| Title | The PIPC to Strengthen Responsibilities and Management Frameworks for Privacy to Prevent Data Breaches | ||
|---|---|---|---|
| Department | Date | 2026.03.13 | |
| Attachment | press release The PIPC to Strengthen Responsibilities and Management Frameworks for Privacy to Prevent Data Breaches.pdf | ||
| Page URL | https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=3005 | ||
| Contents |
Press Release The PIPC to Strengthen Responsibilities and Management Frameworks for Privacy to Prevent Data Breaches - The Amended PIPA will be announced on March 10, 2026, and will take effect from September 11, 2026 - Key amendments include introducing punitive penalties for repeated data breaches, strengthening responsibility of CEOs and CPOs, and mandating the ISMS-P Certification
March 9, 2026 (This is an unofficial translation of a press release, originally prepared in Korean.)
The amended Personal Information Protection Act (PIPA), which strengthens responsibility for personal information protection through the introduction of punitive penalties for repeated or intentional data breaches, enhanced roles for Chief Privacy Officers (CPOs), and improvements to the Personal Information & Information Security Management System (ISMS-P) certification system, will be announced on March 10, 2026. The amendment bill was passed through the National Assembly’s National Policy Committee on December 17, 2025, the Plenary Meeting on February 12, 2026, and the Cabinet Meeting on March 3, 2026.
The passage of the amendment to the PIPA was expedited amid growing anxiety and concerns fueled by a series of massive data breaches, with the aim of making businesses and agencies assume greater responsibility for protecting personal information. The amendment seeks to establish strong deterrence through stricter sanctions for data breaches while preventing recurring breaches by encouraging prevention-oriented investments and strengthening the personal information management framework. The following explains the key amendment to the PIPA.
1. Introducing Punitive Penalties and Incentives for Prevention-Oriented Investments
To address repeated and severe data breaches, the PIPC has introduced a special provision imposing sanctions of up to 10% of a company’s annual turnover. The existing penalty system, which imposes sanctions of 3% of a company’s annual turnover, has been insufficient to secure effective deterrence. Accordingly, the PIPC has established lawful bases for imposing stronger sanctions in cases where data breaches are repeated or have significant implications.
Furthermore, the amendment has introduced incentives to encourage prevention-oriented investments for personal information protection, lowering the level of sanctions when businesses demonstrate that they have made investments in budgets, personnel, facilities, and devices for data protection and privacy. However, data breaches caused by intention or gross negligence are excluded from receiving incentives.
2. Introducing a Notification System for Potential Data Breaches
Under the current PIPA, personal data processors are required to notify data subjects of the data breach when they become aware of it. However, it has caused delays in reporting incidents, even when a data leak is likely to take place. To enable data subjects to be informed and respond promptly to potential risks, the amended PIPA mandates notification or reporting when personal data processors become aware of potential data breaches, including incidents involving forgery or other privacy threats. In addition, the amended PIPA stipulates that personal data processors should provide information on redress, such as damages, application for dispute mediation, and other remedies, when notifying a data breach.
The existing legal framework also does not require obligations to notify and report incidents involving ransomware-related forgery, alteration, or damage to personal information. It often leads to difficulties in rapidly responding to privacy incidents. In this regard, the amended PIPA includes forgery, alteration, and damage to personal information within the scope subject to notification and reporting obligations. At the same time, the amended privacy law requires personal data processors to provide affected data subjects with redress information, such as damages or dispute mediation applications.
3. Strengthening Responsibilities of CEOs and CPOs
To fundamentally prevent data breaches, businesses and agencies should raise awareness of the importance of processing and protecting personal information and pay more attention to their data processing practices across the board. To this end, the amended PIPA aims to establish a robust management system for personal information by strengthening responsibilities of employers, Chief Executive Officers (CPOs), and Chief Privacy Officers (CPOs).
First up, the amended PIPA clarifies that CEOs, as final decision-makers, should be responsible for managing and supervising the processing of personal information. In case personal data processors that process personal information above a certain threshold designate, change, or dismiss CPOs, such decisions should be deliberated by the board of directors and then reported to the PIPC.
At the same time, the amended PIPA strengthens the roles and responsibilities of CPOs to establish a robust personal information management system on a permanent basis. It also mandates that CPOs are required to oversee dedicated personnel and budgets for safeguarding privacy and report matters related to privacy protection to CEOs and the board of directors.
4. Mandating the ISMS-P Certification of Personal Data Processors in Both the Public and Private Sectors
Lastly, the amendment introduces the mandatory ISMS-P certification for companies and agencies that have a significant impact on privacy protection in both the public and private sectors. It aims to encourage them to further advance their information security and personal information protection practices and to establish effective personal information protection management systems. The scope of entities subject to the mandatory certification requirement will be specified during the amendment process of the Enforcement Decree of the PIPA.
The amended PIPA will take effect on September 11, 2026. However, the provisions mandating the ISMS-P certification will be effective from July 1, 2027, given the time required to secure relevant budgets and other circumstances.
The PIPC will accelerate the amendment of the Enforcement Decree of the PIPA, including the establishment of delegation provisions, to ensure the amended PIPA takes effect as planned. At the same time, the PIPC will continue to engage closely with the industry and public sectors to ensure the operational effectiveness of relevant schemes.
* A PDF file, formatted for better readability, is attached. |
||