Korea PIPA is the Personal Information Protection Act, the country’s omnibus privacy statute, enforced by the Personal Information Protection Commission. It reaches foreign companies that serve Korean users without a Korean office, and from September 11, 2026 an amendment adds a 10 percent of total revenue fine ceiling for aggravated cases. Sequence compliance alongside entity formation.

Most foreign executives meet PIPA in one of three moments: a Korean customer’s security questionnaire arrives mid-deal, a Korean agency asks for consent wording before it will launch a lead form, or the first Korean hire’s employment data packet needs signing. By then the architecture is set and expensive to reverse. The broader sequence sits in the guide to doing business in Korea for foreign companies.

Data current as of August 2026; PIPA was amended in 2023, 2025, and 2026, so confirm every provision with Korean counsel.

What Is Korea PIPA and Who Does It Apply To?

PIPA covers public and private sector processing alike, and the Personal Information Protection Commission (PIPC) has held independent enforcement authority since 2020, with power to order corrections, impose surcharges, and refer misconduct for prosecution. Three statutes bind independently alongside it: the Credit Information Use and Protection Act for financial and credit data, the Location Information Act for location data, and Article 50 of the Information and Communications Network Act for commercial advertising. One Korean lead generation program can touch all four.

The September 15, 2023 restructuring put online service providers under the same rules as everyone else. Shin and Kim’s 2023 analysis records that it also moved the surcharge base from violation-related revenue to total revenue, leaving the controller to prove which revenue is unrelated. Fail to submit the materials the PIPC requests and total revenue becomes the base.

Does PIPA Apply to a Company With No Office in Korea?

Yes, in defined circumstances. The PIPC’s guidelines for foreign business operators, published April 4, 2024 and summarized by Shin and Kim in 2024, apply PIPA to any company that provides goods or services to Korean data subjects, processes their personal information in a way that directly or significantly affects them, or holds a place of business in Korea. The tie-breakers are language, currency, and delivery: a Korean-language checkout that prices in won and ships to Korean addresses has answered the question.

Enforcement confirms the reach. On September 14, 2022 the PIPC fined Google KRW 69.2 billion and Meta KRW 30.8 billion for collecting cross-site behavioral data for personalized advertising without clear separate consent, the largest PIPA penalties to that point. It fined the Worldcoin Foundation and Tools for Humanity Corporation KRW 1.104 billion in 2024.

A brass desk stand holding a single blank ivory card beside a closed ivory folder with a copper paper clip

Who Must You Appoint in Korea?

Foreign companies above the Article 32-3 Enforcement Decree thresholds must appoint a domestic representative. The 2025 amendment, effective October 2, 2025 according to DataGuidance’s 2025 reporting, requires a company that already has a Korean entity to designate that entity, ending the practice of naming an unrelated agent while the subsidiary stays outside the compliance chain. Liability stays with the foreign company.

Article 31 requires controllers other than micro enterprises to designate a chief privacy officer from among their own executives or employees. Above the Enforcement Decree thresholds the bar is four years of combined experience across personal information protection, information security, and information technology, two of them in privacy. Ius Laboris reported in 2024 that incumbents held a grace period to March 14, 2026; it has expired, and the bar now applies without transition relief. That rules out the regional model where a privacy lead in Singapore covers Korea as a line item.

How Do Cross-Border Data Transfers Work Under PIPA?

Article 28-8 permits transfers out of Korea on five grounds: separate consent; a law or treaty; storage or entrustment needed to perform a contract with the data subject, disclosed in the privacy policy or notified in writing; a PIPC-recognized certification such as ISMS-P; and an adequacy recognition. Article 28-9 lets the PIPC suspend a transfer.

PIPA imposes no general data localization requirement, which separates Korea from China; localization duties come from sector statutes, including the Electronic Financial Transactions Act for credit and unique identification data in the cloud, the Medical Service Act for electronic medical records, and the Cloud Computing Act for public sector cloud.

On January 23, 2025 the PIPC penalized KakaoPay KRW 5.968 billion for sending user data to Alipay without separate consent or disclosure, and Apple Distribution International Limited KRW 2.45 billion for omitting Alipay as an overseas trustee from its privacy policy. Most B2B companies move Korean data offshore on day one through a CRM, a marketing platform, and an analytics stack, and that work belongs in the entry budget covered in the guide to what entering the Korean market costs.

What Does PIPA Enforcement Actually Look Like?

Coupang defines the current climate. On June 11, 2026 the PIPC fined Coupang KRW 624.7 billion, about USD 409 million, the largest penalty in the commission’s history, and separately fined its logistics affiliate Coupang Fulfillment Services KRW 248 million. The Korea Times reported the 2026 split: KRW 423.6 billion for a breach exposing roughly 37.55 million people, and KRW 201.1 billion for collecting the online activity of about 11.17 million users across third-party sites without consent.

Two features of that case travel. The KRW 201.1 billion component was a consent and collection failure with no security incident behind it, the exposure a marketing stack creates. And the group parent, Coupang, Inc., is a Delaware-incorporated company listed on the New York Stock Exchange, which put nothing in the Korean operation beyond the PIPC’s reach.

The telecom cases set the comparison. On August 27, 2025 the PIPC fined SK Telecom KRW 134.8 billion after USIM data on 23.2 million customers was stolen, citing access control failures and delayed notification; that was the record until Coupang surpassed it. On July 30, 2026 the commission fined KT Corporation KRW 53.979 billion over cloned femtocells: attackers extracted certificates from lost KT units, installed them on devices they had built, and used the illegal base stations to pull subscriber traffic onto their own equipment. The Korea JoongAng Daily reported in 2026 that the breach ran from October 8, 2024 to September 5, 2025, exposed 16,647 subscribers, and enabled fraudulent micropayments costing 368 victims about KRW 240 million. Fewer than 17,000 people, and still a KRW 54 billion penalty, because Korean calculation weighs conduct and revenue base alongside scale.

The surcharge is only part of the exposure. Article 39-2 lets a court award statutory damages of up to KRW 3 million per data subject with no proof of loss, and Article 39(3) allows punitive damages of up to five times actual damages, raised from three times in 2023, with the controller bearing the burden of disproving intent or negligence. Criminal liability lands on individuals: up to five years of imprisonment or a KRW 50 million fine for offenses such as third-party provision without consent, and up to two years where missing safety measures result in a leak.

What Changes on September 11, 2026?

The National Assembly passed the current amendment on February 12, 2026, it was promulgated on March 10, 2026, and it takes effect on September 11, 2026. The IAPP called it the most consequential rewrite since 2023.

The 3 percent baseline stays. On top of it, Hunton’s 2026 analysis identifies three triggers for a 10 percent of total revenue ceiling: an intentional or grossly negligent violation repeated within three years, conduct of the same kind affecting 10 million or more individuals, and failure to comply with a corrective order followed by a breach. The amendment names the business owner or representative as the ultimate responsible person for data protection and expands reporting beyond leakage to forgery, alteration, and damage. ISMS-P certification becomes mandatory for major controllers from July 1, 2027.

Two draft decrees fill in the detail: one published June 1, 2026 on revenue calculation and the fine reduction mechanism, and one published June 2, 2026 on breach prevention and data subject rights, consulted on until July 13, 2026. Act on the reduction provision, because documented investment in privacy staffing, budget, and technical measures becomes a quantifiable mitigating factor.

How Should a Foreign Company Sequence PIPA Compliance?

Start with HR. For any company forming a Korean entity the first PIPA contact is employee data: consent forms, retention limits, and resident registration numbers collected for payroll and the four national insurances all go live on the day of the first hire, before any customer-facing system exists.

Resident Registration Numbers and Article 24-2

Article 24-2 prohibits processing a resident registration number (주민등록번호, jumin deungnok beonho) unless an Act, Presidential Decree, or PIPC notification specifically requires or permits it. Consent alone has not been a lawful basis since 2014. Employment, payroll, and social insurance filings supply that statutory basis; a marketing sign-up or a standard customer account does not. Where a commercial flow needs identity verification, Korea’s designated services replace the number: mobile carrier verification, credit card verification, and i-PIN return a Connecting Information value derived from the RRN. Since the 2023 amendment an RRN failure has fallen under the general Article 64-2 surcharge, up to 3 percent of total revenue, and up to 10 percent from September 11, 2026.

The Korean Privacy Policy

The deliverable has a name: the personal information processing policy (개인정보처리방침, gaeinjeongbo cheori bangchim) required by Article 30. It must state processing purposes, retention periods, third-party provision, outsourcing, data subject rights and how to exercise them, and the name and contact details of the privacy officer, and it must stay published for data subjects to read. Since April 2024 the PIPC has assessed policies under Article 30-2 against its Privacy Policy Drafting Guidelines. Write it from a data flow map, because a translated global notice rarely carries the contents Article 30 requires.

Article 22 requires a controller to split consent needed to deliver the service from optional consent, and Article 22(5) prohibits refusing goods or services because a data subject declined the optional part. Consent for promoting or soliciting sales is a distinct legal act and cannot ride on the terms-of-service checkbox. Article 50 of the Network Act adds a layer for advertising: explicit prior consent, the message labeled as advertising (광고), and separate consent for anything sent between 9 p.m. and 8 a.m. KISA and the Korea Communications Commission published revised illegal-spam guidance on March 4, 2026. Inquivix covers the campaign side in its guide to Korea’s regulatory landscape for financial advertising, and the channel context sits in digital marketing in Korea.

Tie the representative and officer decisions to entity structure: a Korean subsidiary carries both, while a distributor entry needs the agreement to establish who is controller and who is processor, a point covered in the guide to Korea market entry mistakes. Build the incident runbook last and test it against a 72 hour clock that runs in Korean.

Frequently Asked Questions

How large can a PIPA fine be? Until September 11, 2026 the ceiling is 3 percent of total revenue, with the controller proving which revenue is unrelated. From that date the 3 percent baseline remains and the March 10, 2026 amendment adds a 10 percent ceiling for aggravated cases: intentional or grossly negligent violations repeated within three years, incidents affecting 10 million or more individuals, and breaches following non-compliance with a corrective order. The record penalty is KRW 624.7 billion against Coupang on June 11, 2026.

Who must appoint a domestic representative under PIPA? Foreign companies meeting any Article 32-3 threshold: annual global revenue above KRW 1 trillion, a daily average of more than 1 million Korean users’ data processed in the previous year’s final quarter, or a PIPC determination. Since October 2, 2025 a company with a Korean entity must designate that entity.

How quickly must a data breach be reported in Korea? Within 72 hours of becoming aware, to the PIPC or the Korea Internet and Security Agency, when a leak affects 1,000 or more data subjects, involves sensitive information, or follows unauthorized external access, according to Baker McKenzie’s 2025 handbook. Affected individuals get the same window.

Where to Start

PIPA belongs in the same planning window as entity formation, distributor selection, and the incentives covered in the guide to Korea FDI incentives. Inquivix works with international companies on Korea market entry, localization, and digital growth, including the consent and privacy policy architecture behind Korean lead generation, alongside Korean privacy counsel. To discuss a specific entry plan, write to joon@joonklee.com.