This is an English version of our Korean article, based on public information as of October 4, 2026. Please check the official sources below for the latest details.
Read the original Korean article
Summary
- The revised Personal Information Protection Act took effect on September 11, and repeated or serious breaches can now draw a fine of up to 10% of total revenue.
- The revised Information and Communications Network Act took effect on October 1, adding a fine of up to 3% of related revenue for breach incidents repeated through intent or gross negligence.
- A breach-possibility notification system was introduced: even before a breach is confirmed, the affected individuals must be told within 72 hours of learning there is a possibility.
- If you receive a notice, first check where it came from, and if you are worried about identity theft, you can use the Financial Transaction Safe-Block Service (금융거래 안심차단서비스).
〰
Two Laws Took Effect Within a Month of Each Other
As large-scale personal data breaches have continued, the system is shifting toward asking what a company did to prevent an incident, rather than how much it is fined after one. As a result, the Personal Information Protection Act and its enforcement decree were revised and took effect on September 11, and the Information and Communications Network Act (정보통신망법) and its enforcement decree on October 1.
The two laws have similar names and are easy to confuse. The Personal Information Protection Act focuses on personal data breaches themselves and protecting the individuals concerned, while the Information and Communications Network Act focuses on preventing and responding to cyber breach incidents and on corporate security systems. Use the table below to get the big picture first.

| Item | Personal Information Protection Act and decree | Information and Communications Network Act and decree |
|---|---|---|
| Effective date | September 11, 2026 (mandatory ISMS-P certification from July 1, 2027) | October 1, 2026 |
| Fines | Up to 10% of total revenue for repeated or serious breaches | Up to 3% of related revenue for breach incidents repeated through intent or gross negligence |
| Corporate officers | CEO’s ultimate responsibility specified, stronger CPO authority, board resolution and filing when appointing, changing, or dismissing a CPO | CISO raised to executive level (for companies above medium size), mandatory information security committee |
| Touchpoints with users | Breach-possibility notification system, expanded items in breach notices | Stronger breach incident investigation and sanction system, enforcement fine for failing to follow corrective orders |
〰
Personal Information Protection Act: The 10% Fine and Reductions for Investment
According to the Personal Information Protection Commission (개인정보보호위원회), from September 11 a fine of up to 10% of total revenue can be imposed for repeated or serious breaches. The targets include cases where a violation was repeated within three years through intent or gross negligence, cases where intent or gross negligence caused large-scale harm to 10 million or more people, and cases where a breach occurred because a corrective order was not followed.
“10%” is not a number that applies to every incident; it is a ceiling that can be used when these special conditions are met. The actual fine is calculated by considering the nature of the violation, the scale of harm, and other factors.
Meanwhile, companies that invested in prevention get a benefit. Taking into account the size and continuity of budget, staff, and equipment investment, the level of the protection system, and safety measures that go beyond what the law requires, the fine can be reduced by up to 40% of the base fine amount. A reduction of up to 40% is also possible when a company quickly detected an incident, reported and notified it, and prevented the harm from spreading.
Conversely, increases for repeated violations become stronger. The increase rate was raised to +20% for one violation, +40% for two, and +80% for three or more, and if a company fails to report and notify a breach within the legal deadline and also takes no measures to prevent the harm from spreading, the fine can be increased by up to 30%. The intent is to remove a structure in which not reporting is actually more profitable.
Corporate accountability has also changed. The ultimate responsibility of business owners and representatives is now specified, and the Chief Privacy Officer (CPO) has authority over things like managing specialist staff, securing budget, and reporting to the board. Companies above a certain size must obtain a board resolution and report to the Personal Information Protection Commission when appointing, changing, or dismissing a CPO. This obligation has a grace period until December 31, 2027, during which no administrative fine will be imposed.
〰
Information and Communications Network Act: CISO Raised to Executive Level and Fines for Repeated Incidents
The Ministry of Science and ICT said on September 30 that the revised Information and Communications Network Act and its enforcement decree take effect from October 1. It puts into the legal system the government-wide comprehensive information security measures drawn up after the large-scale breach incidents that continued last year.
There are three key points. First, the status of the Chief Information Security Officer (CISO) is raised from employee to executive, so companies above medium size must appoint an executive. Companies that must newly appoint an executive get a six-month grace period, and there is no change for small and medium-sized companies.
Second, companies that are required to report their CISO must set up an information security committee and deliberate on matters such as securing the information security budget and staff. Third, an enhanced certification under the Information Security Management System (ISMS) is newly introduced for operators whose incidents would have a large impact. The specific details of the enhanced certification are expected to be announced by notice within the next six months.
Sanctions have also become stronger. Operators that cause repeated breach incidents through intent or gross negligence face a fine of up to 3% of related revenue, depending on the seriousness of the incident. If they do not follow a corrective order or a request to submit materials, an enforcement fine equal to 0.02% of average daily revenue is added for each day of non-compliance.
〰
What Users Will Notice: Breach-Possibility Notification
The change closest to consumers is the breach-possibility notification system. Previously, people were told only after a breach was confirmed, but now, even if a breach has not been confirmed, notice must be given when it is reasonably judged to be highly likely.
The Personal Information Protection Commission described two covered situations. One is when unauthorized access to a personal information processing system or a handler’s device has occurred and a breach is suspected but it is hard to identify whose information is involved. The other is when it is confirmed that some information is being traded illegally, so other individuals’ information may also have leaked. In these cases, the individuals concerned must be notified within 72 hours of learning of the fact.
The notice includes the items of personal information that may have leaked, the suspected time and circumstances, ways to minimize harm, the procedure for relief from harm, a contact point for reporting harm, and a statement that further notice will be given if the breach is confirmed. The items in a breach notice were also expanded to include how to apply for dispute mediation and how to claim damages.
Also, cases where personal information is forged, altered, or damaged, such as in ransomware attacks, are now covered by breach reporting and notification. If it is later confirmed that no breach actually occurred after a possibility notice, a correction notice must be sent to ease people’s worries.
| What the notice contains | What users should check |
|---|---|
| Personal information items | Check which of your information is included |
| Suspected time and circumstances | Read when and how the problem arose |
| Ways to minimize harm | Follow the steps given right away |
| Relief procedure and reporting contact | Note down how to request dispute mediation or damages |
| Further notice planned if confirmed | Keep checking whether further notices arrive |
〰
Limits to Keep in Mind and What Is Not Yet Decided
First, the new law applies from incidents that occur after it took effect. It was reported that the Personal Information Protection Commission said it would be hard to apply it to cases already under investigation. The new fines do not apply retroactively to past incidents right away.
Next, remember that “up to” means a ceiling. The actual fine is set by considering the nature and degree of the violation and the scale of harm, and a minor violation by a very small or small-to-medium company may even be exempted if it is corrected with technical support.
Finally, items the government has described as policy directions are still at the planning stage. Measures such as strengthening companies’ liability for damages and burden of proof were part of the plan announced in May, so until they are put into law, it is best to separate expectations from reality.
〰
How This Affects You and What to Do Now
A change in the law does not make your information safe automatically. Build the habits below, in this order, to protect yourself.
1) When you receive a breach notice, first check where it was sent from. The financial authorities have warned about voice phishing that uses personal data leaks as a pretext, with claims of opening accounts used for fraud, involvement in identity theft, or paying compensation. Do not tap the address in a text, and check through the company’s official app or main phone number.
2) Follow the harm-minimizing steps in the notice exactly. If the notice says to change your password or take other steps, it is best to do so right away.
3) If you are worried about identity theft, look into the Financial Transaction Safe-Block Service. If you sign up, you can block in advance loans, account openings, and open banking activity being carried out without your knowledge. You can apply at a financial institution branch, in the Korea Financial Telecommunications and Clearings Institute’s Account Info (어카운트인포) app, or through bank mobile banking.
4) Keep the notice. It becomes supporting evidence if you need dispute mediation or to claim damages.
5) If you use the same password for several services, use this chance to separate them. This is a basic habit that helps everyone regardless of the law.
〰
Frequently Asked Questions
Q. Does the fine of 10% of revenue apply to every breach?
No. It is a ceiling that can be used under special conditions, such as when a violation was repeated within three years through intent or gross negligence, when large-scale harm to 10 million or more people was caused, or when a breach occurred because a corrective order was not followed. The actual amount is set by considering the nature of the violation, the scale of harm, and other factors.
Q. How do the fines under the Personal Information Protection Act and the Information and Communications Network Act differ?
Under the Personal Information Protection Act, it is up to 10% of total revenue for repeated or serious breaches; under the Information and Communications Network Act, it is up to 3% of related revenue for breach incidents repeated through intent or gross negligence. They are separate systems with different targets and criteria.
Q. I received a breach-possibility notice. Was my data really leaked?
It may not be confirmed yet. A possibility notice is guidance sent at the stage when a breach is suspected, so if it is confirmed a further notice should arrive, and if it turns out not to have been a breach a correction notice should arrive.
Q. Do the new fines apply to breaches that have already happened?
The new law applies from incidents that occurred after it took effect. It was reported that it would be hard to apply it to cases already under investigation.
Sources
- Personal Information Protection Commission press release: Personal Information Protection Act, enforcement decree, and notices take effect from September 11 (published by Korea Broadcasting News)
- ZDNet Korea: Revised Information and Communications Network Act and decree raising the CISO to executive level take effect October 1 (Sept. 30, 2026)
- Money Today (머니투데이): Information and Communications Network Act takes effect, fines for operators with repeated breach incidents (Sept. 30, 2026)
- Chosun Biz (조선비즈): Personal Information Protection Commission’s plan to shift to a prevention-focused personal data management system (May 12, 2026)
- Newsis (뉴시스): Chuseok voice phishing on the rise, beware of texts impersonating parcels and fines (FSC and FSS guidance)
This article summarizes public information for general information purposes. Product specifications, fees, and policy details may change, so please be sure to check the official announcements. Eligibility for many Korean programs depends on residency or registration status in Korea, so please confirm on the official site.

댓글 남기기