[2026-09-11] Korea’s New Privacy Law Fines Repeat Data Breaches Up to 10% of Revenue

South Korea’s amended Personal Information Protection Act and its enforcement decree took effect on September 11, 2026. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) The Personal Information Protection Commission (PIPC) announced the day before, on September 10, that businesses causing repeated or grossly negligent large-scale data breaches can now face punitive fines of up to 10% of total revenue. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) The special penalty applies when a company intentionally or negligently repeats a violation within three years, causes a breach affecting 10 million or more people, or fails to comply with a corrective order that leads to a recurring breach. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10)

개인정보 유출 과징금 상한 비교
한국 개정 개인정보 보호법 vs EU GDPR 제83조 과징금 상한 비교

How the 10% cap compares to GDPR

Korea’s new 10%-of-revenue ceiling is notably higher than the European Union’s benchmark. Under Article 83 of the GDPR, the most serious infringements — such as violations of consent requirements or data subjects’ rights — carry fines of up to €20 million or 4% of a company’s total worldwide annual turnover, whichever is higher. (Source: https://gdpr-info.eu/art-83-gdpr/, GDPR Article 83) On paper, Korea’s cap is more than double the GDPR’s percentage-based ceiling. However, the PIPC’s September 10 briefing did not specify whether the revenue base for Korea’s 10% cap is domestic revenue only or worldwide revenue, unlike GDPR’s explicit “worldwide annual turnover” language — a distinction that will likely only become clear once the first cases are enforced.

The fine also comes with mitigation provisions: companies that proactively invested in data protection can receive up to a 40% reduction off the base penalty amount, with an additional discretionary reduction of up to 50% based on the nature, scale, and impact of the violation. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) The PIPC’s briefing did not specify the exact formula for combining these two reductions, so the real-world discount in any given case will depend on how enforcement plays out. Small and medium-sized businesses can have fines waived entirely for minor violations corrected with technical assistance. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10)

Board approval now required for CPO appointments

The amendment also strengthens the authority and independence of Chief Privacy Officers (CPOs). Companies subject to the reporting requirement must now obtain board approval when appointing, changing, or dismissing a CPO after the law’s effective date, and must report the appointment to the PIPC within six months. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) CPOs already in place before the law took effect do not need retroactive board approval but must still be reported within six months of the effective date. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) The PIPC will run a grace period through December 31, 2027, to ease the compliance burden of the new CPO system, though the underlying obligation remains in force during that window. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10)

72-hour notice for suspected breaches

A third change introduces a “potential breach notification” requirement: companies must notify affected individuals within 72 hours of recognizing a reasonable, objective likelihood of a breach — even before the breach is finally confirmed. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) The threshold requires concrete circumstantial evidence, such as unauthorized system access or illegal trading of personal data; merely discovering a security vulnerability does not trigger the notification duty on its own. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10)

Why this matters for foreign companies

Foreign technology and platform companies operating in Korea, or handling Korean users’ personal data from abroad, face direct exposure to this revised penalty structure. Multinational firms already complying with GDPR’s 4% cap will need to separately assess Korea’s 10% cap and its distinct triggering conditions, since the two regimes are not identical in scope or calculation base. Companies that already built GDPR-compliant breach-notification workflows have a head start on Korea’s 72-hour potential-breach notice, but will need to extend those processes to cover the “reasonable likelihood” threshold, which is broader than GDPR’s requirement to notify only upon a confirmed breach.

Industry impact

Large platform operators and enterprises handling mass consumer data face the most direct cost pressure, since the 10%-of-revenue fine risk is now real and specific. Companies are likely to reclassify security investment from a cost center to risk-management budgeting, given that pre-incident investment directly determines eligibility for the 40% mitigation discount. Smaller businesses, by contrast, gain a new path to full fine waivers through technical assistance programs, meaning the practical burden diverges sharply by company size. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10)

Consumer impact

For ordinary users, the most tangible change is the 72-hour potential-breach notice. Previously, notification came only after a breach was conclusively confirmed; now, users can be alerted within 72 hours of a reasonably suspected breach, giving them more time to change passwords or freeze payment cards. (Source: https://www.korea.kr/news/policyNewsView.do?newsId=148971656, 2026-09-10) The tradeoff is that earlier notification thresholds could also produce more notices for incidents that ultimately turn out not to be breaches, so users should treat such alerts as a prompt for precaution rather than confirmed harm.

Source: Korea Policy Briefing, 2026-09-10 · Reference: GDPR Article 83

Related: [2026-09-09] Fitch, Moody’s Both Praise Korea’s 2027 Budget | [2026-09-06] Four U.S. Firms Pledge $2B in Korea | [2026-09-04] Korea Raises SME Export Target to $180B by 2030

Leave a Comment