Law / South Korea

South Korea

19 of 20 named instruments researched to a stage, across all six areas of law we track: 18 in force and 1 repealed, withdrawn or blocked. As of 20 September 2026.

When they take effect18 of 19 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 4 instruments (3 in force, 1 repealed, withdrawn or blocked) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 5 instruments (5 in force) 2024: 4 instruments (4 in force) 2025: 1 instrument (1 in force) 2026: 3 instruments (3 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 7
  3. Scraping law 4
  4. Cybersecurity law 1
  5. Age gating law 3
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 in force

Research summary (350 words)

South Korea's AI regime rests on the Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trustworthiness (the AI Framework Act, Act No. 20676), which took effect together with its Enforcement Decree on 22 January 2026. Article 31 imposes prior-use notice, generative-output labeling and deepfake-notice duties on AI business operators, reaching non-domestic operators serving Korean users.

Article 32 requires an operator whose AI system was trained above the Decree's compute threshold to run a life-cycle risk-management system that monitors and responds to AI-related safety accidents, and to submit the results of implementing it to the Ministry of Science and ICT.

Article 34 requires an operator providing high-impact AI to run risk-management, explanation and user-protection plans, provide human oversight, and keep and post supporting documentation, with Article 33 requiring it to review in advance whether its AI is high-impact at all.

Neither the Act nor its Enforcement Decree imposes any duty to report a particular incident, malfunction, accident or safety failure to the Ministry or to any other body: the word for a safety accident appears once in the Act, in Article 32(1), naming what an internal risk-management system must watch for, and nowhere in the Decree, and no provision of Chapters 4 through 6 states a without-delay standard or a day count running from an operator's awareness of one.

The Ministry is deferring administrative fines for most violations, including labeling violations, for about one year from the effective date as an implementation grace period, but the underlying duties are already in force.

A separate election-law prohibition, Public Official Election Act Article 82-8, bans AI-generated deepfake campaign content within 90 days of an election and is treated here as out of scope: it is structurally a ban with only a secondary labeling-based exemption, not an affirmative disclosure duty, so it belongs to a prohibited-practices inquiry rather than to this topic.

Four instruments sometimes associated with this topic, the Information and Communications Network Act Article 48, the Personal Information Protection Act, the Unfair Competition Prevention Act, and Copyright Act Articles 91 to 98, carry no AI-output-labeling content.

AI governance

AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems)

Act No. 20676, Article 32official statute portal, National Law Information Center (law.go.kr)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

Article 32 binds an AI business operator whose AI system was trained using cumulative compute at or above the threshold the Presidential Decree sets, and requires it to identify, assess and mitigate risk across the system's full life cycle and to build a risk-management system that monitors and responds to AI-related safety accidents. The operator must submit the results of implementing those measures to the Ministry of Science and ICT.

The Ministry sets the specific implementation method, and the manner of submitting those results, by public notice, matters the Act itself does not state. The Decree's threshold is met only where cumulative training compute reaches 10^26 floating-point operations or more, the system applies the most advanced AI technology currently in use, and its risk could broadly and seriously affect people's life, physical safety and fundamental rights.

Article 32 took effect on January 22, 2026, one year after the Act's promulgation. The submission is a periodic report of having that internal system in place rather than a notice triggered by a particular accident, and neither the Article nor the Decree states a period running from the moment an operator becomes aware of one.

What it requires

AI risk obligations

AI Framework Act, Article 34 (business-operator duties for high-impact AI)

Act No. 20676, Article 34official statute portal, National Law Information Center (law.go.kr)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

Article 34 binds an AI business operator providing high-impact AI, or a product or service that uses it, and requires it to establish and operate a risk-management plan, to establish and carry out a plan explaining the AI's final output and the main criteria and training-data overview behind it so far as technically feasible, to establish and operate a user-protection plan, to provide human management and supervision of the AI, and to prepare and keep documents confirming those measures.

The Ministry of Science and ICT sets the specific content of those measures by public notice and may recommend that operators comply, and an operator that has already taken equivalent measures under another statute is treated as having complied.

The Enforcement Decree requires the operator to post the main content of the risk-management, explanation and user-protection plans, and the name and contact details of the person supervising the high-impact AI, at its place of business or on its website, and to keep the supporting documentation, including in electronic form, for five years.

High-impact AI is defined by what the AI is used for rather than by what the operator is, covering energy supply, drinking water production, healthcare provision, medical and digital medical devices, nuclear material and facility safety, biometric identification for criminal investigation or arrest, hiring and loan decisions, transportation systems, public-service eligibility and fee decisions, and student assessment in early childhood, elementary and secondary education.

Article 33 separately requires an operator to review in advance whether its AI is high-impact, and lets it ask the Ministry to confirm that answer. Article 34 took effect on January 22, 2026, with the rest of the Act.

What it requires

AI transparency

AI Framework Act, Article 31 (transparency obligations for AI outputs)

Act No. 20676, Article 31official statute portal, National Law Information Center (law.go.kr)

In force 8 months, effective 22 January 2026. Binds public and private bodies.

What this law does

An AI business operator providing a product or service using high-impact or generative AI must give users prior notice that it operates on that AI. An operator providing generative AI, or a product or service using it, must indicate that output was AI-generated, either through a human-perceptible label or machine-readable metadata or watermark.

Where an operator uses AI to produce a virtual sound, image, or video difficult to distinguish from reality, only a user-perceptible label satisfies the deepfake-specific duty, with a narrow exception for artistic or creative works. The Act reaches conduct outside Korea affecting Korean users under its own extraterritoriality clause, and a foreign operator meeting revenue or user thresholds must appoint a domestic representative.

What it requires

Privacy law7 instruments, 7 in force

Research summary (210 words)

South Korea's Personal Information Protection Act (PIPA, Act No. 10465, as amended by Act No. 19234 effective 15 September 2023) is a single omnibus statute covering both public-sector and private-sector personal data processing, enforced by the independent Personal Information Protection Commission (PIPC).

PIPA requires one of several lawful bases, most often consent or the Art. 15(1)(6) legitimate-interest ground, for any processing, treats biometric identifiers as heightened-consent sensitive information through an Enforcement Decree definition that is technology-neutral and reaches a faceprint or voiceprint without naming either, and carries no blanket exemption for publicly available personal data.

Since the 2023 amendment, cross-border transfer may proceed on consent or on a treaty, PIPC certification, or PIPC adequacy recognition instead, and individuals have a private civil remedy (statutory and punitive damages) alongside PIPC's administrative-fine and corrective-order powers.

The regime remains under active development: the 2023 amendment's data-subject rights are still phasing in, PIPC continues to issue new AI-related guidance, and a further amendment reported to raise the administrative fine cap and add executive liability is due to take effect 11 September 2026. PIPA has since been amended again by Act No. 20897, in force 2 October 2025; the consolidated English translation lags, and the findings here are verified against the Act No. 19234 consolidation.

Breach notification

Personal Information Protection Act, breach notification duties

Act No. 10465 (as amended by Act No. 19234, 2023), Art. 34; Enforcement Decree Arts. 39-40official KLRI English translation of the current consolidated PIPA text

In force since 15 September 2023. Binds public and private bodies.

What this law does

Art. 34(1) requires a controller to notify affected data subjects without delay on becoming aware personal information has been divulged, and the Enforcement Decree sets this at within 72 hours.

Art. 34(3) separately requires reporting to the PIPC, or the Korea Internet and Security Agency, without delay for a breach above a Presidential Decree set scale, which the Decree sets at 1,000 or more affected subjects, any sensitive information or unique identification information involved, or a breach caused by illegal external access, also within 72 hours.

What it requires

Comprehensive regime

PIPC Guideline on Processing Publicly Available Data for AI Development and Services

PIPC Guideline (issued 2024-07-18), applying Personal Information Protection Act (Act No. 10465, as amended), Art. 15(1)(6)PIPC official English-language notice

In force since 18 July 2024. Binds public and private bodies.

