South Korea South Korea personal information protection PIPC platform

South Korea's New Privacy Law Ties CEOs to a 10% Revenue Fine Ceiling

South Korea's amended privacy law, effective today, raises maximum fines to 10% of revenue and makes CEOs accountable for privacy officers.

Korea's Privacy Law Overhaul, By the Numbers People of Internet Research · South Korea 10% Maximum revenue-based fine Up from 3%, for repeat, large-scal… 10M+ affected Top-tier fine threshold A single incident this size auto-q… 72 hours Breach notification window Now triggered by suspected exposur… $409M (Coupang) Prior record PIPC fine Issued June 2026, entirely under t… peopleofinternet.com
Korea's Privacy Law Overhaul, By the N… People of Internet Research · South Korea 10% Maximum revenue-based fi… 10M+ affected Top-tier fine threshold 72 hours Breach notification win… $409M (Coupang) Prior record PIPC fine peopleofinternet.com

Key Takeaways

South Korea's amended Personal Information Protection Act (PIPA) takes effect today, September 11, 2026, and it is the most consequential rewrite of the country's privacy regime since the Personal Information Protection Commission (PIPC) was established as an independent regulator in 2020. The headline number is a fine ceiling of 10% of total company revenue, up from 3%, for the most serious violations. But the more structurally important change is what surrounds it: statutory personal liability for CEOs, board-level sign-off on chief privacy officer appointments, and a breach-notification trigger that now fires on suspicion rather than confirmation.

The Case the Regulator Is Making

Before criticizing this, it is worth taking the PIPC's argument seriously, because the record supports it. In June 2026, the PIPC fined Coupang 624.7 billion won ($409 million) — its largest penalty ever — after a breach exposed data on more than 33 million registered members plus millions more non-member delivery records, citing basic failures in safety management. That fine was issued entirely under the old law. Before that, SK Telecom was fined roughly $97 million after a 2025 breach traced to unrestricted internal network access exposed roughly 23 million subscribers' USIM data, with regulators finding the company had been vulnerable since at least 2021. Two of Korea's largest consumer-facing companies, in successive years, failed at security basics affecting tens of millions of people. The PIPC's conclusion — that fines calculated as a fraction of relevant product revenue were too small to force board-level attention — is not a reach. It is a reasonable read of what actually happened.

What Changes Today

The 10% ceiling is not a blanket increase; it is reserved for three specific triggers: a repeat violation involving willful misconduct or gross negligence within a three-year window, a single incident from intentional or grossly negligent conduct affecting 10 million or more people, or a breach following a company's failure to comply with a PIPC corrective order. Companies that can show sustained investment in privacy staffing, budget, and technical safeguards can have that fine reduced by up to 40% — a genuinely well-designed carrot alongside the stick, since it rewards prevention rather than just punishing failure after the fact.

The accountability piece is new territory for Korean privacy law. The amendment designates the business owner or representative — in practice, the CEO — as the person ultimately responsible for personal information protection. For larger data controllers, appointing, reassigning, or dismissing a chief privacy officer now requires board approval and formal notification to the PIPC, and the CPO must have direct reporting lines and budget authority rather than being a compliance figurehead buried in middle management.

Breach notification also tightens. Companies must now notify affected individuals within 72 hours once there is a reasonable likelihood of exposure — not once a breach is fully confirmed, which was the prior, higher bar. The scope of what counts as a reportable incident expands too, explicitly covering forgery, alteration, and destruction of data, which sweeps in ransomware attacks that scramble records without necessarily exfiltrating them.

Where the Proportionality Argument Gets Harder

The investment-linked fine reduction is the strongest part of this law, and other regulators drafting breach-penalty regimes should study it: it explicitly prices in the fact that perfect security is impossible and rewards demonstrated effort, not just outcomes. That is proportionate regulation done well.

The weaker part is the "reasonable likelihood" notification standard. Moving away from waiting for confirmed breaches is defensible — victims deserve faster warning — but "reasonable likelihood" is inherently a judgment call, and companies now face a 72-hour clock to make it under threat of a fine that scales with total revenue, not just the harm caused. That creates a real incentive to over-notify defensively, which erodes public trust in notifications the same way alarm fatigue erodes trust in any warning system that cries wolf too often.

Personal CEO liability is the other place where deterrence and proportionality pull apart. It is one thing to require a company to invest adequately in security; it is another to make an individual executive personally exposed for a subordinate's operational failure, particularly at multinational firms whose Korea unit is a small piece of global revenue but whose CEO now bears outsized personal risk relative to that unit's size. Combined with a fine denominator of total company revenue rather than Korea-specific revenue, this could make senior international executives more cautious about how much decision-making authority they're willing to delegate to a Korea office — the opposite of what a healthy, growing digital economy needs.

The Bottom Line

South Korea did not invent this fine after a single bad news cycle — it followed two of the largest data-protection enforcement actions in the PIPC's history, both under a weaker law. The deterrence logic is sound, and the investment-reduction mechanism shows real regulatory craftsmanship. Whether this ages well now depends on execution: how conservatively the PIPC calibrates "reasonable likelihood" in practice, and whether enforcement stays targeted at the systemic failures the law was written for — the Coupangs and SK Telecoms — rather than becoming a revenue-scaled cudgel against companies whose sins are marginal but whose parent balance sheets are large.

Sources & Citations

  1. National Law Information Center — Personal Information Protection Act
  2. Personal Information Protection Commission (official site)
  3. Diplomacy Journal — PIPC announcement on Sept. 11 enforcement of amended PIPA
  4. IAPP — South Korea overhauls PIPA and ties fines to CEO accountability
  5. The Record — South Korea hits Coupang with record $409 million fine