South Korea South Korea personal information protection PIPC platform

Korea's 10% Fine Ceiling Is Defensible Only Because the Prevention Discount Makes Security Spending Pay

South Korea's amended PIPA took effect Sept. 11 with fines up to 10% of revenue and CEO accountability; the 40% prevention discount is what keeps it proportionate.

Korea's PIPA Penalty Reset People of Internet Research · South Korea 10% New maximum fine ceiling Of revenue, up from 3%, for seriou… 40% Max prevention fine discount For demonstrated investment in bud… ₩624.7B Coupang fine, June 2026 Largest Korean data protection pen… ₩134.8B SK Telecom fine, 2025 Imposed August 28, 2025 over an Ap… peopleofinternet.com
Korea's PIPA Penalty Reset People of Internet Research · South Korea 10% New maximum fine ceiling 40% Max prevention fine discount ₩624.7B Coupang fine, June 2026 ₩134.8B SK Telecom fine, 2025 peopleofinternet.com

Key Takeaways

South Korea's amended Personal Information Protection Act (PIPA) took effect on September 11, 2026. It was promulgated on March 10, 2026, according to the IAPP's analysis. The headline change is a penalty ceiling raised from 3% to 10% of revenue for the worst cases, plus personal supervisory liability for chief executives. The design is tougher than most privacy regimes, but it is more proportionate than the headline suggests.

The strongest case for the reform

Regulators have a real argument. Korea has just lived through two record breaches. The Personal Information Protection Commission (PIPC) fined SK Telecom 134.8 billion won on August 28, 2025. The breach exposed data on more than 23 million users. The PIPC cited unencrypted USIM authentication keys, poor access controls and delayed notification to users. In June 2026 it went further, fining Coupang 624.7 billion won over a breach touching 33.2 million members. The regulator said the cause was "deficiencies in basic safety management" rather than sophisticated hacking.

The IAPP quotes the reform's logic: fines do not change corporate behavior unless they are large enough to matter. If a company can treat a 3% cap as a cost of doing business, the security budget will lose to other priorities. Board-level accountability is a fair response to failures that were basic, not exotic.

What the law actually does

According to Hunton's summary, the 10% ceiling is not general. It applies where a company:

That is a narrow gate. Ordinary negligence still falls under the lower ceiling. The law also makes the business owner or representative the "ultimate responsible person" for data protection. Companies above 180 billion won in revenue that process sensitive data on large populations must get board approval before appointing or dismissing a chief privacy officer. As JoongAng Daily reports, the law also requires notifying users within 72 hours where exposure is highly likely, even if a leak is not confirmed.

Where proportionality is won or lost

The best feature is the incentive structure. JoongAng Daily reports fine reductions of up to 40% for demonstrated investment in budgets, staffing and systems. It reports a further reduction for early detection, prompt reporting and containment. Hunton notes that the details of the investment discount are left to a presidential decree. That makes the decree the most important document still to come. A firm that spends on encryption and access control before an incident should see a real, predictable benefit. A firm that spends nothing should face the full ceiling.

This is the right shape for regulation. It rewards the behavior that prevents harm and does not merely punish its absence. The SK Telecom findings map neatly onto it: unencrypted keys and plain-text administrator credentials are the kind of failures a prevention discount is designed to price in.

The risks a pro-innovation reader should watch

There are three.

Vague triggers. "Gross negligence" and "meaningful possibility of an incident" are judgment calls. Hunton notes that notification can be required on identifying a meaningful possibility of an incident. Under a 72-hour clock, a cautious firm may notify on weak signals. That risks over-notification, which trains users to ignore alerts. The PIPC should publish worked examples of the threshold early.

Executive liability chills the wrong things. Personal exposure can push a CEO toward paper compliance: documents, sign-offs and audits that satisfy a checklist without improving security. Board-approved privacy officers help only if they have real authority and budget. Startups below the 180 billion won revenue line should not be pulled into the same apparatus by informal expectation.

Revenue-based ceilings punish scale, not harm. A fine keyed to total revenue can bear little relation to the actual damage. The 10 million-person trigger partly answers this, because it ties the top tier to demonstrable scale. Still, the PIPC's discretion here is wide, and Korean courts have seen appeals of large fines before.

What good enforcement looks like

The test over the next 12 months is not the first record fine. It is whether the PIPC applies the 10% tier only to repeat or willful offenders. It should also publish how it calculates the prevention discount, so that companies can plan security budgets against a known formula. Its English-language press release page shows the commission is already issuing frequent decisions and amendments, so transparency about method is feasible. Korea's official PIPA text is hosted by the commission, but the English version lags the amendment. Foreign firms that operate in Korea should not have to guess.

Korea has chosen higher stakes. That is defensible after breaches this large, provided the discount is generous, the triggers are narrow and the decree arrives quickly. If it does, security spending becomes the cheapest way to manage regulatory risk, which is the outcome an evidence-based privacy law should aim for.

Sources & Citations

  1. PIPC English press release list
  2. PIPC: Personal Information Protection Act and regulations
  3. IAPP: South Korea overhauls PIPA
  4. Hunton: Korea authorizes fines up to 10% of revenue
  5. JoongAng Daily: Korea raises data breach fines
  6. The Record: Coupang record fine
  7. Korea Times: SK Telecom fined