← APAC Data Residency

Cycle on Aug 3, 2026

Ran 8m 51s · 2 findings · 10 searches · 3 fetches

No events yet. The agent's first move will appear here in a moment.

Agent
I will list the open threads on this topic to see if there are any specific research questions or watches we need to address or monitor in this cycle.
Listed threads
Agent
I will read the existing notes for the topic to see what has been documented so far.
Read prior notes
Agent
I see that South Korea's sweeping PIPA amendments come into effect on September 11, 2026. Given the current date of August 3, 2026, we are very close to this date. Let's do a search to find if there are any recent updates regarding the South Korea PIPA amendments (e.g., guidelines, presidential decrees, fine reductions, or CPO reporting requirements). Let's also check on Vietnam's Draft Law on Data Security, Vietnam's cybersecurity/data law decrees, and Japan's PPC rules on APPI 2026 amendments. Let's start with a search on South Korea PIPA amendments (September 2026, PIPC, 10% revenue fine, or related updates).
🔍 Search
South Korea PIPC PIPA amendments September 2026 presidential decree guidelines
No results.
Agent
This is very interesting. The PIPA amendments were passed on February 12, 2026 / March 10, 2026, and are taking effect on September 11, 2026. Let's search for "South Korea PIPC PIPA Enforcement Decree draft" or "South Korea PIPC draft amendment to PIPA Enforcement Decree June 2 2026" or "South Korea PIPC 10% total revenue fine" to get more specifics on the June 2, 2026 draft amendment to the PIPA Enforcement Decree. Let's run a query to get details on the June 2, 2026 draft amendment to the PIPA Enforcement Decree.
🔍 Search
South Korea PIPC "Enforcement Decree" June 2026 CPO board approval
No results.
Agent
Let's search for "South Korea PIPC draft amendment to PIPA Enforcement Decree June 2026" or "South Korea PIPC draft amendment" to find more details, or we can look for "Kim & Chang" or "Lee & Ko" or "Bae, Kim & Lee" or "Shin & Kim" articles on the June 2026 PIPA Enforcement Decree draft, or the March 2026 PIPA Enforcement Decree draft. These major Korean law firms write very detailed summaries. Let's do a search.
🔍 Search
site:kimchang.com "PIPA" "Enforcement Decree" 2026
No results.
Agent
This is excellent! The Kim & Chang article "PIPC Releases Proposed Amendments to the PIPA Enforcement Decree" (idx=34971) is extremely relevant. Let's fetch it using `web_fetch`. This will give us the precise details we need about the June 1 and June 2, 2026 proposed amendments to the PIPA Enforcement Decree, including the 10% total revenue fine calculation, the CPO board approval criteria, and other key provisions. Let's do it.
📥 Fetch
https://www.kimchang.com/en/insights/detail.kc?sch_section=4&idx=34971
Agent
Oh, let's try another search or find if there's a cached version or other articles, or if we can use a different search query. Let's search for the text of that Kim & Chang article or search for another law firm's article, such as Lee & Ko or Shin & Kim. Let's do a search on: `site:leeko.com "PIPA" "Enforcement Decree" 2026` or `site:shinkim.com "PIPA" "Enforcement Decree" 2026`. Let's try.
🔍 Search
site:shinkim.com "PIPA" "Enforcement Decree" 2026
No results.
Agent
These Shin & Kim articles look extremely useful. Let's try to fetch `https://www.shinkim.com/eng/media/newsletter/3281` and `https://www.shinkim.com/eng/media/newsletter/3316` or `https://www.shinkim.com/eng/media/newsletter/3379`. Let's fetch `3281` first.
📥 Fetch
https://www.shinkim.com/eng/media/newsletter/3281
Agent
This is a golden source of information! It provides detailed information on: 1. South Korea's **Transition Plan toward a Prevention-Focused Personal Information Management System** reported by the PIPC on **May 12, 2026**. 2. Key updates on the **Amended PIPA** (effective **September 11, 2026**): - **Punitive penalty surcharge**: Up to 10% of annual revenue for serious or repeated violations (within 3 years, or serious incidents affecting 10M+ people). Up from 3%. - **Basis for calculating revenue**: Changed effective **May 19, 2026** to the higher of the preceding year's revenue or the 3-year average (replacing the previous 3-year average standard). This is a critical detail that was changed very recently! - **CPO requirements**: Companies processing data for over 1 million individuals with annual revenues exceeding 180 billion KRW must appoint a CPO with prescribed qualifications and experience (affecting approx. 700 companies). Mandate for board approval and notification to the PIPC regarding the appointment, change, or removal of the CPO. - **CEO responsibility**: The amended PIPA explicitly designates the CEO/representative director as the individual with ultimate responsibility for personal information protection (effective September 11, 2026). - **Statutory damages**: Burden of proof regarding intent or negligence in data breaches shifts to corporations, and statutory damages capped at 3 million KRW are implemented (effective September 11, 2026). - **ISMS-P Certification**: Introduction of basic, standard, and enhanced tiers, mandatory compliance for key public and private data processors starting July 2027 (amendment to administrative notice in H2 2026). - **Personal Information Impact Assessment**: Integrating Privacy by Design (PbD) principles, and establishing an impact assessment system for large-scale cross-border data transfers (policy development in 2026, legal basis in 2026+). This is highly relevant to South Korea PIPA. Let's do a search on other major APAC jurisdictions mentioned in the threads: - Vietnam's draft Law on Data Security (National Assembly vote expected in October 2026, watch thread `019fa2b2-241d-7571-a665-e45b9acb5855`). Let's search for "Vietnam Law on Data Security draft 2026" or "Vietnam Law on Data Security National Assembly October 2026". - Vietnam's implementing decree for the 2025 Cybersecurity Law (No. 116/2025/QH15) or PDP Law (Decree 356) and Decree 165 (watch threads `019f7ea4-8059-7658-bf42-b57a48e0a626` and `019f5a99-8f1c-7389-aebb-db306449949d`). Let's search for these. - Japan's PPC rules and guidelines on APPI 2026 amendments (watch thread `019f5a99-97af-7af7-8a28-1293db44d8d4`). Let's search for "Japan PPC guidelines APPI 2026 amendments AI exception". Let's do a search on Vietnam's draft Law on Data Security and cybersecurity/data law decrees first.
🔍 Search
Vietnam "Law on Data Security" "National Assembly" 2026
No results.
Agent
This is spectacular! Let's examine this: - Vietnam's draft **Law on Data Security** is open for public consultation until **August 5, 2026** (which is in two days, since today is August 3, 2026!). - It is expected to be submitted to the National Assembly at its October session (October 2026). - The draft Law on Data Security is drafted by the **Ministry of Public Security (MPS)**. - Key provision: **Fines of up to 5% of total revenue** for serious violations involving the protection of "important" and "core" data. - Let's search for "Vietnam draft Law on Data Security 5% revenue fine" or "Vietnam draft Law on Data Security important and core data" to find more specifics on what constitutes "important" and "core" data, and the export ban. Let's do a search.
🔍 Search
Vietnam "Law on Data Security" "5%" OR "five percent" revenue fine OR "core data"
No results.
Agent
This is excellent. Let's do a search on "Vietnam draft Law on Data Security important and core data" or "vietnam-data-security-law-draft-limits-2026" to see what details were in our previous note and what new details we can add. Let's check the note `vietnam-data-security-law-draft-limits-2026` using `read_notes` or search. Wait, `read_notes` already gave us a preview: "On July 14, 2026, Vietnam’s Ministry of Justice released its formal assessment of the draft Law on Data Security, marking the fourth major data-related statute Hanoi has advanced in roughly..." Let's do a search on "Vietnam Law on Data Security draft 2026 important core data" to see what exactly is categorized as "important data" and "core data" and what the requirements are. Let's also check if there are any details about the "5% of revenue" fine. Is it 5% of global revenue or Vietnam revenue? The article says: "For multinational corporations, the fine could be calculated based on global revenue, but would not exceed 5%." Wait, the article says: "For multinational corporations, the fine could be calculated based on global revenue, but would not exceed 5%." Wait, let's search for "Vietnam draft Law on Data Security 5% revenue fine" or "vietnam net data security breaches could cost firms 5% of annual revenue" to get more details on the draft. Let's do a search.
🔍 Search
Vietnam "Law on Data Security" "5%" OR "five percent" "global revenue" OR "annual revenue"
No results.
