The Personal Data Protection Act and Its Enforcement Decrees Strengthen Prevention and Punishment of Data Breaches from September 11
The Personal Information Protection Commission (PIPC) of South Korea is implementing, from September 11, amendments to the Personal Information Protection Act and its enforcement decree aimed at strengthening the prevention of data breaches and the protection of data subjects.
Punitive fines, reaching up to 10% of total revenue, are introduced for repeated, intentional, or resulting from gross negligence data breaches, with a reduction mechanism for companies investing in preventive measures. The ultimate responsibility of the executive is explicitly established, and the role of the data protection officer is reinforced, including the management of specialized personnel, obtaining a budget, and a mandatory report to the board of directors. The appointment or dismissal of the officer must be approved by the board and notified to the PIPC.
A notification system is established for cases where a data breach is only possible, and the content of notifications is expanded to include information on dispute resolution procedures. The scope of breaches now includes falsification, alteration, or destruction of data, including by ransomware, subject to the same obligations. Finally, a mandatory certification of the Information Security Management System and Personal Information (ISMS-P) will be imposed on major data controllers from July 1, 2027.
Punitive fines, reaching up to 10% of total revenue, are introduced for repeated, intentional, or resulting from gross negligence data breaches, with a reduction mechanism for companies investing in preventive measures. The ultimate responsibility of the executive is explicitly established, and the role of the data protection officer is reinforced, including the management of specialized personnel, obtaining a budget, and a mandatory report to the board of directors. The appointment or dismissal of the officer must be approved by the board and notified to the PIPC.
A notification system is established for cases where a data breach is only possible, and the content of notifications is expanded to include information on dispute resolution procedures. The scope of breaches now includes falsification, alteration, or destruction of data, including by ransomware, subject to the same obligations. Finally, a mandatory certification of the Information Security Management System and Personal Information (ISMS-P) will be imposed on major data controllers from July 1, 2027.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire