South Korea's amended Personal Information Protection Act (PIPA) took effect on September 11, 2026. It was promulgated on March 10, 2026, according to the IAPP's analysis. The headline change is a penalty ceiling raised from 3% to 10% of revenue for the worst cases, plus personal supervisory liability for chief executives. The design is tougher than most privacy regimes, but it is more proportionate than the headline suggests.
The strongest case for the reform
Regulators have a real argument. Korea has just lived through two record breaches. The Personal Information Protection Commission (PIPC) fined SK Telecom 134.8 billion won on August 28, 2025. The breach exposed data on more than 23 million users. The PIPC cited unencrypted USIM authentication keys, poor access controls and delayed notification to users. In June 2026 it went further, fining Coupang 624.7 billion won over a breach touching 33.2 million members. The regulator said the cause was "deficiencies in basic safety management" rather than sophisticated hacking.
The IAPP quotes the reform's logic: fines do not change corporate behavior unless they are large enough to matter. If a company can treat a 3% cap as a cost of doing business, the security budget will lose to other priorities. Board-level accountability is a fair response to failures that were basic, not exotic.
What the law actually does
According to Hunton's summary, the 10% ceiling is not general. It applies where a company:
- intentionally or through gross negligence repeats a violation within three years;
- engages in intentional or grossly negligent conduct affecting 10 million or more people; or
- fails to comply with a PIPC corrective order and a breach occurs.
That is a narrow gate. Ordinary negligence still falls under the lower ceiling. The law also makes the business owner or representative the "ultimate responsible person" for data protection. Companies above 180 billion won in revenue that process sensitive data on large populations must get board approval before appointing or dismissing a chief privacy officer. As JoongAng Daily reports, the law also requires notifying users within 72 hours where exposure is highly likely, even if a leak is not confirmed.
Where proportionality is won or lost
The best feature is the incentive structure. JoongAng Daily reports fine reductions of up to 40% for demonstrated investment in budgets, staffing and systems. It reports a further reduction for early detection, prompt reporting and containment. Hunton notes that the details of the investment discount are left to a presidential decree. That makes the decree the most important document still to come. A firm that spends on encryption and access control before an incident should see a real, predictable benefit. A firm that spends nothing should face the full ceiling.
This is the right shape for regulation. It rewards the behavior that prevents harm and does not merely punish its absence. The SK Telecom findings map neatly onto it: unencrypted keys and plain-text administrator credentials are the kind of failures a prevention discount is designed to price in.
The risks a pro-innovation reader should watch
There are three.
Vague triggers. "Gross negligence" and "meaningful possibility of an incident" are judgment calls. Hunton notes that notification can be required on identifying a meaningful possibility of an incident. Under a 72-hour clock, a cautious firm may notify on weak signals. That risks over-notification, which trains users to ignore alerts. The PIPC should publish worked examples of the threshold early.
Executive liability chills the wrong things. Personal exposure can push a CEO toward paper compliance: documents, sign-offs and audits that satisfy a checklist without improving security. Board-approved privacy officers help only if they have real authority and budget. Startups below the 180 billion won revenue line should not be pulled into the same apparatus by informal expectation.
Revenue-based ceilings punish scale, not harm. A fine keyed to total revenue can bear little relation to the actual damage. The 10 million-person trigger partly answers this, because it ties the top tier to demonstrable scale. Still, the PIPC's discretion here is wide, and Korean courts have seen appeals of large fines before.
What good enforcement looks like
The test over the next 12 months is not the first record fine. It is whether the PIPC applies the 10% tier only to repeat or willful offenders. It should also publish how it calculates the prevention discount, so that companies can plan security budgets against a known formula. Its English-language press release page shows the commission is already issuing frequent decisions and amendments, so transparency about method is feasible. Korea's official PIPA text is hosted by the commission, but the English version lags the amendment. Foreign firms that operate in Korea should not have to guess.
Korea has chosen higher stakes. That is defensible after breaches this large, provided the discount is generous, the triggers are narrow and the decree arrives quickly. If it does, security spending becomes the cheapest way to manage regulatory risk, which is the outcome an evidence-based privacy law should aim for.