News
South Korea's Amended PIPA: Tougher Penalties, Stronger CPO Governance and New Breach Rules

The amended Personal Information Protection Act (PIPA), revised in March, and the amended Enforcement Decree of the PIPA, adopted on 10 September and specifying matters delegated under the PIPA, entered into force on 11 September.
The amendments introduce significant changes to South Korea’s privacy framework, including a stricter penalty regime for certain serious violations, strengthened governance requirements for Chief Privacy Officers (CPOs), and expanded obligations in relation to potential personal information breaches.
The key changes introduced by the amended PIPA and Enforcement Decree are set out below.
⚖️ Stricter Penalties and Incentives for Proactive Data Protection
The amended PIPA introduces a stricter administrative fine regime, with fines of up to 10% of total revenue in cases of repeated, intentional or grossly negligent breaches, large-scale harm, or breach after failure to comply with corrective orders. The amount of the fine is assessed on the basis of, among others, the seriousness of the violation and the harm caused.
At the same time, organisations may receive a reduction of up to 40% of the baseline fine where they can demonstrate proactive investment in personal information protection, including:
- sustained investment in privacy resources (personnel, facilities, equipment);
- strong governance involving the CEO, such as the level of CEO interest and commitment to the protection of personal information;
- strong governance involving the Chief Privacy Officer, such as the performance of their duties, their expertise and the authority actually granted to them;
- security measures exceeding legal requirements, for example additional encryption beyond the legally required categories.
This reduction does not apply where the relevant violation was committed intentionally or through gross negligence. A structured calculation method has therefore been introduced, under which the final administrative fine may be adjusted upward or downward, subject to a maximum cap of 10% of total revenue.
👤 Stronger CPO Authority and New Board and PIPC Requirements
The amendment clarifies the ultimate responsibility of Chief Executive Officers and strengthens the authority and duties of Chief Privacy Officers, including the management of specialised personnel, securing a budget and the obligation to report to the board of directors. The intention is to strengthen CEO and CPO responsibilities in order to promote continuous personal information security management systems among personal information controllers.
The amended PIPA also introduces a new requirement for certain major personal information controllers to obtain board approval and notify the Personal Information Protection Commission (PIPC) when a CPO is appointed, changed or removed. The Enforcement Decree specifies the categories of entities subject to this obligation, which are the same categories already required to appoint a professional CPO:
- entities processing more than KRW 180 billion in annual sales or revenue and processing either the personal information of 1,000,000 or more individuals, or the sensitive information or unique identification information of 50,000 or more individuals;
- universities with 20,000 or more enrolled students;
- tertiary general hospitals;
- institutions operating major public systems.
Personal Information Controllers subject to the notification obligation must obtain board approval for the appointment, change or removal of a CPO, and notify the PIPC within six months from the date on which the reason for notification occurs. For CPOs appointed before 11 September, separate board approval is not required, but notification to the PIPC must be completed within six months from 11 September. In unavoidable circumstances, such as difficulties in convening a board meeting for business reasons, the notification deadline may be extended by up to one year upon request. Notifications must be submitted through the Personal Information Portal by completing the CPO notification form and attaching the required supporting documents.
A grace period applies until 31 December 2027, during which administrative fines will not be imposed for failures relating to CPO appointment, qualification requirements, the board approval obligation or notification.
🚨 Notification of Potential Breaches and a Broader Concept of Breach
Under the amended PIPA, data subjects must be notified where there are reasonable grounds to believe that a breach has likely occurred, even if the breach has not yet been conclusively confirmed. The intention is to allow people to react quickly to early-stage incidents that could lead to large-scale breaches.
Notification must be made within 72 hours of becoming aware of the relevant circumstances where:
- illegal access occurs to a personal information processing system, or to devices used by persons handling personal information, and a breach is suspected but it is difficult to identify the affected individuals;
- some personal information is confirmed to have been leaked, for example because it has been illegally traded, and it is recognised that personal information of other individuals may also have been compromised.
If a breach is confirmed within the period for potential breach notification, the breach notification replaces the potential breach notification. However, if it is later established that no breach occurred, a correction notice must be issued to avoid unnecessary confusion or concern among data subjects.
The amendment also expands the information that must be provided following a breach, and brings incidents that were not sufficiently addressed, such as ransomware-related alteration or destruction of personal information, within the scope of breach reporting requirements. Measures to prevent further damage, including deletion and recovery of leaked personal information, have also been strengthened.
✅ What Should Organisations Do Now?
Following the entry into force of the amended PIPA and Enforcement Decree, organisations should review their privacy governance and incident response framework to ensure compliance with the new requirements. In particular, organisations should:
- Assess whether they are subject to the new CPO notification obligation, and where applicable ensure that CPO appointments, changes or removals are approved by the board and notified to the PIPC within the applicable deadline. Existing CPO appointments should also be reviewed in light of the notification requirement and the grace period running until 31 December 2027;
- Strengthen the role and authority of the CPO, including appropriate resources, budget, expertise, reporting lines and involvement of C-level management;
- Document proactive investments in personal information protection, including governance, staffing, and technical and organisational measures, as these may be taken into account to reduce administrative fines;
- Update personal information breach procedures to address the new obligation to notify data subjects where there are reasonable grounds to believe that a breach is likely to have occurred, even before it is conclusively confirmed;
- Review breach notification templates and response procedures to reflect the expanded definition of a breach, the additional information to be provided to data subjects, and the strengthened measures relating to recovery, deletion and mitigation of harm.
🔎 Conclusion
Overall, the amendment requires organisations to move towards a more proactive approach to privacy governance, executive management responsibility and early breach response.
In short, the key changes are a stricter enforcement framework for serious violations, stronger CPO governance and oversight, and earlier notification requirements where a personal information breach is reasonably suspected. Organisations should ensure that their governance arrangements, CPO framework and incident response procedures reflect these new requirements.
Authors: Laura Mello Laufer & Benjamine Bombeck
Running clinical trials or processing health data in South Korea? Our outsourced DPO for Life Sciences teams review your CPO framework, breach procedures and South Korea PIPA obligations against the amended rules.

