← All guides
Privacy14 min read24 July 2026

South Korea PIPA 2023 Amendments: Consent Architecture, Data Portability, 72-Hour Breach Notification & PIPO Obligations (2026)

Complete guide to South Korea's Personal Information Protection Act (PIPA) 2023 amendments — data portability, automated decision-making rights, 72-hour breach notification, local representative requirements, and PIPC enforcement.

South Korea PIPA 2023 Amendments: The Most Significant Reform Since 2011

South Korea's Personal Information Protection Act (PIPA — 개인정보 보호법) underwent landmark reform in 2023, introducing EU GDPR-inspired provisions including data portability, automated decision-making rights, and a unified 72-hour breach notification timeline. Enforced by the Personal Information Protection Commission (PIPC — 개인정보보호위원회), PIPA now carries penalties of up to KRW 3 billion or 3% of relevant global turnover — making it one of the toughest privacy enforcement regimes in Asia. Use the South Korea PIPA Compliance Checker to assess your organisation across all 42 key obligations.

PIPA History: From 2011 to 2023

When South Korea enacted PIPA in 2011, it became one of the world's first countries to adopt a comprehensive omnibus privacy law outside the EU. The law consolidated a fragmented landscape of sector-specific rules into a single framework covering all personal information handlers (개인정보처리자). In 2020, major structural reforms transferred enforcement authority to the newly independent PIPC, consolidating powers previously split between the Ministry of the Interior, Korea Communications Commission, and Korea Internet and Security Agency (KISA).

The 2023 amendments represent the most substantive content changes since the law's inception, aligning PIPA more closely with the EU GDPR while preserving Korea-specific requirements such as the strict Resident Registration Number (RRN) protection rules and the unique dual-track enforcement regime for Information and Communications Service Providers (ICSPs).

Lawful Basis and Consent Architecture (Articles 15–22)

PIPA provides six lawful bases for processing personal information: (1) consent of the data subject, (2) contractual necessity, (3) legal obligation, (4) vital interests, (5) public task, and (6) legitimate interests. Consent remains the most commonly used basis in practice.

Consent requirements: Consent must be freely given, specific, informed, and unambiguous — materially similar to GDPR standards. Consent cannot be bundled with terms of service. Withdrawal must be as easy as giving consent. Separate, explicit consent is required for sensitive personal information (민감정보), which includes race, beliefs, political views, health/medical data, sexual orientation, genetic information, criminal history, biometric data, and unique identification numbers.

Minimum collection principle: Only personal information strictly necessary for the stated purpose may be collected (최소 수집 원칙). This is actively enforced by PIPC — collecting fields "just in case" is a recognised violation.

Resident Registration Number (RRN): The 13-digit Korean national identification number is among the most strictly regulated data elements in any jurisdiction globally. Processing of RRNs is prohibited unless explicitly authorised by law (RRN Protection Act + PIPA Article 24) or approved in exceptional circumstances by PIPC. Mandatory encryption at rest and in transit is required when RRNs are held under legal authorisation. PIPC regularly fines organisations for unauthorised collection of RRNs even where consent was obtained.

2023 Amendment: New Data Subject Rights

Right to data portability (이동요구권 — Art. 35-2): Data subjects can request that their personal information be provided to them in a structured, machine-readable format, or transferred directly to a designated third party (e.g. a competing service provider). This right applies to personal information provided by the data subject where processing is based on consent or contractual necessity. PIPC will designate eligible categories of information and recipient sectors through ministerial decree — initial focus is expected on financial and health data.

Right regarding automated decision-making (Art. 37-2): Data subjects have the right to: (1) request an explanation of automated decisions that significantly affect them (e.g. credit scoring, job applicant screening, benefit eligibility), and (2) object to such decisions and request human review. Handlers must respond with a meaningful explanation within 30 days. This mirrors GDPR Article 22 but with broader application to private sector automated systems.

Existing rights: Access (열람요구) — 10-day response; correction and deletion (정정·삭제요구) — 10 days; suspension of processing (처리정지요구). All requests require appropriate identity verification (본인확인).

