Skip to content
NOAHLAW OFFICE
  1. Home
  2. Insights
  3. Technology & Privacy

South Korea’s September 2026 PIPA Amendments — Management Accountability, 72-Hour Notification and the New Surcharge Framework

The September 2026 PIPA amendments reshape management accountability, incident notification and surcharge risk. This report explains the principal changes and practical compliance priorities.

Author & reviewer Bo-Gyeong Kim, Attorney at LawUpdated Last reviewed
In this report

01. Privacy Governance Is Now an Explicit Management Responsibility

Amendments to South Korea’s Personal Information Protection Act (“PIPA”) and its Enforcement Decree took effect on 11 September 2026. The amendments do more than strengthen sanctions after a data incident. They expressly identify business owners and corporate representatives as ultimately responsible for privacy governance, strengthen the role and governance of Chief Privacy Officers (“CPOs”), introduce notification obligations in certain situations where a data compromise is not yet fully confirmed, and permit administrative penalty surcharges of up to 10% of total revenue for specified repeat or serious violations.[1][3]

For businesses, implementation should therefore extend beyond revising a privacy policy. The practical questions include who escalates privacy risks to management, when the organisation is deemed to have become aware of an incident, who makes the 72-hour notification decision, and whether privacy investments are actually operating as part of the compliance framework.

New Article 30-3 of PIPA provides that the business owner or representative of a personal information controller bears ultimate responsibility for the safe processing of personal information and the protection of data-subject rights. Management must effectively provide overall support, including professional privacy personnel and sufficient budgets.[1][3]

The CPO’s statutory responsibilities have also been strengthened. They include managing professional privacy personnel, securing budgets and reporting significant privacy matters and the organisation’s privacy position to the business owner, representative and board. Controllers must also safeguard the CPO’s ability to perform the role independently.[1]

The new board-resolution and regulatory filing requirements do not apply identically to every company. For ordinary businesses, the current Enforcement Decree captures businesses whose annual revenue exceeds KRW 180 billion and which also meet either of the following criteria:[2]

  • processing sensitive information or unique identification information relating to at least 50,000 data subjects; or
  • processing personal information relating to at least one million data subjects.

Separate rules apply to certain universities, tertiary general hospitals and public-system operators. Where a qualifying controller is a corporation, appointment, change or removal of the CPO requires a board resolution. The relevant appointment, change or removal must also be reported to the Personal Information Protection Commission (“PIPC”), generally within six months of the relevant event.[2]

Practical Implication

Businesses should not treat CPO appointment as a formal title only. They should examine whether:

  • the CPO can escalate privacy risks directly to management;
  • sufficient budget and personnel can be requested;
  • reported risks lead to actual management decisions;
  • corrective measures are implemented; and
  • the process produces reliable contemporaneous records.

The focus is increasingly on whether the governance framework actually functions.

02. Confirmed Compromise: the Practical Clock Is 72 Hours from Awareness

Where a controller becomes aware that personal information has been compromised, PIPA requires notification to affected data subjects, while the Enforcement Decree provides a 72-hour period from awareness for notification.[2]

The relevant trigger is therefore not simply the date on which the technical intrusion occurred. An incident may have begun several days earlier, while the 72-hour analysis may turn on when the controller actually became aware that a qualifying compromise had occurred.

The Enforcement Decree permits notification after the relevant impediment is removed where, for example:[2]

  • urgent steps are required to block access paths, remediate vulnerabilities, or recover or delete compromised data; or
  • natural disaster or another unavoidable circumstance makes notification within 72 hours impracticable.

A Business Should Not Wait for the Entire Investigation to Finish

At the notification deadline, the organisation may not yet know every affected data field or the exact time and cause of the incident. That does not necessarily permit the entire notification to be postponed. The framework permits an initial notification using the information then available, followed by further notification when additional facts are confirmed.[2]

Accordingly, the completion of forensic work and the legal deadline for notification may not coincide.

Businesses should separately record:

estimated incident time → first anomaly detected → awareness of compromise → additional facts identified → initial notification

Where there is a significant delay between the incident and discovery, evidence showing when the organisation actually became aware of the compromise may become particularly important.

03. Certain Incidents Must Also Be Reported to PIPC Within 72 Hours

Not every incident triggers regulatory reporting, but specified categories must be reported within the applicable 72-hour period.[2]

These include, in particular:

  • compromise involving at least 1,000 data subjects;
  • compromise involving sensitive information or unique identification information; and
  • compromise resulting from unlawful external access.

Notification to data subjects and regulatory reporting are separate compliance steps and should therefore be assigned and tracked separately within an incident-response process.

Where the route of compromise has been identified and recovery, deletion or other measures have reduced the possibility of infringement of data-subject rights to a markedly low level, the Enforcement Decree provides a limited exception under which reporting may not be required.[2]

The amended concept of compromise also extends beyond traditional loss, theft and disclosure to include forgery, alteration and damage of personal information.[1][3]

A business should therefore not assume that no report is required merely because data was not visibly exfiltrated from its systems.

04. Notification May Be Required Even Before Actual Compromise Is Confirmed

One of the most significant changes is the introduction of notification obligations for a possible personal information compromise.

The Enforcement Decree identifies two principal situations.[2]

The first is unlawful access to a personal information system or device used for processing, where there are circumstances indicating a possible compromise but the affected data subjects cannot readily be identified.

The second is where compromise of some personal information has been confirmed and it is reasonably recognised that information relating to other data subjects may also have been compromised.

This does not mean that every security alert automatically requires customer notification. The statutory circumstances must be present.

Contents of a Possible-Compromise Notification

ItemRequired Information
1Categories of personal information potentially affected
2Suspected or recognised time and circumstances of the possible compromise
3Harm-mitigation guidance, the controller’s response and remedies, and relevant contact information
4A statement that further notification will be provided if actual compromise is confirmed

Scroll horizontally to read the full table.

The possible-compromise notification framework also operates on a 72-hour statutory timeline.[2]

If actual compromise is confirmed within the same statutory 72-hour period, the controller should provide the confirmed-compromise notification required under Article 34(1) rather than treating the earlier possible-compromise notice as creating a new 72-hour period.[2]

If the investigation instead confirms that no compromise occurred, the controller must notify the affected individuals of that conclusion without delay. Where individual contact information cannot reasonably be obtained, the Enforcement Decree also provides alternative public-notice mechanisms.[2]

Practical Implication

An incident-response plan should no longer contain only one path: confirmed breach → notify customers.

It should instead provide for: anomaly → possible-compromise assessment → possible-compromise notification decision → confirmation or rejection of actual compromise → confirmed notification or no-compromise follow-up.

05. The Information Provided to Data Subjects Has Expanded

The amended law also expands the information to be included in a compromise notification. In addition to information concerning the affected data, the timing and circumstances of the incident, harm-mitigation steps, the controller’s response and relevant contact details, the notification framework now expressly addresses information concerning legal remedies available to data subjects, including damages claims, statutory damages and privacy dispute mediation.[1][3]

A customer notice should therefore be more than an apology or a statement that an investigation is continuing.

Organisations should consider preparing templates capable of addressing:

  • established facts;
  • matters still under investigation;
  • steps data subjects can take to reduce harm;
  • actions taken by the organisation;
  • contact details;
  • available remedies; and
  • whether further updates will follow.

06. The 10% Surcharge Is Not a General Penalty for Every Data Incident

The amended PIPA permits PIPC to impose an administrative penalty surcharge of up to 10% of total revenue for specified repeat or serious violations. It does not apply automatically to every data incident.[4]

CategoryPrincipal Conditions
Repeat violationA violation under the same numbered item of Article 64-2(1) within three years after a previous surcharge disposition, with intention or gross negligence in both violations
Large-scale harmAn intentional or grossly negligent qualifying violation resulting in harm to at least 10 million data subjects
Failure to comply with a corrective orderFailure to comply with a corrective order resulting in a qualifying compromise under Article 64-2(1)(9)

Scroll horizontally to read the full table.

The surcharge is also not calculated simply by applying a percentage to total corporate revenue. PIPA requires the calculation to exclude revenue unrelated to the violation.[4]

A practical assessment should therefore proceed through at least the following stages:

  1. Is the conduct subject to a surcharge?
  2. What revenue is unrelated to the violation?
  3. Do the enhanced 10% provisions apply?
  4. Does mandatory investment mitigation apply?
  5. Are there further adjustments or grounds for non-imposition?

07. Privacy Investment Is Now Linked to Mandatory Mitigation

The amendments combine stronger enforcement with a statutory incentive for preventive privacy investment.

Article 64-2(6) provides that PIPC shall reduce the surcharge where the prescribed privacy-investment and operational requirements are satisfied. Accordingly, where the statutory requirements are met, whether to apply the investment-based reduction is not simply a matter of unfettered discretion.[4]

The Enforcement Decree and related standards direct consideration of factors including:

  • the scale, proportion and continuity of investment in privacy budgets, personnel, equipment and systems;
  • the extent to which management fulfils its statutory responsibilities;
  • the CPO’s role and the organisation’s privacy governance structure; and
  • additional efforts to strengthen security measures.[2][5]

The current PIPC surcharge guideline defines this investment mitigation as a reduction of up to 40% of the base amount.[5]

There is, however, an important limitation. The mandatory investment-based reduction does not apply where the violation was committed intentionally or with gross negligence.[4]

Investment therefore does not itself provide immunity. A business must satisfy the applicable legal and regulatory criteria, and the amount of the reduction depends on the quality, scale, continuity and actual operation of the relevant privacy measures.

08. In Certain Cases, PIPC May Decide Not to Impose a Surcharge

Article 64-2(7) also provides grounds on which PIPC may refrain from imposing a surcharge.[4]

No.Grounds to consider
1Objectively insufficient ability to pay because of insolvency, suspension of payments or capital impairment
2A legitimate reason for mistakenly believing the conduct was lawful
3Minor seriousness of the violation or a small calculated surcharge
4Other prescribed cases where data-subject harm did not occur or was minor

Scroll horizontally to read the full table.

The statute uses discretionary language—PIPC may refrain from imposing the surcharge. The final analysis, however, should also examine the Enforcement Decree and PIPC’s current surcharge guideline, which further specify how the statutory grounds operate in practice.[4][5]

A meaningful surcharge-risk assessment should therefore consider not only the maximum statutory percentage, but the entire sequence of enhancement → mandatory mitigation → further adjustment → possible non-imposition.

09. LAW NOAH Analysis — Three Immediate Compliance Priorities

1) The Organisation Must Be Able to Prove When It Became Aware of an Incident

The 72-hour framework makes chronology critical. Businesses should be able to distinguish when the technical event likely occurred, when an anomaly was first detected, when a possible compromise became known, when actual compromise was confirmed, and when management and the CPO were informed.

Security logs alone may not tell the entire story. Internal escalation and decision records may also become important.

2) Privacy Investment Should Be Demonstrated Through Operation, Not Procurement Alone

Purchasing security software or equipment is not the same as operating an effective privacy framework. The amended regime looks beyond expenditure to the continuity of investment, management accountability, CPO governance and actual operation of safeguards.

The more useful compliance record is therefore: investment → implementation → operation → detection of weaknesses → remediation.

3) Supplier Contracts Should Support the Statutory Response Timetable

Cloud providers, SaaS vendors, developers, marketing agencies and other processors may be the first organisations to identify suspicious activity. Even a well-designed internal 72-hour response process can fail if a vendor reports an incident too late.

Businesses should therefore consider whether processing and security agreements adequately address:

  • rapid reporting of suspected as well as confirmed incidents;
  • emergency points of contact;
  • preservation of logs and evidence;
  • access to investigation materials; and
  • continuing updates as the investigation develops.

This is a practical contractual response to the amended notification framework, not a claim that PIPA mandates identical contractual wording in every agreement.

10. Practical Business Checklist

AreaQuestions to Review
ManagementCan significant privacy risks reach the CEO or board?
CPODo appointment, authority, budget, board-resolution and filing requirements apply?
Incident awarenessAre anomaly, possible-compromise and confirmed-compromise times separately recorded?
NotificationsIs there a 72-hour decision process and an initial/follow-up notification procedure?
Possible compromiseAre the trigger, required information and no-compromise follow-up addressed?
Regulatory reportingDoes the incident involve 1,000+ data subjects, sensitive/unique-ID data or unlawful external access?
VendorsDo contracts support rapid reporting, evidence preservation and investigation cooperation?
SurchargesHas the business assessed relevant revenue, enhanced surcharge conditions, mandatory mitigation and non-imposition grounds?
InvestmentCan privacy expenditure be connected to actual and continuing operation of safeguards?

Scroll horizontally to read the full table.

The broader significance of the September 2026 amendments is that privacy compliance is moving further from being an isolated IT function toward an integrated management and incident-response responsibility.

Updating a privacy policy alone is unlikely to be enough. Businesses should examine whether decision-making authority, incident information, statutory deadlines and operational safeguards are connected within one functioning compliance system.

Sources

  1. National Law Information Center — PIPA amendment effective 11 September 2026 ↗
  2. National Law Information Center — PIPA Enforcement Decree effective 11 September 2026 ↗
  3. Personal Information Protection Commission — Press release on strengthened privacy accountability and management (9 March 2026) ↗
  4. National Law Information Center — PIPA Article 64-2 (Administrative Penalty Surcharges) ↗
  5. National Law Information Center — PIPC Guidelines on Administrative Penalty Surcharges for PIPA Violations ↗

This report reflects the position at its stated review date. Subsequent amendments or changes in practice should be checked separately.

This content provides general legal information, not legal advice for an individual matter. The applicable law and the specific facts may lead to a different assessment.

← Back to insightsContact the office →