A bill amending the Personal Information Protection Act (PIPA) moved from committee referral to committee review on 26 August 2026. The bill applies to personal data controllers (개인정보처리자) — including foreign companies subject to PIPA — and would significantly expand both civil liability for data breaches and the Personal Information Protection Commission's (PIPC) investigative and enforcement powers. This is a pending bill, not current law; no effective date has been set.

What the bill would change

  • Statutory damages (Art. 39-2) — Removes the current intent-or-negligence requirement. A controller would be liable for damages whenever personal data it processes is lost, stolen, leaked, forged, altered, or damaged. Liability would be excluded only where the controller both implemented adequate security measures and comprehensively proves it bears no responsibility for the incident — a reversal from the current, more permissive standard.
  • Data-preservation orders (Art. 63) — Where a breach has occurred or is suspected, the PIPC could order a controller to preserve related records (e.g., access logs) to confirm whether an incident occurred, analyze its cause, or prepare countermeasures.
  • Regular pre-emptive compliance checks (Art. 63-2) — The PIPC could conduct scheduled reviews of a controller's privacy practices — based on the type and scale of data handled, sector, and business form — rather than only after an incident, effectively formalizing an ongoing oversight regime for large-scale processors.
  • Enforcement fines / 이행강제금 (new Art. 63-3) — A controller that fails to meet a deadline for required action — refusing to submit data, obstructing entry or inspection, failing to comply with a corrective order, or failing to comply with a public-disclosure order — could face an enforcement fine (이행강제금) until it complies.
  • Emergency cessation orders (Art. 64) — Where a violation is clearly suspected and urgent action is needed to protect data subjects or prevent the spread of harm, the PIPC could immediately order the controller to stop the infringing activity, without the usual process delay.

What this means for you

  • This is a bill under committee review, not enacted law — no threshold, effective date, or final penalty amount has been fixed. Treat this as an early warning, not a compliance deadline.
  • If enacted as drafted, the reversed burden on statutory damages (Art. 39-2) would make it materially harder to avoid liability after a breach — review whether your current security measures and incident documentation would let you meet the "comprehensive proof of no responsibility" standard.
  • Check your incident-response procedures against the proposed data-preservation duty (Art. 63): confirm you can preserve access logs and related records on short notice if the PIPC issues an order.
  • If you are a large-scale processor of Korean personal data, expect the possibility of scheduled compliance checks (Art. 63-2) rather than only reactive investigations, and prepare accordingly.
  • Track this bill's progress through the National Assembly's health and welfare / relevant standing committee, since the scope and final thresholds may shift before passage.

Source: