The Korean authority publishes consultation on the amendment of the implementing decree of the Personal Information Protection Act to improve ISMS-P certification

The Personal Information Protection Commission (PIPC) of South Korea has announced a draft amendment to the implementing decree of the Personal Information Protection Act, aiming to reform the audit process of the Information Security Management System and Personal Information Protection (ISMS-P) certification.

The draft amendment seeks to enhance audit effectiveness by allowing simultaneous document and on-site examinations. In case of a security incident or data breach during the validity of the certification, qualified technical experts will be able to conduct on-site vulnerability assessments, a measure extended to annual follow-up audits. The text also proposes differentiating certification criteria based on the volume of data processed and the social impact of the entity. Finally, it introduces a one-year grace period for companies whose mandatory certification is revoked, suspending fines to allow time to obtain a new certification, except if the revocation is due to fraudulent acquisition.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire