Law / South Korea

Personal Information Protection Act, breach notification duties

Act No. 10465 (as amended by Act No. 19234, 2023), Art. 34; Enforcement Decree Arts. 39-40

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 September 2023.

A breach notification rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • An app that suffers a leak, theft, or unauthorized disclosure of Korean personal data must notify affected data subjects without delay, and must report the breach to the PIPC without delay if it affects 1,000 or more people, involves sensitive information such as a biometric identifier, or resulted from illegal external access.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Art. 34(1) requires a controller to notify affected data subjects without delay on becoming aware personal information has been divulged, and the Enforcement Decree sets this at within 72 hours.

Art. 34(3) separately requires reporting to the PIPC, or the Korea Internet and Security Agency, without delay for a breach above a Presidential Decree set scale, which the Decree sets at 1,000 or more affected subjects, any sensitive information or unique identification information involved, or a breach caused by illegal external access, also within 72 hours.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

official KLRI English translation of the current consolidated PIPA text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app