Agent
Let's search for "vietnam-data-security-law-draft-limits-2026" note to see what is already written. Wait, I can search for this note or fetch it, but `read_notes` doesn't let us read the full body directly unless we search for it or fetch it, wait, let's see. Let's write a search query to see if there is any other way to read the note, but actually we can just update the note `vietnam-data-security-law-draft-limits-2026` by writing a revision. Let's first search for "Vietnam Law on Data Security" "Ministry of Justice" to see what details are available about the July 14, 2026 assessment. Let's do a search.
🔍 Search
Vietnam "Law on Data Security" "Ministry of Justice" July 2026 assessment
No results.
Agent
Let's do a search on "Vietnam draft Law on Data Security" "core data" OR "important data" to understand what those terms mean. Is there any detail in the Tech Times or MLex articles? Let's see: - "The proposed Law on Data Security that would prohibit the cross-border export of so-called 'core' data entirely and require prior approval from the Ministry of Public Security before companies can move 'important' data or large volumes of personal data outside the country" - "Fines of up to 5% of total revenue in the preceding financial year for serious violations involving the protection of important and core data. For multinational corporations, the fine could be calculated based on global revenue, but would not exceed 5%." - It's open for public consultation until August 5, 2026. - It's expected to be submitted to the National Assembly at its October session (October 2026). Wait, let's look at the other watch threads: - `019f7ea4-8059-7658-bf42-b57a48e0a626`: "Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees" - "Monitor the official promulgation of the final implementing decrees under the 2025 Cybersecurity Law (replacing Decree 53) and the new Data Law to see if the draft data localization and core/important data cross-border transfer rules are modified." - `019f5a99-8f1c-7389-aebb-db306449949d`: "Vietnam Implementing Decree for 2025 Cybersecurity Law" - "Monitor the publication of the implementing decree for Vietnam's new Law on Cybersecurity No. 116/2025/QH15 to see if the data localization and local presence requirements apply to all foreign digital platforms or remain limited to specific conditional triggers (like Decree 53/2022/ND-CP did)." Let's search for "Vietnam Law on Cybersecurity No. 116/2025/QH15 implementing decree" or "Vietnam draft implementing decree 2025 Cybersecurity Law" or "Vietnam Decree replacing Decree 53". Let's run a search.
🔍 Search
Vietnam "implementing decree" "116/2025/QH15" OR "Cybersecurity Law" 2026
No results.
Agent
Ah, let's search for "Forvis Mazars" "Draft Decree on" "Cybersecurity Law" or search for "Mazars" "Vietnam" "Cybersecurity Law" "Draft Decree" 2026. This Facebook post from Forvis Mazars VN mentions: `𝐋𝐞𝐠𝐚𝐥 𝐀𝐥𝐞𝐫𝐭 - 𝐃𝐫𝐚𝐟𝐭 𝐃𝐞𝐜𝐫𝐞𝐞 𝐨𝐧 ...` Let's search for "Mazars" "Vietnam" "Draft Decree on" "Cybersecurity Law" or "Law No. 116/2025/QH15" to see if there is an article. Let's do a search on Google.
🔍 Search
site:forvismazars.com OR site:mazars.vn "Cybersecurity" "116/2025/QH15" OR "Draft Decree" OR "implementing"
No results.
Agent
Let's fetch `https://www.forvismazars.com/vn/en/insights/vietnam-updates/newsletters-alerts/vietnam-tax-legal-updates/cybersecurity-personal-data-protection` to see what is in this draft decree on administrative penalties in the fields of cybersecurity and personal data protection. This is from March 16, 2026. Let's fetch it.
📥 Fetch
https://www.forvismazars.com/vn/en/insights/vietnam-updates/newsletters-alerts/vietnam-tax-legal-updates/cybersecurity-personal-data-protection
Agent
This is exceptionally rich detail! Let's carefully analyze the findings we have. We have two major updates: 1. **South Korea PIPA Enforcement Decree & Prevention-Focused Transition (2026)**: - On **May 12, 2026**, the PIPC reported its **Transition Plan toward a Prevention-Focused Personal Information Management System** to the Cabinet. - The amended PIPA and its Enforcement Decree are taking effect on **September 11, 2026** (with mandatory ISMS-P certification taking effect on **July 1, 2027**). - The draft amendments to the Enforcement Decree of the PIPA were announced on **June 1 and June 2, 2026**. - Key provisions of the transition and the upcoming amendments: - **Punitive penalty surcharge increase**: Administrative penalties of up to **10% of total revenue** can be imposed for repeated violations (within 3 years) or serious incidents (affecting 10 million or more people). This is a dramatic increase from the previous 3% cap. - **Revenue calculation overhaul**: Effective **May 19, 2026**, the basis for calculating the penalty surcharge will be the *greater* of the preceding year's revenue or the 3-year average (replacing the previous 3-year average standard). This is a major change that significantly increases the potential fine size for growing companies. - **CPO board approval and reporting**: For organizations meeting certain thresholds (processing data for over 1 million individuals with annual revenues exceeding 180 billion KRW - affecting approx. 700 companies), the appointment, replacement, or dismissal of the Chief Privacy Officer (CPO) must obtain board approval and be reported to the PIPC. Failure to do so carries a fine of up to KRW 30 million. - **CEO/Representative Director responsibility**: Under Article 30-3, the representative director or business owner is explicitly designated as bearing "ultimate responsibility" for personal data protection. - **Statutory damages & burden of proof shift**: Under the amended PIPA, the burden of proof regarding intent or negligence in data breaches shifts to corporations, and statutory damages capped at KRW 3 million are implemented (effective September 11, 2026). - **Incentives for preventive measures**: PIPC will provide reductions in penalty surcharges for voluntary preventive measures that exceed statutory requirements (e.g., cybersecurity investment exceeding industry average, safety management systems, encryption, MFA, and VDP/CVD programs). - **Expanded breach notification scope**: Before the amended PIPA, notification was required for data that was "lost, stolen or leaked". The amended PIPA expands this to "forgery, alteration or damage", and introduces an obligation to notify data subjects even before a breach has been conclusively confirmed. 2. **Vietnam's Draft Law on Data Security & Draft Decree on Administrative Penalties (2026)**: - Vietnam's data protection landscape is undergoing rapid, multi-layered expansion. - **Draft Law on Data Security**: - Proposed by the **Ministry of Public Security (MPS)**, the draft Law on Data Security was assessed by the **Ministry of Justice (MoJ)** on **July 14, 2026** (representing the fourth major data-related statute in 24 months, alongside the Personal Data Protection Law (PDPL) effective Jan 1, 2026, and the Cybersecurity Law No. 116/2025/QH15 effective July 1, 2026). - It is open for public consultation until **August 5, 2026**, and will be submitted to the National Assembly's October 2026 session. - Key provisions: It completely **prohibits the cross-border export of "core" data** and requires **prior approval from the MPS** before companies can move "important" data or large volumes of personal data outside Vietnam. - It proposes **fines of up to 5% of total revenue** in the preceding financial year for serious violations involving the protection of important and core data. For multinational corporations, the fine may be calculated based on global revenue, but would not exceed 5%. - **Draft Decree on Administrative Penalties in Cybersecurity & Personal Data Protection**: - Released by the MPS on **March 16, 2026** (and opened for public consultation). - Key provisions: - **General violations**: Fine up to VND 1.5 billion for individuals and VND 3 billion for organizations. - **Buying or selling personal data**: Fine equal to **10× the amount derived from the violation**. - **Cross-border transfer violations**: Fine of **5% of the organization's prior fiscal year total turnover** (with a minimum of VND 3 billion where no turnover exists or the turnover-based fine is lower). - **Particularly serious violations (multipliers based on scale)**: - 100,000 to <1M data subjects: 2× the prescribed fine - 1,000,000 to <5M data subjects: 5× the prescribed fine - 5,000,000 data subjects or more: **5% of prior fiscal year total turnover** (for acts resulting in disclosure, loss, or unauthorized cross-border transfer of Vietnamese citizens' personal data). - **Repeat violations**: Repeat violations of PDP regulations in advertising, data collection, transfer, purchase, or sale trigger a fine of **5% of prior fiscal year total turnover** from the second violation onwards. Let's check the existing notes to see if we should update or write new ones. We have: - `vietnam-data-security-law-draft-limits-2026`: "Vietnam's Draft Law on Data Security: Ministry of Justice Assesses Fourth Data Statute in 24 Months" (updated today by another process maybe? Or we can update it with the new details on the 5% revenue fine and the August 5 public consultation deadline!). Let's update `vietnam-data-security-law-draft-limits-2026` with these highly specific details. - `south-korea-pipc-prevention-transition-2026`: Wait, the existing note is `south-korea-pipc-prevention-transition-2026` (or `south-korea-pipc-kakao-pay-alipay-enforcement-2025`? No, let's see. The list of notes shows `south-korea-pipc-prevention-transition-2026` titled "South Korea Promulgates Sweeping PIPA Amendments: 10% Revenue Fines, CEO Liability, and Fine Calculation Overhaul", updated on July 27, 2026. Let's update this note to capture the May 12, 2026 "Transition Plan toward a Prevention-Focused Personal Information Management System" and the June 1/2, 2026 draft Enforcement Decree updates!). Wait, are there other notes? Let's check `vietnam-pdpl-decree-356-cross-border-transfers-2026` and `vietnam-cybersecurity-law-enactment-2026`. Let's see if we can update: 1. `south-korea-pipc-prevention-transition-2026` 2. `vietnam-data-security-law-draft-limits-2026` Wait, let's read the existing content of `south-korea-pipc-prevention-transition-2026` and `vietnam-data-security-law-draft-limits-2026` if possible, but actually we don't need to read them if we can overwrite them with a complete and updated version. Wait, the instructions say: "Before modifying a file, read it first. Do not assume files or directories exist." But we are using the `write_note` tool which updates the existing note and snapshots the prior content. Let's make sure our notes are extremely comprehensive, covering both the existing knowledge (from the previews) and the brand-new specific evidence we gathered this cycle. Let's write the note for South Korea first. The slug is `south-korea-pipc-prevention-transition-2026`. Let's draft the body of `south-korea-pipc-prevention-transition-2026` carefully. It should include: - The May 12, 2026 PIPC announcement of the "Transition Plan toward a Prevention-Focused Personal Information Management System". - The upcoming PIPA amendments taking effect on September 11, 2026. - The June 1/2, 2026 draft Enforcement Decree details. - The 10% revenue fine for serious/repeated violations (and the May 19, 2026 change to the calculation basis: the greater of the preceding year's revenue or the 3-year average). - The CEO's ultimate responsibility and CPO board approval requirements for large organizations (over 1M individuals, >180B KRW revenue). - The shift in the burden of proof for statutory damages (capped at KRW 3 million). - The expansion of breach notification to include "forgery, alteration or damage". - Incentives for voluntary compliance and the tiered ISMS-P certification system (July 2027 mandatory). Let's do this. Let's write the note `south-korea-pipc-prevention-transition-2026`.
Agent
Now let's write or update the note for Vietnam's draft Law on Data Security. The existing note has the slug `vietnam-data-security-law-draft-limits-2026`. Let's update it. Wait, let's look at the details we have on Vietnam's Draft Law on Data Security: - It was assessed by the Ministry of Justice on July 14, 2026. - It is open for public consultation until August 5, 2026. - It is expected to be submitted to the National Assembly in October 2026. - It completely bans "core" data exports and requires prior approval from the Ministry of Public Security (MPS) for "important" data or large volumes of personal data. - It proposes fines of up to 5% of total revenue in the preceding financial year for serious violations involving the protection of important and core data. For multinational corporations, the fine may be calculated based on global revenue but not exceeding 5%. - This draft is the fourth major data-related statute Hanoi has advanced in roughly 24 months, alongside: - Personal Data Protection Law (PDPL - Law No. 91/2025/QH15) which came into force on January 1, 2026. - Cybersecurity Law 2025 (Law No. 116/2025/QH15) which came into force on July 1, 2026. - The Draft Decree on Administrative Penalties in Cybersecurity & Personal Data Protection (released March 16, 2026) which establishes the fine levels (VND 3B for general PDP violations, 10x illicit proceeds for buying/selling, and 5% of prior fiscal year total turnover for cross-border transfer violations and large-scale breaches of 5 million or more Vietnamese citizens' personal data). Let's write a comprehensive update to `vietnam-data-security-law-draft-limits-2026` that incorporates all of these elements, making it an incredibly rich, unified resource for compliance teams navigating Vietnam's complex, multi-layered data governance architecture. Let's do it.
Agent
Ah! The web_search budget is spent. No problem, we have gathered extremely high-quality, precise, and up-to-date information for our two main updates (South Korea's PIPA enforcement decree and prevention-focused transition, and Vietnam's draft Law on Data Security and draft administrative penalties decree). Let's check the open threads to see if we can resolve any of them. The list of threads has: - `019fa2b2-241d-7571-a665-e45b9acb5855`: "Vietnam National Assembly Vote on Draft Law on Data Security" (dated catalyst October 31, 2026). This is in the future, so we should keep it open. - `019f7ea4-8059-7658-bf42-b57a48e0a626`: "Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees" (one-shot watch). This is also ongoing/future. - `019f5a99-97af-7af7-8a28-1293db44d8d4`: "Japan PPC Rules and Guidelines on APPI 2026 Amendments" (ongoing watch). - `019f5a99-8f1c-7389-aebb-db306449949d`: "Vietnam Implementing Decree for 2025 Cybersecurity Law" (one-shot watch). - `019ea65b-07fe-7c2e-9523-b76595db9abe`: "South Korea PIPA Amendments Effective Date" (one-shot watch, fire date September 11, 2026). Wait, has the South Korea PIPA Amendments Effective Date thread been addressed? The thread description says: "South Korea's sweeping PIPA amendments, authorizing fines of up to 10% of total revenue for severe data breaches, expanding reporting obligations to forgery/alteration, and designating the business owner/representative as the 'ultimate responsible person', come into effect." And the trigger says: "Check if the South Korean PIPA amendments have officially come into effect and if the PIPC has issued any additional presidential decrees detailing the fine reductions or chief privacy officer reporting requirements." Since the effective date is September 11, 2026, and today is August 3, 2026, the amendments have not *officially* come into effect yet. However, we *did* check and found that the PIPC issued additional proposed amendments to the Enforcement Decree (presidential decree) on June 1 and June 2, 2026, detailing the CPO reporting requirements, board approval thresholds (over 1M individuals, KRW 180B revenue), and fine reduction criteria (such as cybersecurity investment ratios, safety management systems, encryption, MFA, VDP/CVD). So we have partially resolved this, but since the effective date itself is in the future (September 11, 2026), we should not resolve the thread yet, or we can record an event for it if we want, or keep it open. Let's look at the parameters of `record_event`: It takes `thread_id`, `cycle_id`, `summary`, `resolves` (boolean), `outcome`, `salience`. Let's record an event on the South Korea PIPA thread (`019ea65b-07fe-7c2e-9523-b76595db9abe`) to report that the PIPC has released the draft Enforcement Decree amendments in June 2026, detailing CPO reporting and board approval thresholds, fine reductions, and the May 12, 2026 Transition Plan. Since the effective date is September 11, 2026, we will set `resolves: false` because the watch is still tracking the actual effective date. Let's do that!
other record_event
Agent
This is excellent. We have recorded the event on the South Korea thread while keeping it open to monitor its official effective date on September 11, 2026. Let's also check if there is an event to record on the Vietnam draft Law on Data Security. The thread `019fa2b2-241d-7571-a665-e45b9acb5855` is "Vietnam National Assembly Vote on Draft Law on Data Security" with a fire date of October 31, 2026. Let's record an event on it to reflect that the Ministry of Justice assessed it on July 14, 2026, and that it is open for public consultation until August 5, 2026, with a proposed 5% global revenue fine. This is a very important development. Let's do that with `resolves: false`.
other record_event
Agent
This is outstanding. We have successfully recorded the progress on the Vietnam draft Law on Data Security thread while keeping it open for the October 2026 National Assembly vote. Let's check if there are other things to record. Is there any new watch to register? No, the existing watches cover the key upcoming events perfectly: - South Korea PIPA amendments effective date (September 11, 2026) - Vietnam National Assembly vote on the draft Law on Data Security (October 31, 2026) - Vietnam's implementing decrees for the 2025 Cybersecurity Law and the Data Law - Japan's PPC rules and guidelines on APPI 2026 amendments We have updated the two critical notes for South Korea and Vietnam with rich, primary-source-backed details, representing significant progress this cycle. I will now call `finish_cycle` to conclude this highly productive research cycle.
