A bill amending the Personal Information Protection Act was introduced on 5 August 2026 by Rep. Park Sun-won and 12 co-sponsors, and has been referred to the competent committee. It would move the physical-security standard for personal-data protection out of the enforcement decree's general language ("storage facilities or lock installation, etc.") and into the statute itself, specifying measures such as physical space separation and entrance lock installation (proposed Article 29 and related provisions). The bill affects personal-information controllers (개인정보처리자) generally; no effective date, threshold, or penalty is specified at this stage — it is a proposal, not current law.
What this means for you
- No action required yet. This is a bill at the committee-referral stage, not an enacted amendment. The technical/administrative/physical-measures duty under the current Personal Information Protection Act remains as-is.
- If your Korean operations hold personal data on-premises, note the direction of travel: the drafters want to move from a general "appropriate physical measures" standard to concrete, named requirements (space separation, locked entry points). If enacted, this would likely tighten what counts as compliant physical security for on-site personal-data storage.
- Watch for committee movement. Track whether the bill advances out of committee, and whether an effective date, threshold, or penalty provision is added or amended before passage — none of those are fixed yet.
- Re-check this bill before any physical-infrastructure decisions (new server rooms, data-center leases, access-control redesigns) that would be costly to retrofit if the specific standards are later written into law.
Source: (no source URL was provided with this alert)