The Personal Information Protection Commission (PIPC) has amended its administrative rule on calculating fines (과징금) under Article 64-2 of the Personal Information Protection Act, effective 11 September 2026. The amendment does not create a new duty — it changes how an existing fine is sized once a violation occurs, by adding a formal severity table for aggravation, sharpening the criteria for investment-related reductions, and tightening or loosening specific aggravating and mitigating factors. Any personal information processor subject to a PIPA fine, including a foreign company processing Korean users' data, is affected the next time an enforcement case reaches the calculation stage.

What changed, specifically

  • New aggravation table (별표 2). The base-amount and aggravation methodology under Article 64-2(2) is now spelled out in a dedicated schedule, replacing case-by-case judgment with a fixed framework.
  • Repeat violations are penalized more heavily. The aggravation for repeat violations is strengthened (Article 9(1)(2)).
  • New aggravation tied to breach response. Where notification or reporting of a breach is delayed or omitted, and the processor also failed to take measures to contain the spread of harm, a fine can now be increased on that basis (Article 10(1)(2)) — this is a new trigger, not a restatement.
  • Reductions are narrowed for major public bodies. State agencies, local governments, and public-system operators under Enforcement Decree Article 30-2 are now expressly excluded from certain reductions tied to the nature and scale of their operations (Article 9(2)(2)).
  • Certification and self-regulatory-activity reductions are scaled back. The discount previously available for holding certifications or running voluntary protection programs is reduced (Article 10(2)(3)).
  • New reduction for incident-response infrastructure. A processor that has built and operated an incident-response system, and responded promptly, can now receive a reduction on that basis (Article 10(2)(5)) — separated out from the general damage-mitigation reduction.
  • Severity criteria now include linked information. The table used to judge the severity of a violation (별표 1) now counts "연계정보" (linkage/linked information) as a type of personal data processed, which can affect the severity tier assigned to a breach.

What this means for you

  • If you already have a breach-response and reporting process, keep records of it. A documented incident-response system and prompt action are now an explicit basis for a fine reduction — evidence of this needs to be readily producible if PIPC opens a case.
  • Do not delay breach notification while assessing scope. Late or missing notification, combined with any failure to act to limit the spread of harm, is now a specific aggravating factor rather than something absorbed into general discretion.
  • Re-check reliance on certifications (e.g., ISMS-P) as a mitigation argument. The reduction tied to certification and voluntary protective activity has been cut back, so it should not be treated as carrying the same weight it did before.
  • Confirm whether "연계정보" (linked/linkage information) is part of what you process. Its inclusion in the severity table can raise the severity classification assigned to an incident involving that data type.
  • This is a calculation-methodology change, not a new compliance obligation — it matters at the enforcement and fine-negotiation stage, so it is worth having in hand before, not after, a breach investigation begins.

Source: https://www.law.go.kr/행정규칙/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EB%B2%95%20%EC%9C%84%EB%B0%98%EC%97%90%20%EB%8C%80%ED%95%9C%20%EA%B3%BC%EC%A7%95%EA%B8%88%20%EB%B6%80%EA%B3%BC%EA%B8%B0%EC%A4%80