Korea’s PIPA spent a decade as the strictest consent regime in Asia, then rebuilt itself in 2023 into something closer to GDPR with Korean enforcement teeth. The amendment merged the special online-provider rules into one uniform law, widened lawful bases beyond consent, added automated-decision rights, and, most consequentially for foreign platforms, moved fines onto a total-revenue baseline. The PIPC has used that power: Meta’s KRW 21.6 billion fine in November 2024 for processing religious and political inference data of Korean users is the current benchmark.
| Regulation | PIPA, Act No. 10465 of 2011 (2023 amendment effective 15 September 2023) |
|---|---|
| Max penalty | 3% of total annual revenue (administrative); 5 years (criminal) |
| Enforcing authority | PIPC |
| Official text | PIPA (English, KLRI) |
| EU adequacy | Yes, since 17 December 2021 |
The duty structure
Lawful processing. Consent, statute, contract necessity (since 2023 a full basis, not a crutch), urgent life/safety/property interests, public tasks, and a narrow legitimate-interest clause where the controller’s justifiable interest clearly overrides the data subject’s rights. Sensitive information (beliefs, health, sex life, biometric and genetic data, criminal records) and unique identifiers require separate consent or explicit legal authorization; resident registration numbers are barred outright absent statute.
Transparency and rights. Privacy policies must be published in prescribed detail; data subjects hold access, correction, deletion, suspension, and consent-withdrawal rights, plus the 2023 right to refuse or demand explanation of fully automated decisions that materially affect them, Korea’s Article 22 analogue.
Security and accountability. Mandated technical-organizational measures (encryption of unique identifiers and passwords, access logging, network controls per PIPC standards), a designated privacy officer, mandatory PIA for public institutions and recommended for high-risk private processing, and a domestic agent for large offshore controllers.
Breach. 72 hours to notify individuals and report qualifying incidents; the PIPC publishes enforcement outcomes, and litigation follows, Korea recognizes statutory damages for breaches without proof of specific harm.
Enforcement pattern
The PIPC combines audits, fines, and correction orders, with foreign platforms a stated priority: Meta (KRW 21.6B, 2024; earlier KRW 30.8B jointly with Google in 2022 over behavioral advertising consent), AliExpress (KRW 1.978B, 2024, unlawful overseas provision), Golfzon (KRW 7.5B, 2023, ransomware breach). Public-sector leaks draw disciplinary referrals. The 2022 Google/Meta decision remains the largest consent-related penalty in Korean history and signaled that dark-pattern consent flows fail PIPA.
Plan exports with the Korea transfer guide, compare regimes in PIPA vs GDPR vs APPI, and note the finance-sector overlay in the Credit Information Act guide. Baseline what your Korean-facing site collects with a free scan.