A bill amending the Personal Information Protection Act moved from committee referral to committee review on 26 August 2026. As drafted, it would remove the "intent or negligence" requirement from statutory damages claims (draft Art. 39-2), introduce an enforcement fine (이행강제금) for failure to comply with corrective orders, temporary suspension orders, or public-disclosure orders (new Art. 63-3), let the Personal Information Protection Commission (PIPC) request business suspension from other regulators in serious or repeat cases (Art. 64), and create a new temporary suspension order (임시중지명령) letting the PIPC halt processing on an emergency basis where a clear violation risks irreversible harm to a large number of data subjects (Art. 64-3 etc.). The bill applies to personal information controllers generally — no revenue or user threshold is specified in the draft — and no effective date has been set; it remains at the committee-review stage.
Key points
- Statutory damages get easier to win. Under the draft, a controller is liable unless it proves it took the safeguards required for security, or that the breach was caused by the data subject's own intent or gross negligence and occurred through no fault of the controller. This shifts the practical burden onto the controller.
- Non-compliance with orders now carries a recurring fine. Failing to comply with a corrective order, temporary suspension order, or public-disclosure order would trigger an enforcement fine (이행강제금) under new Art. 63-3, separate from any existing administrative fine.
- New emergency stop power. The PIPC could order an immediate halt to some or all processing (Art. 64-3) where a violation is clear and irreversible harm to many data subjects is imminent; consumer groups could request that the PIPC invoke it.
- Business-suspension referral power. Under revised Art. 64, the PIPC could ask another regulator to suspend a business's operations where a breach recurs despite a corrective order, or where corrective measures alone cannot prevent or remedy the harm.
- The bill is conditional. Its passage is expressly tied to a separate e-commerce consumer-protection bill (Bill No. 18221, sponsored by Rep. Han Chang-min); if that bill fails or is passed in amended form, this bill's provisions would need to be adjusted accordingly.
What this means for you
- Nothing is in force yet. This is a committee-stage bill, not current law — no designation duty, threshold, or effective date has been set. Do not change your compliance posture based on this alone.
- Re-check your security safeguards documentation now. If enacted as drafted, your ability to avoid statutory damages will depend on being able to prove you took the safeguards required for security — not on the claimant proving fault. Make sure your technical/organizational measures are documented in a form that could support that defense.
- Watch for the linked e-commerce bill. Because this bill's fate is tied to Bill No. 18221, track both bills together; the scope or even the survival of these PIPA changes depends on what happens to the e-commerce bill.
- Note there is no threshold carve-out in the current draft. Unlike Korea's domestic-agent regimes, this amendment as drafted would apply to personal information controllers generally, not only to companies above a revenue or user-count line — so smaller foreign operators should not assume they fall outside its reach if it passes.
- Track committee movement. The bill is now in substantive committee review; the next milestones to watch are committee vote, and any amendment to the threshold, penalty amounts, or the conditional link to Bill No. 18221.
Source: