Asia-Pacific South Korea / EU / Japan

PIPA vs. GDPR vs. APPI: Korea, EU, and Japan Compared

A three-way comparison of Korea's PIPA, the EU GDPR, and Japan's APPI: lawful bases, fines, breach clocks, transfers, and how to run one program across all three.

Regulation

PIPA; Regulation (EU) 2016/679; APPI

Max Penalty

PIPA: 3% of total revenue; GDPR: EUR 20M or 4%; APPI: JPY 100M criminal

Enforcing Authority

PIPC (Korea); EU supervisory authorities; PPC (Japan)

Official Source

www.pipc.go.kr

Executive Summary

  • All three jurisdictions interoperate through EU adequacy: Japan since January 2019 (mutual), Korea since December 2021, so EEA data flows to both without SCCs.
  • Lawful-basis philosophy differs: GDPR requires a basis for everything; PIPA is consent-centric with 2023-widened alternatives; APPI runs on published purpose limitation with consent at the edges.
  • Fine models diverge sharply: GDPR up to 4% of worldwide turnover, PIPA up to 3% of total revenue, APPI capped at JPY 100 million criminal fines.
  • Breach clocks: GDPR 72 hours to the authority; PIPA 72 hours to individuals and regulator; APPI prompt preliminary plus 30/60-day final reports.
  • One program can serve all three if built GDPR-first with Korean consent granularity and Japanese purpose-statement discipline layered on.

The EU, Korea, and Japan form the world’s most interoperable privacy triangle: both Asian regimes hold EU adequacy, and both borrowed GDPR vocabulary in their latest amendments. But the three laws still reason differently, GDPR polices legal grounds, PIPA polices consent and prescriptive security, APPI polices purpose boundaries, and the differences surface exactly where global templates assume uniformity.

AxisGDPRPIPA (Korea)APPI (Japan)
ModelLawful basisConsent-centric + 2023 alternativesPurpose limitation
Max fineEUR 20M / 4% turnover3% total revenueJPY 100M (criminal)
Breach clock72h to authority72h to individuals + PIPCPrompt + 30/60-day final
DPOConditionalMandatoryCustomary
EU adequacyn/aYes (2021)Yes (2019, mutual)
TextsEUR-LexKLRI EnglishJLT English

Where the triangle bends

Consent quality. Korea demands the most: separate consents per purpose, itemized transfer consents, and regulator hostility to bundled UX (the 2022 Google/Meta KRW 30.8B decision turned on consent design). GDPR’s Article 7 standard is high but basis-substitutable; APPI needs consent rarely, but validly when it does.

Security prescriptiveness. PIPA and its enforcement decrees specify controls, encryption of unique identifiers, access-log retention, network separation for large handlers, where GDPR Article 32 stays risk-based and APPI points to PPC guidelines. Korean audits check the control list literally.

Rights. All three grant access, correction, deletion, and suspension/objection variants. GDPR adds portability as standard; Korea added portability foundations and automated-decision rights in 2023; Japan grants disclosure of provision records, unique among the three, and deceased-relative rights exist in China but none of these three.

Enforcement economics. GDPR: administrative fines plus private damages at EU scale. Korea: revenue-based fines plus statutory damages without proof of harm. Japan: modest criminal ceilings, but public naming and correction orders that move markets. Budget accordingly: EU and Korea carry the financial tail risk.

One program, three laws

Build GDPR-first, then: (1) Korean layer, privacy officer, control-list security, separate-consent UX, 72-hour dual notification, transfer bases per the 2023 rules; (2) Japanese layer, published utilization purposes, provision/receipt records, categorical breach matrix, Article 28 transfer handling; (3) shared machinery, one DSAR pipeline, one breach playbook with three notification maps, one ROPA with per-country views. The country deep-dives: PIPA, APPI, and the GDPR guide.

Frequently Asked Questions

Which of the three laws is strictest?

Depends on the axis. Fines and case law: GDPR. Consent granularity and regulator aggression toward platforms: PIPA, the PIPC's KRW 21.6B Meta fine and KRW 30.8B Google/Meta consent decision are the region's landmark actions. Day-to-day prescriptiveness (mandated security measures, encryption rules): PIPA again. APPI is lightest on paper but demanding on purpose discipline and breach reporting.

Can data move freely between the EU, Korea, and Japan?

Largely yes on the EEA-outbound side: both Japan and Korea hold adequacy, so EEA data flows in under each country's supplementary rules. Korea-Japan flows need a basis under each law (Japan does not list Korea as equivalent-standard, and vice versa), so intra-Asia transfers typically ride consent or contractual safeguards.

Do all three require a DPO?

Korea: yes, every controller designates a privacy officer (with 2023 qualification rules for large controllers). Japan: no statutory DPO, though practice and PPC guidance expect a responsible manager. EU: only when Article 37 triggers apply (public bodies, large-scale monitoring, or sensitive data at scale).

How do the sensitive-data definitions line up?

Core categories (health, beliefs, sex life, biometrics) overlap. Korea adds unique identifiers with near-prohibition of resident registration numbers. Japan's 'special care-required' list adds crime-victim status but treats financial data as ordinary. GDPR alone covers trade union membership explicitly; Korea and Japan handle it under beliefs/social status. Mapping fields to the strictest applicable definition is the safe design.

Which automated-decision rules apply where?

GDPR Article 22 (right not to be subject to solely automated significant decisions), PIPA's 2023 right to refuse or demand explanation of fully automated decisions, and APPI, nothing specific yet, though Japan's triennial review has examined it. Build the explanation-and-override capability once and apply it in the EU and Korea.

Regulatory Crosswalk

GDPRPIPAAPPI

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.