Summary

A bill to amend the Personal Information Protection Act, introduced 17 September 2026 by Rep. Park Seong-hun and 10 co-sponsors, would for the first time let regulators impose a fine — capped at a percentage of revenue to be set by presidential decree — on a personal-data controller that conceals, destroys, forges, or alters investigation-related records (e.g., access logs) before or during a breach investigation. It would also create a reward payment for anyone who reports such concealment or destruction and submits supporting evidence. The bill has just been referred to committee; it is not yet law, and no effective date has been set.

Key provisions as drafted

  • New Article 64-3 (proposed): A fine may be imposed on a personal-data controller that hides, destroys, forges, or alters investigation-related materials either before an investigation begins or while it is underway, in connection with a personal-data breach incident. The fine ceiling is expressed as a percentage of revenue, with the exact rate left to a presidential decree — the bill itself does not fix the number.
  • New Article 62-2 (proposed): A reward may be paid to a person who reports or tips off the regulator about such concealment or destruction, provided they submit evidence capable of proving it.
  • Rationale stated in the bill: the sponsors cite recurring cases where companies facing large-scale breaches have hidden or destroyed access logs and other records to delay or obstruct investigation, and note that current law lacks a dedicated tool to catch and separately sanction that conduct.

Where it stands

The bill was referred to its standing committee following introduction on 17 September 2026. Committee review is the next step; there is no indication yet of a hearing date, amendments, or a path to a floor vote. Nothing in current law changes unless and until this bill passes.

What this means for you

  • This does not yet apply to you. No obligation exists today under this bill — it is a proposal at the committee stage, not an effective rule.
  • Review your document-retention and log-preservation practices now, before this could bind. If enacted, the exposure attaches specifically to conduct during or before an investigation — i.e., what you do with access logs and related records once a breach becomes known or a regulator's inquiry starts. Companies with weak internal controls over who can delete or alter logs during an incident are the ones this bill is aimed at.
  • Treat this as a signal on internal reporting exposure. The proposed reward for whistleblowers means an employee or contractor with knowledge of record concealment would have a direct incentive — and a mechanism — to report it, separate from any regulator-led discovery.
  • Track committee movement. The fine's actual size depends entirely on a future presidential decree that does not yet exist, so the practical bite of this bill cannot be assessed until it clears committee and that decree is drafted. We recommend re-checking status before assuming either that it will pass as written or that it will stay stalled.

Source: