#
Core regulator, statutory basis, and material scope are Confirmed via T1/T2 sources; only territorial scope carries residual definitional ambiguity noted by secondary legal commentary.
Sub-modules (5)
Regulator And AuthorityGreen
PIPC is the statutory enforcement authority for PIPA and its Enforcement Decree.
Claims (1):
- The Personal Information Protection Commission (PIPC) is responsible for enforcing PIPA and the PIPA Enforcement Decree.
Act And InstrumentsGreen
PIPA, enacted September 30, 2011, is a comprehensive statute applying broadly, including to government entities.
Claims (1):
- South Korea's comprehensive Personal Information Protection Act was enacted September 30, 2011 and is considered one of the world's strictest privacy regimes, enforced with criminal and regulatory penalties.
Material ScopeGreen
PIPA applies to most organisations, public and private, processing personal information.
Claims (1):
- PIPA protects privacy rights from the data subject's perspective and applies broadly to most organizations, including government entities.
Territorial ScopeAmber
PIPA does not explicitly codify territorial/extraterritorial scope; application to foreign entities is assessed on factors such as Korea-targeted services.
Claims (1):
- PIPA does not explicitly specify its territorial or extraterritorial scope; in practice, applicability to foreign entities is determined by factors such as whether services are targeted at Koreans.
Regulator Registration And FilingGreen
Foreign business operators meeting statutory criteria must establish a domestic corporation and designate/supervise a local representative, in force since October 2, 2025.
Claims (1):
- Foreign business operators processing personal information who meet statutory criteria must establish a domestic corporation and designate a local representative, with the overseas headquarters required to manage and supervise that representative; the amendment was signed April 1, 2025 and took effect October 2, 2025.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
- ConfirmedDataGuidance — The Personal Information Protection Commission (PIPC) is responsible for enforcing PIPA and the PIPA Enforcement Decree.observed
- ConfirmedIAPP — South Korea's comprehensive Personal Information Protection Act was enacted September 30, 2011 and is considered one of the world's strictest privacy regimes, enforced with criminal and regulatory penalties.observed
- ConfirmedIAPP — PIPA protects privacy rights from the data subject's perspective and applies broadly to most organizations, including government entities.observed
- ProbableDataGuidance / Lee & Ko — PIPA does not explicitly specify its territorial or extraterritorial scope; in practice, applicability to foreign entities is determined by factors such as whether services are targeted at Koreans.observed
- ConfirmedDataGuidance — Foreign business operators processing personal information who meet statutory criteria must establish a domestic corporation and designate a local representative, with the overseas headquarters required to manage and supervise that representative; the amendment was signed April 1, 2025 and took effect October 2, 2025.observed