A bill amending Korea's Personal Information Protection Act (PIPA) advanced from committee referral to committee review on 26 August 2026. The bill would affect any personal information controller (개인정보처리자) subject to PIPA, including foreign companies processing Korean users' data, and covers four areas: statutory damages liability, illegal trading of leaked data, data-preservation orders, and a new enforcement-fine (이행강제금) mechanism. It has not been enacted — no effective date has been set — and remains at the committee-review stage.

What the bill would do

  • Reverse the burden of proof for statutory damages (Art. 39-2). Where personal data is lost, stolen, leaked, forged, altered, or damaged, the controller would be liable for damages unless it can affirmatively prove it was not responsible for the incident — shifting the current standard, which the bill's drafters describe as too strict for data subjects to obtain effective redress.
  • Criminalize illegal trading of leaked data (Art. 59, Art. 72). The bill would newly prohibit purchasing, receiving, providing, or distributing personal data that a party knows to be lost, stolen, or leaked, where done for profit or improper purposes without justification, and would impose criminal penalties for this conduct.
  • Introduce data-preservation orders (Art. 63). The Personal Information Protection Commission (PIPC) would gain authority to order a controller to preserve access logs and related records where an investigation into a suspected breach — its occurrence, cause, or remedial measures — is deemed necessary.
  • Introduce enforcement fines for non-compliance (new Art. 63-3, etc.). Where a controller refuses to submit data, obstructs entry/inspection, or fails to comply with a corrective order or a public-disclosure order by the stated deadline, the PIPC would be able to impose an enforcement fine (이행강제금) in addition to existing administrative fines.

What this means for you

  • This is a pending bill, not current law. No effective date has been set, and the bill could still change in committee. Do not treat any of the above as binding yet, but track it — a reversed burden of proof and new criminal exposure for data trading are significant if enacted as drafted.
  • Review your breach-response documentation now. If enacted, you would need to affirmatively prove absence of fault in a breach — meaning your internal incident logs, security controls, and access records need to be strong enough to support that showing, not just to satisfy a lighter burden.
  • Check your data retention and log-preservation capability. The proposed preservation-order power means a PIPC investigation could require you to freeze and hand over access logs on short notice; confirm your systems can do this.
  • Flag any downstream data-sharing or vendor relationships involving previously leaked data. The new criminal provision targets knowing purchase, receipt, or distribution of leaked personal data for profit or improper purpose — relevant if your due diligence on data sources is not already rigorous.
  • Watch for the enforcement-fine provision if you have ongoing PIPC correspondence. A failure to meet a corrective-order or data-submission deadline could newly carry a recurring fine, separate from the existing administrative fine.

Source: