Korea’s Data Breach Fines Up to 10%: 2026 Law Changes

조회수

1

어두운 방 책상 위 노트북과 자물쇠 모양 오브제

This is an English version of our Korean article, based on public information as of October 4, 2026. Please check the official sources below for the latest details.

Read the original Korean article

Summary

  • The revised Personal Information Protection Act took effect on September 11, and repeated or serious breaches can now draw a fine of up to 10% of total revenue.
  • The revised Information and Communications Network Act took effect on October 1, adding a fine of up to 3% of related revenue for breach incidents repeated through intent or gross negligence.
  • A breach-possibility notification system was introduced: even before a breach is confirmed, the affected individuals must be told within 72 hours of learning there is a possibility.
  • If you receive a notice, first check where it came from, and if you are worried about identity theft, you can use the Financial Transaction Safe-Block Service (금융거래 안심차단서비스).

〰

Two Laws Took Effect Within a Month of Each Other

As large-scale personal data breaches have continued, the system is shifting toward asking what a company did to prevent an incident, rather than how much it is fined after one. As a result, the Personal Information Protection Act and its enforcement decree were revised and took effect on September 11, and the Information and Communications Network Act (정보통신망법) and its enforcement decree on October 1.

The two laws have similar names and are easy to confuse. The Personal Information Protection Act focuses on personal data breaches themselves and protecting the individuals concerned, while the Information and Communications Network Act focuses on preventing and responding to cyber breach incidents and on corporate security systems. Use the table below to get the big picture first.

A hand reaching for a smartphone on a desk
Not related to any specific product (AI-generated image)
ItemPersonal Information Protection Act and decreeInformation and Communications Network Act and decree
Effective dateSeptember 11, 2026 (mandatory ISMS-P certification from July 1, 2027)October 1, 2026
FinesUp to 10% of total revenue for repeated or serious breachesUp to 3% of related revenue for breach incidents repeated through intent or gross negligence
Corporate officersCEO’s ultimate responsibility specified, stronger CPO authority, board resolution and filing when appointing, changing, or dismissing a CPOCISO raised to executive level (for companies above medium size), mandatory information security committee
Touchpoints with usersBreach-possibility notification system, expanded items in breach noticesStronger breach incident investigation and sanction system, enforcement fine for failing to follow corrective orders
Source: Personal Information Protection Commission press release (Personal Information Protection Act); Ministry of Science and ICT announcement coverage (Information and Communications Network Act) (as of October 4, 2026)

〰

Personal Information Protection Act: The 10% Fine and Reductions for Investment

According to the Personal Information Protection Commission (개인정보보호위원회), from September 11 a fine of up to 10% of total revenue can be imposed for repeated or serious breaches. The targets include cases where a violation was repeated within three years through intent or gross negligence, cases where intent or gross negligence caused large-scale harm to 10 million or more people, and cases where a breach occurred because a corrective order was not followed.

“10%” is not a number that applies to every incident; it is a ceiling that can be used when these special conditions are met. The actual fine is calculated by considering the nature of the violation, the scale of harm, and other factors.

Meanwhile, companies that invested in prevention get a benefit. Taking into account the size and continuity of budget, staff, and equipment investment, the level of the protection system, and safety measures that go beyond what the law requires, the fine can be reduced by up to 40% of the base fine amount. A reduction of up to 40% is also possible when a company quickly detected an incident, reported and notified it, and prevented the harm from spreading.

Conversely, increases for repeated violations become stronger. The increase rate was raised to +20% for one violation, +40% for two, and +80% for three or more, and if a company fails to report and notify a breach within the legal deadline and also takes no measures to prevent the harm from spreading, the fine can be increased by up to 30%. The intent is to remove a structure in which not reporting is actually more profitable.

Corporate accountability has also changed. The ultimate responsibility of business owners and representatives is now specified, and the Chief Privacy Officer (CPO) has authority over things like managing specialist staff, securing budget, and reporting to the board. Companies above a certain size must obtain a board resolution and report to the Personal Information Protection Commission when appointing, changing, or dismissing a CPO. This obligation has a grace period until December 31, 2027, during which no administrative fine will be imposed.

〰

Information and Communications Network Act: CISO Raised to Executive Level and Fines for Repeated Incidents

The Ministry of Science and ICT said on September 30 that the revised Information and Communications Network Act and its enforcement decree take effect from October 1. It puts into the legal system the government-wide comprehensive information security measures drawn up after the large-scale breach incidents that continued last year.

There are three key points. First, the status of the Chief Information Security Officer (CISO) is raised from employee to executive, so companies above medium size must appoint an executive. Companies that must newly appoint an executive get a six-month grace period, and there is no change for small and medium-sized companies.

Second, companies that are required to report their CISO must set up an information security committee and deliberate on matters such as securing the information security budget and staff. Third, an enhanced certification under the Information Security Management System (ISMS) is newly introduced for operators whose incidents would have a large impact. The specific details of the enhanced certification are expected to be announced by notice within the next six months.

Sanctions have also become stronger. Operators that cause repeated breach incidents through intent or gross negligence face a fine of up to 3% of related revenue, depending on the seriousness of the incident. If they do not follow a corrective order or a request to submit materials, an enforcement fine equal to 0.02% of average daily revenue is added for each day of non-compliance.

〰

What Users Will Notice: Breach-Possibility Notification

The change closest to consumers is the breach-possibility notification system. Previously, people were told only after a breach was confirmed, but now, even if a breach has not been confirmed, notice must be given when it is reasonably judged to be highly likely.

The Personal Information Protection Commission described two covered situations. One is when unauthorized access to a personal information processing system or a handler’s device has occurred and a breach is suspected but it is hard to identify whose information is involved. The other is when it is confirmed that some information is being traded illegally, so other individuals’ information may also have leaked. In these cases, the individuals concerned must be notified within 72 hours of learning of the fact.

The notice includes the items of personal information that may have leaked, the suspected time and circumstances, ways to minimize harm, the procedure for relief from harm, a contact point for reporting harm, and a statement that further notice will be given if the breach is confirmed. The items in a breach notice were also expanded to include how to apply for dispute mediation and how to claim damages.

Also, cases where personal information is forged, altered, or damaged, such as in ransomware attacks, are now covered by breach reporting and notification. If it is later confirmed that no breach actually occurred after a possibility notice, a correction notice must be sent to ease people’s worries.

What the notice containsWhat users should check
Personal information itemsCheck which of your information is included
Suspected time and circumstancesRead when and how the problem arose
Ways to minimize harmFollow the steps given right away
Relief procedure and reporting contactNote down how to request dispute mediation or damages
Further notice planned if confirmedKeep checking whether further notices arrive
Source: Compiled from the Personal Information Protection Commission press release (Personal Information Protection Act revision takes effect, Sept. 11, 2026) (as of October 4, 2026)

〰

Limits to Keep in Mind and What Is Not Yet Decided

First, the new law applies from incidents that occur after it took effect. It was reported that the Personal Information Protection Commission said it would be hard to apply it to cases already under investigation. The new fines do not apply retroactively to past incidents right away.

Next, remember that “up to” means a ceiling. The actual fine is set by considering the nature and degree of the violation and the scale of harm, and a minor violation by a very small or small-to-medium company may even be exempted if it is corrected with technical support.

Finally, items the government has described as policy directions are still at the planning stage. Measures such as strengthening companies’ liability for damages and burden of proof were part of the plan announced in May, so until they are put into law, it is best to separate expectations from reality.

〰

How This Affects You and What to Do Now

A change in the law does not make your information safe automatically. Build the habits below, in this order, to protect yourself.

1) When you receive a breach notice, first check where it was sent from. The financial authorities have warned about voice phishing that uses personal data leaks as a pretext, with claims of opening accounts used for fraud, involvement in identity theft, or paying compensation. Do not tap the address in a text, and check through the company’s official app or main phone number.

2) Follow the harm-minimizing steps in the notice exactly. If the notice says to change your password or take other steps, it is best to do so right away.

3) If you are worried about identity theft, look into the Financial Transaction Safe-Block Service. If you sign up, you can block in advance loans, account openings, and open banking activity being carried out without your knowledge. You can apply at a financial institution branch, in the Korea Financial Telecommunications and Clearings Institute’s Account Info (어카운트인포) app, or through bank mobile banking.

4) Keep the notice. It becomes supporting evidence if you need dispute mediation or to claim damages.

5) If you use the same password for several services, use this chance to separate them. This is a basic habit that helps everyone regardless of the law.

〰

Frequently Asked Questions

Q. Does the fine of 10% of revenue apply to every breach?

No. It is a ceiling that can be used under special conditions, such as when a violation was repeated within three years through intent or gross negligence, when large-scale harm to 10 million or more people was caused, or when a breach occurred because a corrective order was not followed. The actual amount is set by considering the nature of the violation, the scale of harm, and other factors.

Q. How do the fines under the Personal Information Protection Act and the Information and Communications Network Act differ?

Under the Personal Information Protection Act, it is up to 10% of total revenue for repeated or serious breaches; under the Information and Communications Network Act, it is up to 3% of related revenue for breach incidents repeated through intent or gross negligence. They are separate systems with different targets and criteria.

Q. I received a breach-possibility notice. Was my data really leaked?

It may not be confirmed yet. A possibility notice is guidance sent at the stage when a breach is suspected, so if it is confirmed a further notice should arrive, and if it turns out not to have been a breach a correction notice should arrive.

Q. Do the new fines apply to breaches that have already happened?

The new law applies from incidents that occurred after it took effect. It was reported that it would be hard to apply it to cases already under investigation.

This article summarizes public information for general information purposes. Product specifications, fees, and policy details may change, so please be sure to check the official announcements. Eligibility for many Korean programs depends on residency or registration status in Korea, so please confirm on the official site.

댓글 남기기

Sean Daily에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기