A bill amending the Personal Information Protection Act (PIPA) has moved from committee referral to committee review as of 26 August 2026. As drafted, the bill would amend Article 39(4)(8) and add a new Article 39-2(3) to exclude non-cash compensation — company points, vouchers, or exchange coupons — from the "efforts to remedy harm" factor that courts currently weigh when calculating damages owed to a data subject harmed by a personal-data breach, including statutory damages. The bill has not been enacted; no effective date or penalty amount has been specified.
The stated rationale is that in-kind compensation offered before litigation is sometimes used as a marketing tool to keep affected users tied to a platform rather than as genuine redress, and the bill aims to preserve data subjects' actual right to claim damages by keeping such compensation out of the court's calculation.
This would apply to any 개인정보처리자 (personal information controller) — a category that includes foreign companies processing the personal data of individuals in Korea, regardless of size.
What this means for you
- Do not rely on the bill's current status as settled law. It is at the committee-review stage, not enacted; there is no effective date yet, and the scope could still change before passage.
- Review breach-response and compensation policies now. If your incident-response playbook offers points, coupons, or in-kind credit as part of remediation, understand that — if this bill passes — such offers would not reduce your exposure in a court's damages calculation, including statutory damages claims.
- Track the bill's progress. Watch for committee report, plenary vote, and any changes to the proposed effective date, since none of these have been set yet.
- Distinguish compensation policy from legal defense strategy. Continue any customer-goodwill compensation practices as a business matter, but do not treat them as a substitute for legal damages mitigation once/if this amendment takes effect.
Source: (no link provided in source data)