Security Measures and 72-Hour Breach Notification

PIPA Article 29 requires personal information handlers to implement technical, managerial, and physical security measures. PIPC publishes detailed Security Measures Standards (고시) specifying minimum requirements by organisation size and volume of data:

  • Access control: Minimum access principle, authentication for system access, access logs retained for at least 3 years
  • Encryption: Mandatory encryption of RRNs, passwords, biometric data, and financial data — both at rest and in transit (TLS 1.2+)
  • Intrusion prevention: Network monitoring, intrusion detection for systems processing large data volumes
  • Physical security: Access controls for areas containing personal information processing systems

2023 Amendment — 72-hour breach notification: The 2023 amendments harmonised breach notification timelines to 72 hours from awareness of a notifiable breach — aligning with GDPR standards. Previously, Information and Communications Service Providers (ICSPs) faced a 24-hour notification requirement to KISA, while other handlers had a 5-day requirement. Now all personal information handlers must notify PIPC within 72 hours. Individual notification to affected data subjects is required for high-risk breaches without undue delay, disclosing the breach circumstances, data affected, likely impact, remediation actions taken, and the complaint contact channel.

Cross-Border Transfer Framework

Cross-border transfer (국외 이전) of personal information requires separate consent from the data subject, with mandatory disclosure of: (1) the foreign country receiving the data, (2) the recipient's name and contact, (3) the transfer purpose, (4) items transferred, (5) retention period, and (6) the data subject's rights including withdrawal. This disclosure-first approach differs from the GDPR mechanism (which relies primarily on adequacy decisions and SCCs).

Alternatives to consent include: adequacy determination (PIPC has recognised a limited number of jurisdictions), contractual safeguards (standard clauses), or binding corporate rules. The 2023 amendments also granted PIPC authority to restrict cross-border transfers to countries posing unacceptable risk to Korean data subjects — a new investigative and enforcement tool.

Personal Information Protection Officer (PIPO)

Every personal information handler must appoint a Personal Information Protection Officer (PIPO / 개인정보 보호책임자) with sufficient authority, independence, and resources. The PIPO must meet qualification criteria set by PIPC regulation — typically a senior management member or a designated privacy professional with relevant expertise. The PIPO is responsible for overseeing PIPA compliance, managing privacy risk, responding to data subject rights requests, and cooperating with PIPC investigations.

2023 Amendment — Local representative requirement: Foreign companies are now required to appoint a local representative (국내대리인) in Korea if they have 1 million or more Korean data subjects or generate annual revenue of KRW 10 billion or more from Korean-based activities. The local representative's contact must be published in Korean and must be capable of responding to PIPC inquiries and data subject requests on behalf of the overseas handler.

PIPC Enforcement and Penalty Regime

The 2023 amendments significantly increased enforcement teeth:

  • Administrative fines: Up to KRW 3 billion or 3% of relevant global annual turnover (whichever is higher) for serious violations — a dramatic increase from the previous KRW 500 million cap
  • Criminal penalties: Up to 10 years imprisonment or fines up to KRW 100 million for illegal cross-border transfers and unauthorised processing of sensitive information
  • RRN collection violations: Fines of up to KRW 50 million for unauthorised collection of Resident Registration Numbers
  • Corrective orders and public disclosure: PIPC can issue binding corrective orders and publicly disclose enforcement actions — reputational consequences that often exceed financial penalties

PIPC enforcement priorities include: RRN protection, security measures and breach response, lawful basis for processing, and consent architecture for marketing communications.

ISMS-P Certification

Korea operates a voluntary but strategically important certification — ISMS-P (정보보호 및 개인정보보호 관리체계 인증) — combining information security management (ISMS) with privacy management (P). Organisations that process significant volumes of personal information or operate public-facing internet services are encouraged (and in some sectors required) to pursue ISMS-P certification. Holding ISMS-P certification demonstrates to PIPC and business partners a robust compliance posture and typically reduces regulatory scrutiny.

Use the South Korea PIPA Compliance Checker

The South Korea PIPA Compliance Checker covers all 42 key obligations across six categories: lawful basis and consent, data subject rights (including new 2023 portability and automated decision-making rights), handler obligations (RRN protection, retention, security measures, processor contracts), breach notification (72-hour PIPC notification), cross-border transfer, and PIPO governance (including local representative for foreign companies). Generate a tailored AI compliance report with a prioritised 90-day remediation roadmap.