What this law does

PIPC guidance interprets PIPA Art. 15(1)(6)'s legitimate interest ground as the lawful basis authorizing an AI developer to collect and use publicly available personal data from the open web for AI training and service development, provided the controller's interest clearly overrides data subjects' rights. It treats such data as remaining within PIPA's scope, not exempt, given the privacy risk from addresses, unique identifiers, and financial data mixed into public web content.

The guideline's own text addresses AI developers and service providers generally, with no stated limit to private-sector controllers.

What it requires

Personal Information Protection Act, comprehensive regime and lawful bases

Act No. 10465 (Mar. 29, 2011), as amended by Act No. 19234 (Mar. 14, 2023), Art. 15official statute text, Korea Legislation Research Institute (KLRI) English translation

In force since 15 September 2023. Binds public and private bodies.

What this law does

PIPA is Korea's single omnibus personal-data statute, reaching public institutions and private businesses alike. Art. 15 sets several lawful bases for collecting and using personal information, most commonly consent or the controller's justifiable interest where it is manifestly superior to the data subject's rights, and confines processing to the stated purpose of collection.

There is no separate controller and processor split as sharp as General Data Protection Regulation (GDPR)'s; PIPA instead regulates the broadly defined personal information controller.

What it requires

Cross border transfer

Personal Information Protection Act, cross-border transfer restrictions

Act No. 10465 (as amended by Act No. 19234, 2023), Art. 28-8(1), Arts. 28-8 to 28-11official KLRI English translation of the current consolidated PIPA text

In force since 15 September 2023. Binds public and private bodies.

What this law does

Art. 28-8 prohibits cross-border transfer of personal information unless a lawful basis applies, separate consent from the data subject first among them (Art. 17(3), the rule's pre-2023 home, was deleted by Act No. 19234), and bars a transfer contract that would violate the Act.

The 2023 amendment's Arts. 28-8 to 28-11 add alternative grounds: a treaty or international agreement, PIPC certification of the recipient's safeguards, or PIPC recognition that the destination country affords adequate protection, and arm the PIPC to order a transfer suspended for a serious or repeated violation. There is no data localization mandate.

What it requires

Data subject rights

Personal Information Protection Act, data subject rights and automated decisions

Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 4, 35, 36, 37, 37-2official English translation, KLRI, supplemented by convergent secondary legal reporting on Art. 37-2's specific effective date

In force since 15 March 2024. Binds public and private bodies.

What this law does

PIPA Arts. 4 and 35 through 37 grant a data subject the right to confirm whether their data is processed, to access it, to demand correction and deletion, and to suspend processing, exercisable against the personal information controller. Art. 37-2, added by the 2023 amendment, adds the right to demand an explanation of, or refuse, a fully automated decision that significantly affects the subject's rights or obligations, subject to a controller's justifiable reason defense.

The same amendment added Art. 35-2, a data portability right, reported by secondary sources to have taken effect separately on 13 March 2025; that date is not confirmed against primary text.

What it requires

Enforcement supervision

Personal Information Protection Act, enforcement and private civil remedy

Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 39, 39-2, 51, 64-2official statute text, KLRI English translation

In force since 15 September 2023. Binds public and private bodies.

What this law does

The Personal Information Protection Commission (PIPC), Korea's independent data protection authority, enforces PIPA with investigative, corrective order, and administrative fine power, including a fine of up to 3% of a controller's total sales revenue for major violations under Art. 64-2.

Individuals separately have a private civil remedy: Art. 39 lets a court award damages up to five times actual loss where the controller acted with intention or negligence, and Art. 39-2 lets a data subject recover statutory damages up to KRW 3,000,000 for loss, theft, or divulgence without proving actual loss, with the controller bearing the burden of proving it was not negligent.

Art. 51 separately authorizes an injunction only group action by qualified consumer or civic organizations to stop an ongoing infringement, not a damages class action.

