Law / South Korea

Personal Information Protection Act, enforcement and private civil remedy

Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 39, 39-2, 51, 64-2

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 September 2023.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • An app processing Korean personal data must be able to answer to the PIPC for its lawful basis and safeguards, and an individual harmed by a security failure may bring a private civil claim for statutory damages, or damages up to five times the actual loss, without needing to prove the controller's negligence.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

PIPA Chapter X, Penalty Provisions, confirmed current: Art. 70 punishes causing suspension, paralysis or severe hardship to a public institution's work by altering or erasing its data, or comparable unauthorized-access conduct, with imprisonment with labor of up to 10 years or a fine up to KRW 100,000,000; Art. 71 punishes several unauthorized processing and disclosure offenses (including providing personal information to a third party without consent) with imprisonment up to 5 years or a fine up to KRW 50,000,000; Art. 72 (misuse of visual data processing devices and related conduct) carries imprisonment up to 3 years or a fine up to KRW 30,000,000; Art. 73 (various safeguard and procedural failures) carries imprisonment up to 2 years or a fine up to KRW 20,000,000. Art. 74 imposes joint liability: where a corporation's representative, agent or employee commits an Art. 70 offense in the course of the corporation's business, the corporation itself is also fined up to KRW 70,000,000, absent due care.

Penalty structure

Art. 64-2(1), confirmed against the current KLRI English consolidation, which reflects amendments through Act No. 19234 (Mar. 14, 2023): the Protection Commission may impose a penalty surcharge on a personal information controller not exceeding 3/100 (3 percent) of total sales, or up to KRW 2,000,000,000 where no sales exist or sales cannot be calculated. This article was newly inserted 2023-03-14 and reads unchanged in that consolidation. PIPA has since been amended again by Act No. 20897 (in force 2025-10-02), which KLRI's English consolidation does not yet reflect. A further amendment reported elsewhere as promulgated 2026-03-10 is reported to raise this cap toward 10 percent of total revenue and add personal liability for a controller's chief executive, effective 2026-09-11, but no official source for that amendment is located, so the 3 percent figure above is what the primary text confirms as of this row's as_of date.

Rule
Turnover pct only
As of
2 September 2026
Currency
KRW
Turnover percentage cap
3

Statutory damages

Art. 39-2(1), confirmed unchanged in the current KLRI consolidation (still reads 'three million won'): a data subject who suffers damage from loss, theft, divulgence, forgery, alteration or damage of their personal information caused by a controller's intention or negligence may claim a reasonable amount of damages not exceeding KRW 3,000,000, without needing to prove the controller's fault; the controller bears the burden of proving the absence of intention or negligence. Mapped to per_person_negligent since the reversed burden of proof, not a negligence finding by the plaintiff, is what unlocks this ceiling. A separate, non-schema-fitting remedy sits at Art. 39(1): a court may award up to 5 times the actual loss where the controller acted with intention or gross negligence. Art. 51 authorizes an injunction-only group action by qualified consumer or civic organizations to stop an ongoing infringement, not a damages class action, so class_action_available is recorded false for a damages claim specifically.

As of
2 September 2026
Currency
KRW
Per person negligent
3,000,000

Who enforces it

Enforcement body

Personal Information Protection Commission (PIPC), Korea's independent data protection authority, established under the Prime Minister as a central administrative agency under PIPA Art. 7.

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Information Protection Commission (PIPC), Korea's independent data protection authority, enforces PIPA with investigative, corrective order, and administrative fine power, including a fine of up to 3% of a controller's total sales revenue for major violations under Art. 64-2.

Individuals separately have a private civil remedy: Art. 39 lets a court award damages up to five times actual loss where the controller acted with intention or negligence, and Art. 39-2 lets a data subject recover statutory damages up to KRW 3,000,000 for loss, theft, or divulgence without proving actual loss, with the controller bearing the burden of proving it was not negligent.

Art. 51 separately authorizes an injunction only group action by qualified consumer or civic organizations to stop an ongoing infringement, not a damages class action.

A further amendment reported as promulgated 10 March 2026 is reported to raise the Art. 64-2 fine cap toward 10% of total revenue for repeated or large scale violations and to add personal liability for a controller's chief executive, effective 11 September 2026, but no official source for that amendment is located, so it is not recorded as a dated stage.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official statute text, KLRI English translation

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app