South Korea PIPA Amendments: PIPC Finalizes Enforcement Decree, Fine Calculation Overhaul, and CPO Mandates Ahead of September 2026 Effective Date
South Korea is finalizing its regulatory preparation for the September 11, 2026 effective date of its sweeping amendments to the Personal Information Protection Act (PIPA) (Act No. 21445, promulgated March 10, 2026). Throughout mid-2026, the Personal Information Protection Commission (PIPC) has issued critical updates to the PIPA Enforcement Decree, fine calculation standards, and administrative guidelines to shift the compliance landscape toward strict accountability, higher penalties, and expanded individual rights.
1. Sweeping Overhaul of Fine Calculation and Enforcement (May 2026)
On May 18, 2026, the PIPC announced the implementation of amendments to the PIPA Enforcement Decree and the Standards for Imposing Fines, which took effect on May 19, 2026. This update dramatically strengthens the financial impact of data protection violations:
- Revenue Calculation Formula: Previously, fines were calculated based on the average annual revenue of the three business years prior to a violation. Under the new standards, the PIPC will use the higher amount between the revenue of the immediately preceding business year and the three-year average. This ensures that companies experiencing rapid growth cannot benefit from lower historical averages.
- Restricted Leniency: The amended decree restricts fine reductions for severe misconduct, ensuring that sanctions retain their deterrent effect.
2. Chief Privacy Officer (CPO) Board Approval and Breach Notification Mandates (June 2026)
On June 2, 2026, the PIPC announced a draft amendment to the PIPA Enforcement Decree aimed at preventing personal data leaks and strengthening individual rights. Key provisions include:
- Board-Level Accountability for CPOs: The draft establishes strict criteria for organizations that must obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer (CPO). This board-approval mandate applies to:
- Organizations with an annual revenue of at least KRW 180 billion.
- Universities with 20,000 or more students.
- Large general hospitals.
- Operators of public information systems.
- Mandatory ISMS-P Certification: Designated entities must obtain the Personal Information and Information Security Management System (ISMS-P) certification by December 31, 2028.
- 72-Hour Breach Notification: Organizations are required to notify data subjects within 72 hours of discovering unauthorized access or illegal data distribution.
- Calibrated Administrative Fines: The standards introduce warnings for minor violations while escalating penalties for repeat offenses.
3. Expansion of Data Portability and Fine Criteria (June-July 2026)
- Universal Data Portability (June 25, 2026): The PIPC announced measures to support the stable implementation of the right to data portability under the amended PIPA Enforcement Decree. This right has been expanded from healthcare and telecommunications to encompass all fields, including education and employment.
- Administrative Fine Criteria Realignment (July 16, 2026): The PIPC issued a public notice proposing amendments to the Criteria for the Imposition of Administrative Fines for Violations of PIPA. This update aligns administrative fine criteria with the PIPA amendments taking effect on September 11, 2026, reorganizing aggravation and mitigation rules, clarifying fine calculation steps, and resolving practical gaps identified during enforcement.