Personal Information Protection Act of South Korea
South Korea's Personal Information Protection Act (PIPA) is the country's comprehensive framework for protecting personal information and regulating its collection, use, disclosure, storage, transfer, and other forms of processing.
PIPA applies to organizations handling personal information in South Korea and can also apply to certain foreign businesses that provide goods or services to people in Korea, process information in ways that significantly affect Korean data subjects, or maintain a business establishment in Korea.
PIPA establishes requirements around:
Consent is important under PIPA, but it is not required for every processing activity. For example, processing necessary to perform a contract can rely on a statutory basis rather than consent.
South Korea
In force; major amendments effective September 11, 2026
Asia & Africa
PIPA applies to organizations that process personal information in the course of their business.
It can also apply to foreign business operators where, among other circumstances, they:
The Korean Personal Information Protection Commission (PIPC) has specifically published guidance addressing how PIPA applies to foreign businesses.
Foreign businesses may therefore need to assess PIPA even when their headquarters and primary infrastructure are outside Korea.
PIPA provides significant administrative and other sanctions for violations.
The existing penalty-surcharge framework can impose sanctions of up to 3% of relevant revenue for certain violations. Amendments effective September 11, 2026 introduced a stronger punitive mechanism for certain repeated and severe personal information breaches, allowing sanctions of up to 10% of annual turnover in the circumstances specified by the amended law.
Other enforcement measures can include:
The PIPC has demonstrated active enforcement against both Korean and foreign companies, including substantial sanctions involving data breaches and unlawful cross-border transfers.
Organizations subject to PIPA should establish controls for:
PIPA does not require consent for every collection or use of personal information.
Depending on the circumstances, processing may be permitted under statutory grounds including:
The PIPC has specifically emphasized that organizations should not improperly label processing as requiring consent when a statutory basis, such as contractual necessity, applies.
This distinction is important when designing website consent experiences.
Where consent is used as the legal basis, organizations should provide individuals with clear information about the processing and obtain consent in accordance with PIPA's requirements.
Consent interfaces should distinguish relevant processing activities rather than combining unrelated purposes into a single unclear choice.
Organizations should maintain evidence showing:
ConsentX can help maintain this evidence for website-level consent activities.
PIPA contains circumstances in which separate or additional consent is required.
These can include processing involving:
The PIPC has taken enforcement action where businesses failed to obtain or properly communicate consent for cross-border processing.
PIPA provides enhanced protection for sensitive personal information.
This includes information revealing or relating to areas such as:
Processing sensitive personal information is restricted and requires an appropriate legal basis and additional safeguards. Where consent is the applicable basis, separate consent is required.
Organizations should maintain separate controls for:
PIPA provides additional protections for unique identifying information.
Organizations processing information such as certain identification numbers must comply with specific statutory requirements.
Where consent is required, organizations should not assume that a general privacy consent automatically covers the processing of unique identifying information.
Consent and privacy workflows should clearly distinguish this processing where applicable.
PIPA provides additional protections for children under 14 years of age.
Where required, organizations must obtain consent from the child's legal guardian and implement appropriate procedures for verifying and documenting that consent. The PIPC's guidance for foreign businesses specifically identifies guardian consent for children under 14 as an important PIPA obligation.
Organizations serving children should therefore consider:
PIPA provides individuals with important rights concerning their personal information.
Depending on the circumstances, individuals may exercise rights including:
The PIPC provides mechanisms for individuals to request access, correction, deletion, and suspension of processing.
Organizations should maintain documented workflows for:
PIPA requires organizations to establish and disclose an appropriate privacy policy.
The policy should provide understandable information about relevant personal information processing, including matters such as:
The PIPC specifically highlights privacy-policy disclosure as an obligation for foreign businesses subject to PIPA.
Organizations should collect and use personal information only to the extent necessary for legitimate and defined processing purposes.
Businesses should regularly review:
Data that is no longer required should be destroyed in accordance with applicable PIPA requirements.
PIPA requires organizations to implement appropriate safeguards to protect personal information from:
Organizations should establish both technical and organizational controls.
These can include:
The PIPC has increasingly emphasized preventive privacy and security management rather than relying only on post-incident enforcement.
Organizations must respond promptly to qualifying personal information breaches.
Under the current framework, businesses generally must notify the relevant authority and affected data subjects without undue delay and within 72 hours where the applicable notification requirements are triggered. The PIPC has also emphasized the 72-hour requirement for foreign businesses handling Korean data subjects' information.
A breach-response program should include:
The PIPC has imposed significant sanctions where organizations failed to maintain adequate safeguards or delayed breach notifications.
PIPA contains specific requirements for transferring personal information outside South Korea.
Depending on the circumstances and applicable mechanism, organizations may need to:
The PIPC has actively enforced these rules against companies transferring Korean users' information overseas without satisfying the applicable requirements.
Organizations should distinguish between:
An overseas service provider processes personal information on behalf of the organization under the applicable outsourcing/entrustment arrangement.
The recipient independently receives or processes the information in a manner that falls outside ordinary entrusted processing.
The distinction matters because the applicable legal basis, transparency, contractual obligations, and transfer requirements can differ.
The PIPC has specifically emphasized that simply describing every external transfer as "sharing" or "outsourcing" is not sufficient; organizations should correctly characterize the relationship.