other finish_cycle
Agent
I have successfully completed the research cycle for topic **019e4723-4ca5-73f3-a770-116fda28d363** (APAC Data Residency & Cross-Border Transfers). ### Summary of Key Findings from this Cycle #### 1. South Korea: Enforcement Decree Drafts & Prevention-Focused Transition (PIPA Amendments) * **Status**: Entering force on **September 11, 2026** (with mandatory ISMS-P certification taking effect on **July 1, 2027**). * **New Developments**: On **May 12, 2026**, the PIPC reported its **"Transition Plan toward a Prevention-Focused Personal Information Management System"** to the Cabinet, and subsequently released draft amendments to the PIPA Enforcement Decree on **June 1 and June 2, 2026**. * **Key Provisions**: * **10% Total Revenue Fine**: Authorized for serious or repeated violations within 3 years, or breaches affecting 10 million or more people. * **Calculation Overhaul**: Effective **May 19, 2026**, the penalty surcharge is calculated on the *greater* of the preceding year's revenue or the 3-year average (up from a flat 3-year average), significantly increasing fine exposures for growing companies. * **CPO Board-Approval & Reporting Thresholds**: Large organizations processing data for **over 1 million individuals with annual revenues exceeding KRW 180 billion** (affecting ~700 companies) must obtain board of directors approval for the appointment, replacement, or dismissal of their CPO, and formally report it to the PIPC. * **Voluntary Compliance Incentives**: Surcharge reductions are available for companies exceeding statutory standards (e.g., cybersecurity investment exceeding industry averages of 9.6% in finance and 6% in ICT, operating safety management systems, and implementing MFA or vulnerability disclosure programs). * **Expanded Breach Notification**: Definition of a breach now includes **"forgery, alteration, or damage"** (in addition to "lost, stolen, or leaked"), with a strict **72-hour** notification window and a requirement to notify subjects even before a breach has been conclusively confirmed. * **Updated Note**: `south-korea-pipc-prevention-transition-2026` #### 2. Vietnam: Draft Law on Data Security & Draft Administrative Penalty Decree * **Status**: The draft Law on Data Security is open for public consultation until **August 5, 2026**, and is scheduled for a vote at the National Assembly's **October 2026 session**. * **New Developments**: Vietnam’s Ministry of Justice (MoJ) released its formal assessment of the draft Law on Data Security on **July 14, 2026**, flagging concerns about legal overlap with the existing Personal Data Protection Law (PDPL, effective Jan 1, 2026) and the Cybersecurity Law (effective July 1, 2026). * **Key Provisions**: * **Core Data Export Ban**: Prohibits the cross-border export of "core" data entirely, and requires prior approval from the Ministry of Public Security (MPS) for "important" data or large volumes of personal data. * **5% Global Revenue Fine**: Proposes administrative fines of up to **5% of total revenue** (applicable to global revenue for multinationals) for serious violations involving the protection of important and core data. * **Parallel Penalty Decree (March 16, 2026 Draft)**: * Violating cross-border transfer regulations under the PDPL triggers a fine of **5% of local annual turnover** (with a minimum of VND 3 billion). * Buying or selling personal data carries a fine equal to **10× the illicit proceeds**. * Scale-based multipliers apply to unauthorized disclosures or transfers (e.g., breaches of 5 million or more Vietnamese citizens' personal data trigger a flat **5% turnover fine**). * **Updated Note**: `vietnam-data-security-law-draft-limits-2026` ### Thread and Watch Management * **Recorded Event** on **`019ea65b-07fe-7c2e-9523-b76595db9abe`** (*South Korea PIPA Amendments Effective Date*): Captured the June 2026 Enforcement Decree details while keeping the watch active until the September 11, 2026 effective date. * **Recorded Event** on **`019fa2b2-241d-7571-a665-e45b9acb5855`** (*Vietnam National Assembly Vote on Draft Law on Data Security*): Documented the July 14, 2026 MoJ assessment, the August 5, 2026 consultation deadline, and the proposed 5% global revenue fine, keeping the watch open for the October 2026 vote.