) rather than direct PIPA-primary-text confirmation of the exact age threshold.

Primary frameworkPersonal Information Protection Act (PIPA); Act on the Protection and Use of Location Information (analogous child-consent threshold)
Traffic-light rationale — RedOnly two of five declared sub-modules carry populated claims, and even those rest on comparative (Probable/Uncertain) rather than direct PIPA-primary-text confirmation of the exact age threshold.

Sub-modules (5)

Age VerificationAmber

The Act on the Protection and Use of Location Information sets a 14-years-old threshold requiring legal-representative consent for collecting children's location data; whether PIPA itself uses an identical threshold was not directly confirmed in this pass.

Claims (1):

  • Under Korea's Act on the Protection and Use of Location Information, a location-information provider seeking to collect, use, or provide personal location information from children under the age of 14 must obtain the consent of their legal representative.

Minor Profiling BansRed

No minor-specific profiling ban was evidenced in this research pass.

Absence provenance: No claim populated in this pass.. Searched: PIPA Article 22-2 children under 14 legal representative consent Korea.

Education SettingsRed

No education-settings-specific children's-data rule was evidenced in this research pass.

Absence provenance: No claim populated in this pass.. Searched: PIPA Article 22-2 children under 14 legal representative consent Korea.

Dependent AdultsRed

No dependent-adult-specific protection was evidenced in this research pass.

Absence provenance: No claim populated in this pass.. Searched: PIPA Article 22-2 children under 14 legal representative consent Korea.

Category narrative88 words

PIPA requires the consent of a guardian or legal representative to process children's personal information, paralleling GDPR Art 8, but the statute lacks provisions specifically targeted at protecting children's data comparable to COPPA's granular regime. A precise, PIPA-specific statutory age threshold was not confirmed verbatim in this research pass; the analogous Location Information Act sets a 14-years-old threshold for requiring legal-representative consent to collect children's location data, which is indicative but not conclusive for PIPA's own child-consent age. Minor-profiling bans, education-settings-specific rules, and dependent-adult protections were not evidenced.

Sources and claims (2)
  1. UncertainDataGuidance (hosting official statute translation) — Under Korea's Act on the Protection and Use of Location Information, a location-information provider seeking to collect, use, or provide personal location information from children under the age of 14 must obtain the consent of their legal representative.observed
  2. ProbableDataGuidance / Lee & Ko — Both the GDPR and PIPA provide that the consent of a guardian or legal representative is required to process the personal information of children, though PIPA does not contain provisions specifically targeted at protecting children's personal information comparable to COPPA.observed

#

Enforcement activity and the forthcoming penalty regime are Confirmed at high materiality, but collective-redress and private-right-of-action mechanisms carry no populated claims, and regulator funding/capacity information rests on a non-binding EDPB observation.

Primary frameworkPersonal Information Protection Act (PIPA), as amended March 2026
Traffic-light rationale — AmberEnforcement activity and the forthcoming penalty regime are Confirmed at high materiality, but collective-redress and private-right-of-action mechanisms carry no populated claims, and regulator funding/capacity information rests on a non-binding EDPB observation.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, effective September 11, 2026.

Claims (1):

  • South Korea's March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.

Enforcement Activity IndexGreen

Recent enforcement includes the July 2026 Apple fine (Siri voice data) and the January 2025 Kakao Pay/Alipay fine with algorithm-deletion order.

Claims (2):

  • On July 23, 2026, the PIPC fined Apple Distribution International Limited KRW 252 million (approx. $171,400) for violations of PIPA and the former Information and Communications Network Act, following an investigation into unauthorized collection of Siri voice data until August 2019.
  • The PIPC's January 2025 Kakao Pay decision levied a KRW 8.3 billion fine on the wallet provider after finding it sent 40 million users' data to Alipay without consent, and ordered destruction of the resulting AI-derived scoring algorithm.

Regulator Funding And CapacityAmber

The EDPB's 2021 adequacy opinion noted the draft decision lacked reference to PIPC staffing and financial resources, and requested further clarification.

Claims (1):

  • The EDPB's 2021 opinion on the draft Korea adequacy decision noted that no reference was made to the specificities of PIPC staffing or the financial resources made available to it, and welcomed additional information.

Collective Redress And Class ActionsRed

No PIPA-specific collective-redress or class-action mechanism was evidenced in this research pass.

Absence provenance: No claim populated in this pass.. Searched: PIPC Korea enforcement fine 2026.

Private Right Of ActionRed

No PIPA-specific private-right-of-action mechanism distinct from PIPC administrative enforcement was evidenced in this research pass.