Certain foreign businesses subject to PIPA may be required to designate a domestic representative in Korea.
The representative can serve as an important point of contact for privacy-related communications, regulatory matters, and data-subject rights.
Foreign organizations should assess whether their business activities and processing volumes trigger the applicable domestic-representative requirements.
PIPA places significant emphasis on organizational accountability.
Organizations should establish clear responsibility for personal information protection, including the role of the Chief Privacy Officer (CPO) where applicable.
The 2026 amendments further strengthen management accountability and the role of privacy officers, including measures relating to organizations handling large amounts of personal information or sensitive information.
Privacy governance should cover:
Organizations processing personal information in circumstances covered by PIPA's assessment requirements may need to conduct a Personal Information Impact Assessment (PIA).
A PIA can help organizations identify:
Organizations should assess whether their processing activities fall within mandatory PIA requirements.
PIPA is not a dedicated cookie-consent law.
However, cookies, pixels, advertising identifiers, analytics tools, device identifiers, and other tracking technologies can involve personal information or personal-information-related processing depending on how they are used.
Organizations should therefore assess:
For websites, organizations should avoid assuming that every cookie automatically requires consent under PIPA. Instead, the specific processing activity and applicable legal basis should be assessed.
Advertising and analytics ecosystems can create additional PIPA compliance considerations.
Organizations should review:
Where a third party independently processes or uses personal information, the organization should assess whether the arrangement constitutes entrusted processing or third-party provision and identify the applicable legal requirements.
PIPA includes protections concerning automated decision-making.
Organizations using automated systems to make decisions affecting individuals should evaluate applicable transparency, explanation, objection, and other requirements.
This area is particularly relevant for:
Organizations should document how automated processing operates and identify the applicable rights and safeguards.
South Korea's privacy regulator has increasingly developed guidance addressing the use of personal information in AI development and services.
The PIPC has recognized legitimate interests as a potential legal basis for certain AI-related processing of publicly available data where the statutory requirements are satisfied, including purpose legitimacy, necessity, and balancing of interests and data-subject rights.
Organizations using personal information for AI should therefore evaluate:
The PIPA amendment that took effect on September 11, 2026 introduces significant changes to South Korea's privacy enforcement and governance framework.
Key developments include:
The amended framework introduces punitive sanctions of up to 10% of annual turnover for specified repeated and severe data-breach circumstances.
The amendments strengthen the responsibilities of CEOs and Chief Privacy Officers for personal information protection.
The amended framework strengthens the relationship between privacy protection and ISMS-P certification, including additional mechanisms for oversight and prevention.
In August 2026, the National Assembly also passed a further PIPA amendment addressing the lawful use of personal information for AI development in the public interest, together with additional privacy safeguards and PIPC oversight mechanisms. Organizations should monitor the effective date and implementing requirements of this amendment.
Organizations should retain personal information only for as long as necessary for the applicable processing purpose or as otherwise required by law.
Retention programs should establish:
The PIPC has emphasized the importance of destroying personal information once it is no longer necessary to minimize the impact of potential breaches.
Organizations using vendors to process personal information should maintain appropriate oversight.
This includes:
Where an overseas vendor processes Korean personal information, the organization should separately evaluate PIPA's cross-border requirements.
ConsentX can help organizations operationalize website-level privacy and consent controls relevant to PIPA.
Create clearly separated consent choices for processing activities where consent is required.
Configure distinct consent workflows for sensitive personal information where separate consent applies.
Maintain clear consent records for applicable third-party disclosure activities.
Create region-specific consent experiences for international data transfers where PIPA requires additional consent or disclosures.
Prevent configured non-essential cookies and trackers from activating before the applicable consent decision.
Maintain auditable records of user choices, including timestamp, consent context, policy version, and applicable preferences.
Use regional rules to provide appropriate consent and privacy experiences to visitors from South Korea.
Support workflows for managing applicable access, deletion, correction, and processing-suspension requests.
Build a structured privacy and consent workflow for websites serving users in South Korea.
Scan your website, identify trackers and third-party technologies, configure Korea-specific consent rules, block applicable trackers before consent, and maintain auditable consent evidence.
Run a website scan to identify cookies, pixels, trackers, scripts, analytics tools, and third-party technologies.
Identify:
Create separate consent categories for processing activities that require consent under PIPA.
Where sensitive personal information is processed, implement the applicable separate-consent and privacy controls.
Use prior-script blocking to prevent configured non-essential trackers from firing before the required consent decision.
Store consent receipts documenting:
Use the DSAR workflow to manage applicable requests for access, correction, deletion, or suspension of processing.
Identify third-party services and overseas vendors that process Korean personal information and assess the applicable PIPA requirements.
Keep records of consent, preferences, privacy notices, processing changes, and rights requests to support compliance reviews.
This page provides a plain-English overview of South Korea's Personal Information Protection Act for general informational purposes. It is not legal advice.
PIPA obligations can vary depending on the organization's activities, processing methods, data categories, sector, organizational size, cross-border transfers, and other applicable Korean laws and regulations.
PIPA was amended in 2026 and further changes relating to AI and other areas may take effect according to their respective effective dates. Organizations should verify current requirements against the latest legislation, PIPC regulations, guidelines, and enforcement guidance and obtain qualified Korean legal advice where necessary.