A bill amending Article 66 of Korea's Personal Information Protection Act moved from committee referral to committee review on 26 August 2026. Under current law, the Personal Information Protection Commission (PIPC) has discretion whether to publicize a corrective order, fine, or other sanction issued against a data controller for a violation such as a personal-data breach. The bill would remove that discretion for "significant" violations above a scale still to be defined, requiring the data controller itself to directly disclose the sanction and any remedial measures to affected data subjects, with the content and method of disclosure to be specified.

This is a bill at the committee-review stage, not enacted law. No threshold, effective date, or penalty has been fixed yet — the text as introduced leaves the exact scale ("a certain scale or more") of a qualifying breach to further specification.

What this means for you

  • No action required yet. The bill has not passed and no effective date or threshold has been set. Treat this as a monitoring item, not a current obligation.
  • If you handle Korean user data, watch for the threshold definition. Once a violation-scale threshold is specified, it will determine which breaches trigger the direct-disclosure duty — track this before assuming you fall outside it.
  • Anticipate a shift in breach-response obligations. If enacted, the duty to notify data subjects of a sanction and corrective measures would move from PIPC's discretionary public notice to a mandatory disclosure made directly by your company. Review your breach-notification templates and incident-response workflow now so you are not building this from scratch if the bill passes.
  • Track committee progress. A bill at committee review can stall, be amended, or advance quickly; the threshold, effective date, and any penalty for non-disclosure may all change before passage.

Source: