South Korea
ComprehensivePersonal Information Protection Act (PIPA)
Authority: Personal Information Protection Commission (PIPC) | Enforcement: Active | Enacted: September 2011
Overview
South Korea's PIPA is one of the strictest data protection laws in Asia. The 2023 amendments enhanced cross-border transfer rules and introduced data portability. South Korea has EU adequacy status. Enforcement is active with significant penalties.
14-Topic Coverage
Data Protection Authority
Fully AddressedPIPC is the independent supervisory authority with strong enforcement powers.
Consent Requirements
Fully AddressedOpt-in consent required with detailed disclosure. Separate consent for sensitive data, cross-border transfers, and marketing.
Data Subject Rights
Fully AddressedRights to access, correction, deletion, suspension, and data portability (2023 amendment).
Cross-Border Transfer
Fully AddressedAdequacy, consent, SCCs, or BCRs. 2023 amendments modernised transfer framework. EU adequacy mutual recognition.
Breach Notification
Fully AddressedMust notify PIPC and affected individuals within 72 hours of discovery.
DPO Requirements
Fully AddressedChief Privacy Officer (CPO) required for all personal information processors above certain thresholds.
Children's Data
Fully AddressedConsent of legal guardian required for children under 14.
Penalties & Enforcement
Fully AddressedUp to 3% of related revenue. Criminal penalties. Active enforcement with significant fines.
Sector-Specific Rules
Fully AddressedCredit Information Act, Network Act provisions, health data regulations.
Cookie/Tracking
Fully AddressedNetwork Act requires consent for cookies and tracking. Active enforcement.
AI & Automated Decisions
Partially AddressedRight to reject automated decisions. AI governance framework under development.
Data Localisation
Partially AddressedFinancial and certain government data must be stored locally.
Significant Data Fiduciary
Not AddressedNo direct equivalent but thresholds trigger enhanced obligations.
Government Data
Fully AddressedPIPA applies to government. Separate provisions for public institutions.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate South Korea's regulations.
Book a Consultation