A bill amending the Personal Information Protection Act moved from committee referral to committee review on 2026-08-26. As drafted, it would revise Article 38(4) and add a new Article 63-3 to (1) impose an enforcement fine (이행강제금) on a personal-data controller that refuses the Personal Information Protection Commission's request for data submission, and (2) prohibit designing membership sign-up so that it is simple while making withdrawal or consent revocation comparatively difficult — a practice the bill's drafters describe as procedural deception that obstructs a data subject's exercise of rights. The bill applies to personal-data controllers generally; no revenue or user threshold is specified, and no effective date has been set, as this is still a pending bill rather than enacted law.

What this means for you

  • This is not yet in force. The bill is at the committee-review stage only. No enforcement fine amount, effective date, or final statutory text has been fixed — treat this as a signal to prepare, not an obligation to act on today.
  • Audit your PIPC request-response process now. If the bill passes as drafted, refusing or failing to respond to a PIPC data-submission request could trigger an enforcement fine on top of existing penalties. Confirm you have a workable internal process for responding to such requests.
  • Compare your sign-up flow against your withdrawal/consent-revocation flow. If joining your service is a one-click process while leaving or withdrawing consent requires multiple steps, additional verification, or contact with customer service, that asymmetry is the specific pattern the bill targets. Consider simplifying withdrawal and consent-revocation now, before this becomes a compliance requirement.
  • Track this bill's progress. Committee review can end in passage, amendment, or the bill lapsing — the practical obligations (if any) will depend on the final text and effective date, neither of which exists yet.

Source: