An amendment to the Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 36671) was promulgated on 10 September 2026 and takes effect 11 September 2026, implementing the parent Act amendment (Act No. 21445) that comes into force the same day. It affects any personal information controller subject to Korea's chief privacy officer (CPO) designation duty, and separately, any controller subject to Korea's security-measure and breach-notification obligations. The changes cover CPO reporting timelines, a new duty to notify data subjects of a *possible* breach, revised administrative-fine mitigation criteria, and higher fine amounts.
What changed
- CPO designation reporting deadline (Art. 32(4)). A controller required to designate a CPO must report the designation to the Personal Information Protection Commission (PIPC) within 6 months of the triggering event. An extension of up to 1 year is available for unavoidable business reasons (e.g., management circumstances).
- New "possibility of breach" notice duty (new Arts. 39-2, 39-3). Where there is evidence of illegal access to a personal-information processing system but it is unclear which data subjects' information was affected, the controller must notify affected data subjects in writing (or equivalent) within 72 hours of becoming aware of the illegal access. The notice must cover the categories of personal information potentially exposed and the suspected timing and circumstances. If the controller later confirms no actual leak occurred, it must notify data subjects of that fact as well.
- **Surcharge (*gwajingeum*) mitigation clarified (new Art. 60-2(5), new Annex 1-5). Where a violator's investment in budget, personnel, facilities, or equipment for personal-data protection (and the continuity of that investment) is considered in mitigating a surcharge, the reduction is capped at 40%** of the base surcharge amount.
- **Administrative fines (*gwataeryo*) raised for security-measure violations (Annex 2). For failure to take required security measures, fines rise from KRW 6 million / 12 million / 24 million (1st / 2nd / 3rd-or-more violation) to KRW 9 million / 18 million / 30 million** respectively.
What this means for you
- If you have designated (or must designate) a CPO in Korea, confirm your designation was reported to the PIPC within 6 months of the triggering event, or apply for the up-to-1-year extension if a legitimate business reason applies — do this before assuming the reporting clock has closed.
- Update your incident-response procedures now. The 72-hour clock for the new "possibility of breach" notice starts when you become aware of illegal access, not when you confirm an actual leak. Build a process to issue a preliminary notice within that window even where scope is still unclear, and a follow-up notice if you later confirm no leak occurred.
- Revisit your security-measure compliance posture. The raised fine schedule (up to KRW 30 million for repeat violations) increases the cost of gaps in required safeguards; treat this as a prompt to audit current measures rather than wait for an inspection.
- If you are negotiating a surcharge reduction, document your investment in privacy-related budget, personnel, facilities, and equipment, and its continuity — this is now the specified basis for the capped 40% mitigation.
Source: https://www.law.go.kr/법령/개인정보 보호법 시행령