Asia-Pacific South Korea

South Korea PIPA: Personal Information Protection Act Guide

Korea's PIPA after the 2023 overhaul: scope, consent rules, revenue-based fines up to 3%, 72-hour breach reporting, and PIPC enforcement against Meta and others.

Regulation

Personal Information Protection Act (Act No. 10465 of 2011, substantially amended 2023)

Max Penalty

Administrative fine up to 3% of total annual revenue (less unrelated revenue); criminal penalties up to 5 years

Enforcing Authority

Personal Information Protection Commission (PIPC)

Official Source

www.pipc.go.kr

Executive Summary

  • PIPA (2011) is Korea's omnibus privacy law, consolidated further by the 2023 amendment that absorbed the online-service rules and unified duties for all controllers.
  • The 2023 amendment re-based administrative fines to up to 3% of total annual revenue (with unrelated revenue deductible), among the region's toughest, and added a right against fully automated decisions.
  • Consent remains central, but 2023 widened non-consent bases, including contract necessity, easing Korea's historically rigid consent-for-everything practice.
  • Breach notification runs on a 72-hour clock to affected individuals and the PIPC for qualifying incidents.
  • The PIPC enforces hard: KRW 21.6 billion against Meta (November 2024) for processing sensitive data of Korean users without a legal basis, plus actions against AliExpress, Golfzon, and public bodies.

Korea’s PIPA spent a decade as the strictest consent regime in Asia, then rebuilt itself in 2023 into something closer to GDPR with Korean enforcement teeth. The amendment merged the special online-provider rules into one uniform law, widened lawful bases beyond consent, added automated-decision rights, and, most consequentially for foreign platforms, moved fines onto a total-revenue baseline. The PIPC has used that power: Meta’s KRW 21.6 billion fine in November 2024 for processing religious and political inference data of Korean users is the current benchmark.

RegulationPIPA, Act No. 10465 of 2011 (2023 amendment effective 15 September 2023)
Max penalty3% of total annual revenue (administrative); 5 years (criminal)
Enforcing authorityPIPC
Official textPIPA (English, KLRI)
EU adequacyYes, since 17 December 2021

The duty structure

Lawful processing. Consent, statute, contract necessity (since 2023 a full basis, not a crutch), urgent life/safety/property interests, public tasks, and a narrow legitimate-interest clause where the controller’s justifiable interest clearly overrides the data subject’s rights. Sensitive information (beliefs, health, sex life, biometric and genetic data, criminal records) and unique identifiers require separate consent or explicit legal authorization; resident registration numbers are barred outright absent statute.

Transparency and rights. Privacy policies must be published in prescribed detail; data subjects hold access, correction, deletion, suspension, and consent-withdrawal rights, plus the 2023 right to refuse or demand explanation of fully automated decisions that materially affect them, Korea’s Article 22 analogue.

Security and accountability. Mandated technical-organizational measures (encryption of unique identifiers and passwords, access logging, network controls per PIPC standards), a designated privacy officer, mandatory PIA for public institutions and recommended for high-risk private processing, and a domestic agent for large offshore controllers.

Breach. 72 hours to notify individuals and report qualifying incidents; the PIPC publishes enforcement outcomes, and litigation follows, Korea recognizes statutory damages for breaches without proof of specific harm.

Enforcement pattern

The PIPC combines audits, fines, and correction orders, with foreign platforms a stated priority: Meta (KRW 21.6B, 2024; earlier KRW 30.8B jointly with Google in 2022 over behavioral advertising consent), AliExpress (KRW 1.978B, 2024, unlawful overseas provision), Golfzon (KRW 7.5B, 2023, ransomware breach). Public-sector leaks draw disciplinary referrals. The 2022 Google/Meta decision remains the largest consent-related penalty in Korean history and signaled that dark-pattern consent flows fail PIPA.

Plan exports with the Korea transfer guide, compare regimes in PIPA vs GDPR vs APPI, and note the finance-sector overlay in the Credit Information Act guide. Baseline what your Korean-facing site collects with a free scan.

Frequently Asked Questions

Who must comply with PIPA?

Every 'personal information controller': businesses, public institutions, organizations, and individuals processing personal information for business purposes, onshore or offshore where Korean data subjects are targeted. Since 2023 the separate, stricter regime for online service providers was merged, so one duty set applies to all controllers, with a domestic-agent requirement for large foreign operators.

How large are PIPA fines really?

Up to 3% of total annual revenue, but the controller can prove out revenue unrelated to the violation. Benchmarks: Meta KRW 21.6 billion (2024, sensitive data); Golfzon KRW 7.5 billion (2023, breach of 2.2 million users); AliExpress KRW 1.978 billion (2024, transfers). Criminal exposure (up to 5 years) attaches to acts like processing sensitive data unlawfully.

What changed on consent in 2023?

Korea moved off consent-maximalism: contract performance and urgent interests became workable standalone bases, consent requests must be clear and refusable without service denial beyond necessity, and the amendment directed simpler, layered consent UX. Sensitive information and unique identifiers (resident registration numbers) still demand separate consent or statutory authorization.

What are the breach notification rules?

Notify affected individuals and report to the PIPC within 72 hours when a breach involves 1,000 or more people, sensitive information, or unlawful outside access, covering what leaked, when, how, and mitigation. The old 24-hour rule for online providers was harmonized to 72 hours in the 2023 consolidation.

Does Korea have EU adequacy?

Yes, since 17 December 2021, covering commercial operators and public authorities, with the PIPC's supplementary rules binding recipients. EEA data can flow to Korea without SCCs; the decision passed its first review in 2024 and works alongside Korea's own expanded 2023 transfer bases.

Regulatory Crosswalk

GDPRAPPIPIPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.