Absence provenance: No claim populated in this pass.. Searched: PIPC Korea enforcement fine 2026.

Recent Developments 180DGreen

Within the last 180 days: the July 23, 2026 Apple fine, and the June 2, 2026 draft PIPA Enforcement Decree amendment (CPO governance, ISMS-P, 72-hour breach notice).

Claims (2):

  • On June 2, 2026, the PIPC announced a draft amendment to the PIPA Enforcement Decree introducing CPO board-approval/notification requirements, mandatory ISMS-P certification by December 31, 2028, and a 72-hour breach-notification standard.
  • On July 23, 2026, the PIPC fined Apple Distribution International Limited KRW 252 million (approx. $171,400) for violations of PIPA and the former Information and Communications Network Act, following an investigation into unauthorized collection of Siri voice data until August 2019.
Category narrative112 words

The PIPC has demonstrated sustained, aggressive enforcement, including a KRW 252 million fine against Apple (July 23, 2026) over unauthorized Siri voice-data collection and the KRW 8.3 billion Kakao Pay/Alipay fine plus algorithm-deletion order (January 2025). The March 2026 PIPA amendment substantially raises the stakes, introducing a 10%-of-turnover penalty ceiling and personal CEO supervisory liability, effective September 11, 2026; the June 2026 draft Enforcement Decree amendment would further formalize CPO governance, ISMS-P certification, and 72-hour breach notification. The EDPB's 2021 opinion flagged a lack of detailed information on PIPC's staffing and financial resources as an area needing clarification. Collective-redress/class-action and private-right-of-action mechanisms specific to PIPA were not evidenced in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedIAPP — South Korea's March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.observed
  2. ConfirmedDataGuidance — On July 23, 2026, the PIPC fined Apple Distribution International Limited KRW 252 million (approx. $171,400) for violations of PIPA and the former Information and Communications Network Act, following an investigation into unauthorized collection of Siri voice data until August 2019.observed
  3. ConfirmedIAPP — The PIPC's January 2025 Kakao Pay decision levied a KRW 8.3 billion fine on the wallet provider after finding it sent 40 million users' data to Alipay without consent, and ordered destruction of the resulting AI-derived scoring algorithm.observed
  4. ConfirmedEDPB — The EDPB's 2021 opinion on the draft Korea adequacy decision noted that no reference was made to the specificities of PIPC staffing or the financial resources made available to it, and welcomed additional information.observed
  5. ProbableDataGuidance — On June 2, 2026, the PIPC announced a draft amendment to the PIPA Enforcement Decree introducing CPO board-approval/notification requirements, mandatory ISMS-P certification by December 31, 2028, and a 72-hour breach-notification standard.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct90.48
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for South Korea
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s) (43 category placement(s)), 27 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator/framework, lawful-processing/special-data, data-subject-rights, cross-border/adequacy, and enforcement/redress modules rest substantially on T1 sources (EDPB Opinion 32/2021, EU Commission Implementing Decision (EU) 2022/254) supplemented by T2 secondary legal/news commentary (IAPP, DataGuidance). Controller/processor-duties and sectoral-watch modules mix Confirmed T1/T2 in-force provisions with Probable/proposed items still in draft (June 2026 Enforcement Decree amendment) or enacted-not-yet-effective (March 2026 CEO-liability/10%-turnover amendment, effective Sept 11, 2026). Adtech/commercial-privacy and children/vulnerable-groups modules are thin: only direct_marketing and two children's-data sub-modules are populated, relying on T2 sources and one T3/analogous-statute inference (Location Information Act's 14-year threshold used as an indicative, not confirmed, proxy for PIPA's own child-consent age). Algorithmic/biometric/surveillance-governance module combines T1 EDPB material with T2 enforcement reporting but lacks genetic-data-specific evidence.

Unresolved questions (5):

  • What is PIPA's own statutory age threshold for requiring legal-representative consent to process children's personal information (Art 22-2), independent of the analogous Location Information Act's 14-year threshold?
  • Has the June 2, 2026 draft PIPA Enforcement Decree amendment (CPO governance, ISMS-P certification, 72-hour breach notice) been finalized, and on what effective date?
  • What SCC/BCR-equivalent contractual transfer instruments, if any, does PIPA formally recognize for private-sector cross-border transfers absent adequacy?
  • Does PIPA provide a dedicated collective-redress/class-action or private-right-of-action mechanism distinct from PIPC administrative enforcement?
  • What are the precise ROPA (records-of-processing) and retention/disposal obligations under PIPA's processing-policy provisions (Arts 21, 30-32)?

Escalate to primary-source review: yes