The EU, Korea, and Japan form the world’s most interoperable privacy triangle: both Asian regimes hold EU adequacy, and both borrowed GDPR vocabulary in their latest amendments. But the three laws still reason differently, GDPR polices legal grounds, PIPA polices consent and prescriptive security, APPI polices purpose boundaries, and the differences surface exactly where global templates assume uniformity.
| Axis | GDPR | PIPA (Korea) | APPI (Japan) |
|---|---|---|---|
| Model | Lawful basis | Consent-centric + 2023 alternatives | Purpose limitation |
| Max fine | EUR 20M / 4% turnover | 3% total revenue | JPY 100M (criminal) |
| Breach clock | 72h to authority | 72h to individuals + PIPC | Prompt + 30/60-day final |
| DPO | Conditional | Mandatory | Customary |
| EU adequacy | n/a | Yes (2021) | Yes (2019, mutual) |
| Texts | EUR-Lex | KLRI English | JLT English |
Where the triangle bends
Consent quality. Korea demands the most: separate consents per purpose, itemized transfer consents, and regulator hostility to bundled UX (the 2022 Google/Meta KRW 30.8B decision turned on consent design). GDPR’s Article 7 standard is high but basis-substitutable; APPI needs consent rarely, but validly when it does.
Security prescriptiveness. PIPA and its enforcement decrees specify controls, encryption of unique identifiers, access-log retention, network separation for large handlers, where GDPR Article 32 stays risk-based and APPI points to PPC guidelines. Korean audits check the control list literally.
Rights. All three grant access, correction, deletion, and suspension/objection variants. GDPR adds portability as standard; Korea added portability foundations and automated-decision rights in 2023; Japan grants disclosure of provision records, unique among the three, and deceased-relative rights exist in China but none of these three.
Enforcement economics. GDPR: administrative fines plus private damages at EU scale. Korea: revenue-based fines plus statutory damages without proof of harm. Japan: modest criminal ceilings, but public naming and correction orders that move markets. Budget accordingly: EU and Korea carry the financial tail risk.
One program, three laws
Build GDPR-first, then: (1) Korean layer, privacy officer, control-list security, separate-consent UX, 72-hour dual notification, transfer bases per the 2023 rules; (2) Japanese layer, published utilization purposes, provision/receipt records, categorical breach matrix, Article 28 transfer handling; (3) shared machinery, one DSAR pipeline, one breach playbook with three notification maps, one ROPA with per-country views. The country deep-dives: PIPA, APPI, and the GDPR guide.