• Sources: Korea JoongAng Daily report, HN discussion
  • Summary: The revised Personal Information Protection Act took effect 2026-09-11 and was reported on 2026-09-10, raising the cap from 3 percent of sales to 10 percent of total revenue for leaks of 10 million or more records through intent or gross negligence, applied to repeat violators within three years or to companies breached after failing a corrective order. A new potential data breach notification requires notice to affected individuals within 72 hours of determining that exposure is likely, including after illegal access to processing systems, and ransomware damage to data now falls under the same reporting duty. Documented investment in data protection budget, staffing and equipment can reduce a fine by up to 40 percent, early detection with prompt reporting can reduce it by a further 40 percent, and companies above 180 billion won revenue processing 1 million or more people's data need board approval to appoint or dismiss a chief privacy officer.
  • Why it matters: Incident-response timelines change for anyone holding Korean user data, because notice can now fall due before the investigation establishes what was taken.

send feedback on this story