What it is
The Personal Information Protection Act (PIPA) is South Korea's general data protection law. It was enacted in 2011 and has been amended several times, most significantly in 2020 (data-economy reforms, a single regulator) and 2023 (rights and enforcement changes). It covers both the private and the public sector in one statute.
Who it applies to
PIPA applies to any "personal information controller": a public institution, legal person, organization or individual that handles personal information for business or other purposes. The people it protects are called "data subjects". Foreign companies that handle the personal information of people in Korea can fall within its scope, and certain overseas businesses must appoint a domestic representative in Korea.
Core principles
The Act requires that personal information be collected lawfully, for a specified and explicit purpose, and only to the minimum extent necessary. Information must be kept accurate and secure, handled in a way that respects the data subject's rights, and, where possible, processed anonymously or in pseudonymized form. Consent is the traditional centre of the regime, and separate, specific consent is required for sensitive information, unique identifiers and certain other uses.
Individual rights
Data subjects have the right to be informed about processing, to access their personal information, to request correction or deletion, to request suspension of processing, and to withdraw consent. Amendments added rights relating to fully automated decisions, including the ability to refuse them or request an explanation, and a right to request that personal information be transmitted to themselves or to another controller (data portability, in particular sectors and conditions set by decree).
Key obligations
Controllers must publish a privacy policy, take technical, managerial and physical safeguards, and designate a privacy officer (Chief Privacy Officer) responsible for compliance. Separate rules apply to pseudonymized information for statistics, scientific research and public-interest archiving, to outsourcing of processing, and to video surveillance devices. Public institutions and some other organizations must carry out privacy impact assessments for systems that pose a higher risk.
Data breaches
When a leak or other breach of personal information occurs, the controller must without delay notify the affected data subjects and, above a threshold set by decree, report to the Personal Information Protection Commission (PIPC) or a designated specialist agency. The implementing rules set a short deadline measured in hours rather than days, and prescribe what the notice must contain.
International transfers
Transferring personal information outside Korea generally requires the data subject's informed consent, or another basis recognised by the Act, such as a transfer that is part of outsourcing or storage with the required disclosures, or transfer to a country or recipient that the PIPC has recognised as providing an equivalent level of protection or certified under a PIPC-approved scheme. Disclosure to the data subject of the recipient, purpose and retention period is a standard element.
Enforcement and penalties
The PIPC is the independent central regulator and can investigate, order corrective measures, publish violations and impose penalty surcharges. Surcharges for the most serious violations can reach a percentage of the controller's relevant total revenue (capped by statute at a low single-digit percentage), in addition to administrative fines for lesser breaches. Certain unlawful acts, such as illegally obtaining or providing personal information, are also criminal offences carrying imprisonment or criminal fines.
The official text
The authoritative version is the Korean-language Act published by the Ministry of Government Legislation. The English text linked here is a reference translation prepared by the Korea Legislation Research Institute (KLRI) and is not legally binding, and translations can lag behind recent amendments. Use the Korean text, not this summary, for anything that matters.
Below is the source we understand to be the official text (English translation (government institute, unofficial); Korean is authoritative). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →