Policy

South Korea PIPA Amendment Takes Effect With 10 Percent Global Revenue Fine Ceiling

The revised law caps aggravated penalties at 10 percent of worldwide revenue, outranks GDPR limits, and writes the first national rules for training AI models on personal data.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 11, 2026 / Updated September 13, 2026 / 7 min read

South Korea's amended Personal Information Protection Act took effect on September 11, 2026, seven months after the National Assembly approved it and six months after it was promulgated as Act No. 21445 on March 10, 2026. The revision raises the maximum administrative fine for the most serious violations to 10 percent of a company's total global annual revenue, and it establishes the first national legal framework anywhere for using personal data to train artificial intelligence models.

The law is not a new statute but a rewrite of the Personal Information Protection Act, which South Korea enacted on March 29, 2011 and which is enforced by the Personal Information Protection Commission, known as the PIPC. Regulators and law firms describe the change as the most consequential revision since the law's 2023 overhaul, and it lands in a market where breach volumes and penalty totals have both climbed sharply.

Tech Times reported on September 10, 2026 that the previous enforcement regime produced fines of roughly $0.70 per breached record, while the volume of personal data leaked in Korea surged nearly thirteenfold. Mondaq reported on August 26, 2026 that the PIPC logged 447 breach notifications in 2025, up 45.6 percent from 307 in 2024, imposed administrative fines in 40 cases totaling KRW 167.7 billion that year, and saw combined fines and penalties rise 172 percent year on year.

IAPP reported on March 12, 2026 that the amendment is the most consequential rewrite of the law since the 2023 overhaul and that it ties fines to chief executive accountability, framing the reform around a diagnosis Korean regulators had developed over years: fines alone do not change corporate behavior unless they are large enough to matter, are aimed at the people who set priorities, and are triggered early enough to protect data subjects before harm is done.

Key Facts

The headline change is the penalty ceiling. Article 64-2(1) keeps a general cap of 3 percent of revenue, but new Article 64-2(2) allows fines of up to 10 percent of total revenue in three situations, according to Mondaq: a repeat violation of the same category within three years of a prior fine where each was intentional or grossly negligent; an intentional or grossly negligent violation harming 10 million or more data subjects; or a leak resulting from a failure to comply with a corrective order. Tech Times noted on September 10, 2026 that the 10 percent ceiling surpasses the 4 percent maximum under the European Union's General Data Protection Regulation and the 7 percent ceiling in the EU AI Act.

A second pillar shifts responsibility onto executives. New Article 30-3 names the business owner or representative director as the ultimate responsible person, a duty that cannot be delegated. Above a scale threshold to be set by enforcement decree, controllers must obtain board approval before appointing, reassigning or removing a Chief Privacy Officer and must file that designation or removal with the PIPC within one month. Recording Law reported on July 23, 2026 that the CPO must manage specialist staff and control an adequate budget.

The law also adds a mitigation route. New Article 64-2(6) requires the PIPC to reduce a fine where the controller invested in data protection in advance, and the draft decree caps that reduction at 40 percent. Recording Law reported that the reduction mechanism applies where the violation is not intentional or grossly negligent.

Breach reporting rules tighten as well. Notification now triggers on a meaningful or reasonable possibility of leakage rather than a confirmed incident, and the notifiable categories cover forgery, alteration and damage, including ransomware. Draft decree language cited by Mondaq points to notifying potentially affected data subjects within 72 hours. Mandatory ISMS-P certification for the largest controllers begins July 1, 2027, a date both Mondaq and Recording Law confirm.

On AI, the amendment creates what Tech Times described on September 10, 2026 as the world's first national AI training data framework. The PIPC's generative AI guidance sets three adoption tiers: use of a third party API, fine tuning or retrieval augmented generation, and self developed pre-trained models. The self developed tier requires a reconstructible provenance record of origin, consent history and pseudonymization for every training record. Kim & Chang reported on August 21, 2026 that a further amendment passed the National Assembly plenary on August 20, 2026, introducing new Article 28-12(1), which lets a controller use lawfully collected personal information for AI development if anonymization or pseudonymization would make development difficult, safeguards set in the Enforcement Decree are in place, the purpose advances the public interest or broader social interests, and the risk of unjust infringement is significantly low, subject to PIPC review and approval. That amendment takes effect six months after promulgation.

Enforcement is not hypothetical. SK Telecom disclosed a breach of USIM related data affecting some 23.24 million subscribers in April 2025 and was fined KRW 134.79 billion that August, a record at the time. Coupang disclosed a breach in November 2025 assessed as affecting roughly 37.55 million people and was fined about KRW 624.7 billion in June 2026, the largest data protection fine in Korean history and roughly 4.6 times the SK Telecom record, according to Recording Law.

Analysis

What this really means is that South Korea has moved from a data protection regime that priced breaches per record to one that prices them as a share of the entire business. A 3 percent to 10 percent range on global revenue puts the country's exposure above the GDPR's 4 percent ceiling, and the aggravating factors are written to capture exactly the patterns regulators saw over the past two years: repeat offenses, large scale harm, and defiance of corrective orders.

The bigger picture here is governance, not just money. IAPP reported on March 12, 2026 that the amendment places personal supervisory liability on the CEO at a time when the enforcement authority has consistently shown a willingness to investigate aggressively and impose substantial penalties, making the practical risk among the highest in the world. Naming a responsible person, requiring board level sign off on CPO appointments, and offering up to 40 percent reductions for verified privacy investment all push spending upstream from investigation and remediation toward prevention.

The AI provisions may prove the more consequential export. No other national data protection law had made explicit rules for training models on personal data before this framework, and the tiered structure, from third party APIs to self developed pre-trained models, effectively regulates by how much control a company has over the training pipeline. The strongest obligations, including reconstructible provenance for every training record, land on the companies building their own models.

Two details complicate the picture. The August 20 amendment carves out exemptions from ten PIPA provisions for approved AI development, including restrictions on use beyond the original purpose and on processing sensitive information, so the same law both tightens general enforcement and loosens specific constraints for AI. The law also reaches foreign companies: PIPA applies extraterritorially to businesses processing data of individuals in South Korea, and since October 2, 2025 such companies must appoint a domestic representative. Whether the PIPC can supervise cross border training pipelines as rigorously as domestic ones remains untested.

Why It Matters

The 10 percent ceiling is now the highest headline fine in any general data protection law, and it is paired with a compliance architecture other regulators have been debating. The European Union's AI Act caps penalties at 7 percent, and the GDPR at 4 percent, so South Korea's move sets a reference point that multinationals will have to price into their global compliance budgets regardless of where they are headquartered.

For AI developers, the significance is structural. Provenance obligations that require a reconstructible record of origin, consent history and pseudonymization for every training record raise the cost of training on personal data, and the requirement that training and deployment rest on separate legal bases means a single approval does not cover an entire model lifecycle. Companies that rely on licensed or synthetic data may find the calculus changes.

The timing matters too. With 447 breach notifications in 2025 and fines rising 172 percent year on year, Korean regulators have both the caseload and the mandate to test the new tiers quickly, and the Coupang penalty shows the commission is willing to use the top of its existing range, which stood at 3 percent at the time.

Next Up

Attention now turns to the Enforcement Decree, which will set the scale threshold for board approved CPO appointments, define the safeguards and risk assessment criteria for AI development under Article 28-12, and fix the details of the 72 hour notification window and the 40 percent investment reduction. The AI amendment passed on August 20, 2026 takes effect six months after promulgation, so its operative date will follow the September 11 start of Act No. 21445.

Mandatory ISMS-P certification for the largest controllers arrives on July 1, 2027, and the first enforcement actions under the 10 percent tier will show how aggressively the PIPC applies the aggravating factors. For companies processing Korean personal data, from domestic platforms to foreign AI developers with users in the country, the compliance clock has already started.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.