A further amendment reported as promulgated 10 March 2026 is reported to raise the Art. 64-2 fine cap toward 10% of total revenue for repeated or large scale violations and to add personal liability for a controller's chief executive, effective 11 September 2026, but no official source for that amendment is located, so it is not recorded as a dated stage.

What it requires

Sensitive categories

Personal Information Protection Act, sensitive information and biometric data

Act No. 10465 (as amended by Act No. 19234, 2023) Art. 23; Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 34309, Mar. 12, 2024), Art. 18official statute and Enforcement Decree text, KLRI English translation

In force since 15 September 2023. Binds public and private bodies.

What this law does

Art. 23 bars processing sensitive information without separate consent or statutory authorization, listing ideology, belief, health, sex life, and trade union or political affiliation directly and delegating further categories to the Enforcement Decree.

Decree Art. 18 adds DNA information, criminal history records, information revealing racial or ethnic origin, and biometric information, defined technology neutrally as data from specific technical processing of physical, physiological, or behavioral characteristics used to uniquely identify a person. That definition covers a faceprint and a voiceprint alike without naming either, and does not exclude an identifier derived from a photo, video, or audio recording.

What it requires

Scraping law4 instruments, 4 in force

Research summary (171 words)

South Korea has no scraping-specific statute. Computer misuse is read narrowly for public-page scraping: the Supreme Court held in Yanolja Co. v. GC Company (2021Do1533, 12 May 2022) that scraping publicly available listing data via a tool hitting an API server did not violate the Copyright Act or the network-intrusion statute as charged, though the same conduct separately lost as unfair competition in a parallel civil proceeding.

The Unfair Competition Prevention and Trade Secret Protection Act's general catch-all clause has done most of the real work in reported scraping cases, and a 2021-or-later amendment added a second, purpose-built data-misappropriation clause squarely on point for scraping that had not previously been catalogued here. The Copyright Act gives a sui generis database-producer right, unlike the United States or China.

A Personal Information Protection Commission guideline, not itself a statute, supplies the legitimate-interest basis for processing publicly available personal data in AI training. A text-and-data-mining copyright exception remains a pending bill, not enacted. As a unitary jurisdiction, Korea has no subnational divergence to research.

Computer misuse

Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention)

Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 21305, as amended), Art. 48official text, National Law Information Center (law.go.kr)

In force since 23 January 2024. Binds public and private bodies.

What this law does

Article 48(1) prohibits intruding into an information and communications network without legitimate access authority or beyond the scope of permitted authority. The Supreme Court held in Yanolja Co. v. GC Company (2021Do1533, 12 May 2022) that scraping publicly available data without defeating an authentication or access-control measure did not violate this provision as charged.

Paragraph (4), added January 23, 2024, separately prohibits installing, transmitting, or distributing a program or technical device whose purpose is to bypass a network's normal protection or authentication procedures, reaching a scraper's own circumvention tools directly even though paragraph (1)'s basic prohibition predates it and remains the article's core text.

What it requires

Personal data

Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline

Personal Information Protection Act (Act No. 18972, as amended) Art. 15(1)(vi); PIPC Guideline for Personal Data Processing for the Development and Utilization of Generative AI (issued 2024-07-18)official English-language press release, Personal Information Protection Commission (pipc.go.kr)

In force since 18 July 2024. Binds public and private bodies.

What this law does

Article 15(1)(vi) lets a personal information handler process personal information without consent where necessary to achieve the handler's legitimate interest and that interest clearly overrides the data subject's rights, provided the interest is substantially related to the handler's legitimate interest and does not exceed a reasonable scope.

The Personal Information Protection Commission's July 18, 2024 guideline, non-binding but currently the operative practical standard, clarifies that publicly available data can be used for AI training and service development under this ground, provided the processor meets three requirements: a specified, legitimate purpose for the AI model; necessity, meaning collection is limited to adequate and relevant data for that purpose; and a documented assessment that the processor's interest clearly overrides data subjects' rights, backed by named technical safeguards (examining training-data sources, de-identification, secure storage) and procedural ones (privacy-policy disclosure, impact assessment, an erasure or objection mechanism).

What it requires

Unfair competition

Unfair Competition Prevention and Trade Secret Protection Act, Art. 2(1) items ka and pa (data misappropriation and general catch-all)

Unfair Competition Prevention and Trade Secret Protection Act (Act No. 21065, as amended), Art. 2(1)(ka), (pa)official text, National Law Information Center (law.go.kr)

In force 12 months, effective 1 October 2025. Binds private bodies.

What this law does

Item pa is the general catch-all: using, contrary to fair commercial practice, the outcome of another person's substantial investment or effort for one's own business without authorization. It has done most of the real work in reported scraping cases: the Seoul High Court found systematic evasive scraping of a competing job-listing database an unfair-competition violation in Saramin Co. v. JobKorea Co. (2016Na2019365, 6 Apr.

2017, secondary-sourced), and in Yanolja Co. v. GC Company's parallel civil proceeding (Seoul High Court, 2021Na2034740, 25 Aug. 2022, secondary-sourced) the same scraping conduct that cleared criminally under the Information and Communications Network Act nonetheless lost under this clause, with an award of roughly KRW 1 billion.

A separate item, ka, added no earlier than December 2021 and not previously catalogued in this topic's research, is a purpose-built data-misappropriation clause: it reaches acquiring data by theft, fraud, unauthorized access, or other wrongful means and using or disclosing data so acquired; using or disclosing data obtained under a contractual access limit beyond that limit, for wrongful profit or to harm the data holder; acquiring or using data known to have been obtained either way; and providing, manufacturing, or distributing a technology or device whose main purpose is to circumvent a technical measure protecting data.

Item ka's structure closely parallels China's 2025 Anti-Unfair Competition Law Article 13 and is more directly on point for a scraping fact pattern than item pa's general catch-all.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (875 words)

South Korea's product-security and cyber-resilience duties for the private sector sit inside the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (the Network Act, an official English translation current through Act No. 20069, effective Jan. 23, 2024) and the Personal Information Protection Act (PIPA), rather than in a dedicated cyber-resilience code.

Network Act Article 45(1) directs both a provider of information and communications services and a manufacturer or importer of a connected device a Presidential Decree designates to take protective measures securing the network's stability, but the specific content of those measures is left to guidelines the Minister of Science and ICT (MSIT) may issue and may only recommend a bound person observe, backed by MSIT's own power to order corrective measures under Article 64; no provision sets a binding technical standard, a pre-market compliance gate, or a mandatory vulnerability-disclosure channel a manufacturer must meet before placing a device on the market, so the product-requirements research dimension is a researched absence.

Article 48-3 requires a provider of information and communications services to report a computer security incident to MSIT or the Korea Internet and Security Agency (KISA) immediately on discovering it, with no revenue or user threshold gating the reporting duty itself, and Article 48-4 requires the same broad class to analyze the incident's cause, respond to it, and preserve or submit the data MSIT or KISA demands for that analysis; failing either duty is an administrative fine of up to KRW 30,000,000 under Article 76(1).

Because that reporting duty binds a provider of information and communications services in the Act's own broad for-profit online-service sense rather than a licensed or government-designated status, it is flagged here rather than deferred, the same posture this profile gives India's CERT-In Directions.

A separate, higher bar inside the same Act binds only a class of information and communications service provider a Presidential Decree designates: mandatory designation of a Chief Information Security Officer under Article 45-3, and mandatory certification of an information security management system under Article 47 (ISMS, since consolidated with the former personal-information management system certification into a single ISMS-P scheme KISA and the Personal Information Protection Commission run jointly), with the certification duty's own qualifying class set at an annual sales or tax revenue of at least KRW 150,000,000,000, an information-and-communications-service sales of at least KRW 10,000,000,000, or an average of at least one million daily users over the preceding year.

No declared activity in this corpus's vocabulary expresses that threshold class, so this regime is recorded here rather than raised against a guess, the same treatment this profile gives DORA's financial entities and New York's Department of Financial Services Part 500 covered entities.

The Act on the Protection of Information and Communications Infrastructure separately binds the operator of a critical information and communications infrastructure facility the government designates case by case, sector by sector, under its own Article 8, with a vulnerability-analysis and protection-plan duty and an incident-notification duty, and it carries criminal exposure of up to ten years' imprisonment or a fine of up to KRW 100,000,000 for disturbing, paralyzing, or destroying such infrastructure; its bound party is likewise a government-designated status no declared activity can express, so it too is deferred rather than flagged.

PIPA Article 29 (Duty of Safeguards) belongs to the privacy topic rather than here, as one article of the comprehensive regime addressed to a personal information controller, the same place the General Data Protection Regulation's Article 32 sits.

It requires every personal information controller, with no sector or size gate, to take the technical, managerial, and physical measures a Presidential Decree prescribes, including an internal management plan and preservation of access records, so that personal information is not lost, stolen, divulged, forged, altered, or damaged; a controller who breaches that duty and thereby causes a data subject to suffer exactly that kind of harm exposes itself to up to five times the subject's actual damages under Article 39(3), or to statutory damages of up to KRW 3,000,000 under Article 39-2 without proof of actual loss, the same general civil remedy this jurisdiction's own privacy enforcement row already records.

Korea has no enacted product-security law with a market-placement gate; the nearest instrument is KISA's IoT Security Certification System, a voluntary programme that evaluates a product against Lite and Standard assurance tiers and carries no legal force of its own beyond a public-procurement preference for a certified product, so it is named here rather than filed as an instrument.

Two further amendments are not coded as instruments because the primary text is not yet available through a reachable source and the finding rests only on secondary legal commentary: a PIPA amendment (Act No. 21445, promulgated Mar. 10, 2026) is reported to take effect Sept. 11, 2026 and to make ISMS-P certification mandatory from Jul. 1, 2027, and a Network Act amendment (Bill No. 14896, promulgated Mar. 31, 2026) is reported to take effect Oct.

1, 2026 (except a new information-security-level assessment system, Apr. 1, 2027) and to expand the Chief Information Security Officer's staffing, budget, and board-reporting duties. This jurisdiction's own privacy row already records PIPA's breach-notification duty to the Personal Information Protection Commission and to an affected individual (Article 34); it is not repeated here.

Vulnerability and incident reporting

Information and Communications Network Act, Report on Computer Security Incidents

Arts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection Etc. (Act No. 20069, Jan. 23, 2024)Official English translation, Korea Legislation Research Institute (elaw.klri.re.kr), consolidated through Act No. 20069 (Jan. 23, 2024)

In force since 10 June 2022. Binds private bodies.

What this law does

A provider of information and communications services, a person who for profit provides information or acts as an intermediary in providing information using a telecommunications business operator's services, must immediately report a computer security incident to the Minister of Science and ICT or the Korea Internet and Security Agency (KISA) upon discovering it; a report already made for the same incident under another statute satisfies this duty.

The same class of person must then analyze the cause of the incident, respond based on that analysis, and take measures to keep the resulting damage at bay, and must preserve or submit the data the Minister or KISA demands for that analysis when ordered to. Failing to report the incident, or failing to submit the demanded data or submitting false data, is an administrative fine of up to KRW 30,000,000.

What it requires

Age gating law3 instruments, 2 in force, 1 repealed, withdrawn or blocked

Research summary (121 words)

South Korea has required age and identity verification before providing media designated as harmful to youth since a 2001 amendment, a duty now housed in Article 16 of the Youth Protection Act (Korean: 청소년 보호법) and enforced with criminal penalties for commercial violations.

Online game access for minors is separately managed under the Game Industry Promotion Act's (Korean: 게임산업진흥에 관한 법률) Game Time Selection System (Article 12-3), which lets a minor or the minor's legal guardian set the minor's own play-time limits; this became the sole statutory game-time control after the government's mandatory overnight shutdown system (the former Youth Protection Act Article 26) was repealed effective January 1, 2022. No dedicated social-media minimum-age or app-store age-verification statute is currently in force.

Adult content age verification (AV)

청소년 보호법 (Youth Protection Act), Article 16, age and identity verification for youth-harmful media

청소년 보호법 (Youth Protection Act, Act No. 21277, most recently amended 2025-12-30, effective 2026-07-01) Art. 16; verification duty introduced by the amendment of Act No. 6479 (2001), renumbered by the 2011 whole amendmentofficial consolidated text, Korea National Law Information Center (law.go.kr)

In force since 25 August 2001. Binds private bodies.

What this law does

Requires anyone who sells, rents, distributes or otherwise provides media designated as harmful to youth (Korean: 청소년유해매체물) to verify the recipient's age and identity, using in-person confirmation, a certified digital certificate, or mobile phone carrier authentication, and prohibits providing such media to anyone under 19. The verification duty dates to the 2001 amendment (Act No. 6479, effective 25 August 2001) and sits in Article 16 of the wholly amended Act. Commercial violations carry criminal penalties under Article 58.

Note and primary source

Age-appropriate design code

게임산업진흥에 관한 법률 (Game Industry Promotion Act), Article 12-3, Game Time Selection System

게임산업진흥에 관한 법률 (Game Industry Promotion Act, Act No. 20485, amended 2024-10-22), Art. 12-3official consolidated text, Korea National Law Information Center (law.go.kr)

In force since 22 January 2012. Binds private bodies.

What this law does

Lets a minor under 18 or the minor's legal guardian request that an online game provider restrict the minor's game access to specific hours or a set daily duration, and requires the game provider to comply with the requested restriction. Since the parallel mandatory overnight shutdown system was repealed effective January 1, 2022, this parental-choice system is the sole statutory game-time control for minors.

Note and primary source

청소년 보호법 (former) Article 26, mandatory online game curfew (shutdown system), repealed

청소년 보호법 (Youth Protection Act) former Art. 26, repealed by Act No. 18550 (promulgated 2021-12-07)official amendment record, Korea National Law Information Center (law.go.kr)

Repealed: no longer in force, effective 20 November 2011. Binds private bodies.

What this law does

Formerly barred online game providers from offering internet games to anyone under 16 between midnight and 6 a.m., commonly called the shutdown system or Cinderella law. The National Assembly passed the repeal on 11 November 2021, the repeal was promulgated as Act No. 18550 on 7 December 2021, and it took effect on 1 January 2022, unifying game-time control into the parental-choice Game Time Selection System under the Game Industry Promotion Act.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (248 words)

South Korea has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining code, and no hot-news or misappropriation doctrine distinct from ordinary copyright law; each is a sourced absence in the Copyright Act's own text rather than an unresolved question.

The Copyright Act excludes current news reporting that delivers simple facts from protection outright (Art. 7(5)), permits reproducing a work encountered while reporting current events (Art. 26), lets a media organisation reproduce, distribute, or broadcast a news article or editorial carried in another newspaper, online newspaper, or news agency unless the originating outlet has posted a prohibition (Art. 27), and allows quoting an already-published work for news reporting, criticism, education, or research within fair practice (Art. 28); no machine-readable text-and-data-mining reservation has been located, and no statute or case law on hyperlinking or framed display has been located either.

Separately, and outside any of this topic's six law families, the Act on the Promotion of Newspapers requires a person operating an online news service, its term for an electronic publication that continuously supplies or intermediates news articles of newspapers, online newspapers, news agencies, broadcasts, or magazines via the internet, to register with the relevant Mayor or Do Governor before operating, on pain of an administrative fine of up to KRW 20,000,000 for operating unregistered (Arts. 2, 9, 39); that registration and licensing duty attaches to the aggregation activity itself rather than to a copyright, bargaining, or linking mechanism, so it is not recorded as an instrument of this topic.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.